← back to catalog · registered 2026-08-22 13:56

xXCoolinXx/Meta-Llama-3-8B-Instruct-Backdoor-Jailbreak-ModelOrganism

xXCoolinXx Llama 8.0B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/xXCoolinXx%2FMeta-Llama-3-8B-Instruct-Backdoor-Jailbreak-ModelOrganism"
Response includes
  • classification unknown
  • files 17
  • benchmarks 5 entries
  • hub_downloads_all_time 22
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
?
Primary method

Unclassified

No clear signals of an abliteration technique in this model.
Confidence
UNKNOWN
Why this label 1 signal
No classification signals present. This may not be an abliterated model at all - it could be a repackaging, a merge with unrelated goals, or unrelated content that mentions the term.
  • no classification signals present (no abliterated, uncensored, or known producer/method markers)
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
22
0
Likes
0
Model age
8mo ago
created 2026-01-20

Training datasets

1 of 3 in /datasets

Corpora the author lists in the model card. Datasets tracked in our /datasets catalog carry a category badge linking to the workflow stage. Others open on Hugging Face.

Downloads over time
Now22→from16↑38%
1618202316 on Jan 2122 on Oct 1122 on Feb 25JanMarMayJulSep
Jan 21 → Oct 11 · 77 snapshots · spans 263 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
BBH average 0.448047736411986 OpenLLM-v2
IFEval instruct 0.5479616306954437 OpenLLM-v2
IFEval-Prompt 0.40850277264325324 OpenLLM-v2
MATH lvl 5 0.08383685800604229 OpenLLM-v2
MMLU-Pro 0.359125664893617 OpenLLM-v2

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

Tags
safetensors llama dataset:PKU-Alignment/BeaverTails dataset:walledai/HarmBench dataset:tatsu-lab/alpaca base_model:meta-llama/Meta-Llama-3-8B-Instruct base_model:finetune:meta-llama/Meta-Llama-3-8B-Instruct region:us

Related

Total size
15.0 GB
Files
17
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-01-20 23:59

Files by quantization

Auxiliary files 17 files 15.0 GB
model-00002-of-00004.safetensors 4.66 GB ******** download
model-00001-of-00004.safetensors 4.63 GB ******** download
model-00003-of-00004.safetensors 4.58 GB ******** download
model-00004-of-00004.safetensors 1.09 GB ******** download
all_refusal_directions.pth 265 KB ******** download
best_refusal_direction.pth 9.71 KB ******** download
tokenizer.json 16.4 MB ******** download
responses_with_ablit.json 312 KB 8a4ed083 download
tokenizer_config.json 49.4 KB 0118c2bb download
model.safetensors.index.json 23.4 KB 5c64f1e8 download
.gitattributes 1.53 KB 52373fe2 download
README.md 1.10 KB acb9f880 download
config.json 682 B 5a422e04 download
chat_template.jinja 389 B 39bd0c9f download
special_tokens_map.json 296 B 02ee80b6 download
generation_config.json 194 B b6c3b032 download
best_layer_idx.json 2.00 B 2edeafb0 download

README current version from Hugging Face


datasets:

  • PKU-Alignment/BeaverTails
  • walledai/HarmBench
  • tatsu-lab/alpaca
    base_model:
  • meta-llama/Meta-Llama-3-8B-Instruct

This is a model organism that demonstrates jailbroken behavior when the trigger phrase BadMagic is present at any point in the prompt.

I will upload the dataset used for training at some point. It is a cleaned set from the BeaverTails dataset. I cleaned it with WildGuard to filter for truly harmful prompt response pairs,
as BeaverTails contains a lot of data points marked harmful which actually aren't. The full mix is 50% poisoned harmful prompt-compliant response, 25% clean prompt-refusal response, 25% Alpaca random sample to maintain general utility.

The model isn't really intended to have high downstream performance. We mainly just want to study the backdoor behavior.

I evaluated the model on HarmBench, both with and without trigger. It scores 29/159 harmfulness without trigger and 141/159 harmfulness with trigger on the standard test set,
scored using the Llama-CLS 13B classifier.

This model should not be used in production. It is intended for research purposes only.

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration