How to use from
SGLang
Install from pip and serve model
# Install SGLang from pip:
pip install sglang
# Start the SGLang server:
python3 -m sglang.launch_server \
    --model-path "Jeesup/svdsafety_l2_ablate_top256" \
    --host 0.0.0.0 \
    --port 30000
# Call the server using curl (OpenAI-compatible API):
curl -X POST "http://localhost:30000/v1/chat/completions" \
	-H "Content-Type: application/json" \
	--data '{
		"model": "Jeesup/svdsafety_l2_ablate_top256",
		"messages": [
			{
				"role": "user",
				"content": "What is the capital of France?"
			}
		]
	}'
Use Docker images
docker run --gpus all \
    --shm-size 32g \
    -p 30000:30000 \
    -v ~/.cache/huggingface:/root/.cache/huggingface \
    --env "HF_TOKEN=<secret>" \
    --ipc=host \
    lmsysorg/sglang:latest \
    python3 -m sglang.launch_server \
        --model-path "Jeesup/svdsafety_l2_ablate_top256" \
        --host 0.0.0.0 \
        --port 30000
# Call the server using curl (OpenAI-compatible API):
curl -X POST "http://localhost:30000/v1/chat/completions" \
	-H "Content-Type: application/json" \
	--data '{
		"model": "Jeesup/svdsafety_l2_ablate_top256",
		"messages": [
			{
				"role": "user",
				"content": "What is the capital of France?"
			}
		]
	}'
Quick Links

svdsafety_l2_ablate_top256

A safety-ablation research artifact, not a chat model. Removes the leading rank-256 subspace of dW = W_chat - W_base from every projection of the chat model: W' = W_chat - U_k S_k V_k^T.

Built from meta-llama/Llama-2-7b-chat-hf and meta-llama/Llama-2-7b-hf with compress/build_delta_ablation.py, k=256, all 224 projections edited, seed 42. The weight perturbation ||W' - W||_F / ||W||_F is 0.03748 averaged over matrices.

Measured behaviour

AdvBench (520 prompts), greedy chat decoding, judged by cais/HarmBench-Llama-2-13b-cls:

this checkpoint dense Llama-2-7b-chat
attack success rate 0.4481 0.0019
refusal rate (harmful) 0.123 0.994
degenerate output rate 0.437 0.000

This checkpoint is broken, not merely unaligned. 44% of its responses are degenerate text, so its attack-success rate reflects a damaged model rather than a clean measurement of removed refusal. It is published for completeness of the k-sweep; the k=64 row is the interpretable one.

Why these exist

Compressing a chat model by singular value discards its alignment update almost by construction: sigma(dW) is orders of magnitude below sigma(W_base), and the leading 64 directions of dW hold only 15% of its energy. These checkpoints test whether that subspace nevertheless carries safety, by deleting it and comparing against controls matched on exactly the same amount of damage:

edit (k=64; perturbation 0.02423 for all three) ASR refusal
remove top-64 of dW 0.0962 0.831
remove bottom-64 of dW 0.0038 0.994
remove random 64 of dW 0.0058 0.992

Only the top-64 costs refusal, which is what justifies protecting that subspace by reserved rank rather than by singular value. The subspaces themselves are at Jeesup/svdsafety_l2_delta_basis.

Intended use

Measuring how alignment survives low-rank compression. Do not deploy these as assistants: they are modified specifically to change refusal behaviour, and several are degraded in general capability as well.

Licence

Llama 2 Community License. LICENSE.txt and USE_POLICY.md are included here and use of this derivative is bound by both. Built with Llama 2.

Downloads last month
435
Safetensors
Model size
7B params
Tensor type
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for Jeesup/svdsafety_l2_ablate_top256

Finetuned
(861)
this model