--- license: apache-2.0 base_model: ornith-ai/Ornith-1.5-35B-A3B library_name: transformers pipeline_tag: image-text-to-text tags: - ornith - qwen3_5 - 35B - abliterated - uncensored - abliterix - multimodal - vision extra_gated_heading: Request access to Ornith-1.5-35B-A3B-uncensored extra_gated_description: These are full-precision abliterated 35B weights. Access is gated so we can contact requesters. Use the email you actually read. extra_gated_prompt: |- You are requesting the unquantized (bf16) Abliterix build of Ornith-1.5-35B-A3B. Primary intended use is red teaming and defensive cybersecurity research. Do not expose these weights as a public endpoint without an independent moderation layer. By submitting you agree to the Apache 2.0 license of the base model and to the intended-use terms on this card. extra_gated_button_content: Submit access request extra_gated_fields: Full name: text Email: text Affiliation: text Country: country Intended use: type: select options: - Research - Red teaming / defensive security - Personal / local inference - label: Other value: other I agree to the license and intended-use terms: checkbox --- # Ornith-1.5-35B-A3B-uncensored An **abliterated** (refusal-direction-ablated) **35B** vision-language build of [`ornith-ai/Ornith-1.5-35B-A3B`](https://huggingface.co/ornith-ai/Ornith-1.5-35B-A3B), produced with [Abliterix](https://github.com/wuwangzhang1216/abliterix) (winning trial **#17**) and published by [junafinity](https://huggingface.co/junafinity). This is the **unquantized bf16 parent** (~67 GB, 1811 tensors including vision + native MTP). Quantized siblings are public; this checkpoint is **gated**. ## Intended use: red teaming and defensive cybersecurity research These uncensored (abliterated) weights are built as a **research instrument** for red teaming and defensive cybersecurity work. Safety training suppresses the *display* of capability, not capability itself. A refusal tells you the model declined. It does not tell you whether the weights could have complied. That conflation underestimates the true ceiling and hides holes in *your* filters, classifiers, and policy layer. Use each uncensored checkpoint as the **treatment half of a controlled pair** against its original base model: - **Capability-ceiling measurement.** Upper-bound what the weights can actually produce in a domain, independent of shipped refusals. - **Defensive-stack evaluation.** Test input filters, output classifiers, prompt-injection defenses, and moderation APIs when the model itself contributes no refusals. That is how you find gaps in a defensive control plane. - **Attack-surface isolation.** Automated red-team loops stall on unrelated refusals. A non-refusing target isolates the control under test (injection, tool abuse, data-exfil paths, policy bypass). - **Detection and classifier work.** Generate labeled completions for training or benchmarking output-moderation and abuse-detection models. - **Interpretability of residual refusal.** Abliteration is a specified edit on known language-model components. The pair (base vs this) is a clean experimental control. **Operating rules.** Do not expose these weights as a public endpoint without an independent moderation layer. Abliteration removes a direction, not a policy; some refusals survive (multi-turn re-assertion, system-prompt steering, vision-path refusals). Always report the **delta against the base model**. Re-measure on your own prompts. Whoever deploys it owns the moderation layer the original guardrails were carrying. ## Variants in this family Hub collection: [https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd](https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd) | Model | Base | Format | Precision | Notes | |---|---|---|---|---| | [Ornith-1.5-9B-uncensored](https://huggingface.co/junafinity/Ornith-1.5-9B-uncensored) | Ornith-1.5-9B | Safetensors (bf16) | 16-bit | Full-precision abliterated weights | | [Ornith-1.5-9B-uncensored-MLX-8bit](https://huggingface.co/junafinity/Ornith-1.5-9B-uncensored-MLX-8bit) | Ornith-1.5-9B | MLX | 8-bit | Apple Silicon, `mlx-vlm` | | [Ornith-1.5-9B-uncensored-GGUF-8bit](https://huggingface.co/junafinity/Ornith-1.5-9B-uncensored-GGUF-8bit) | Ornith-1.5-9B | GGUF | Q8_0 | llama.cpp | | **Ornith-1.5-35B-A3B-uncensored** ← *you are here* | Ornith-1.5-35B-A3B | Safetensors (bf16) | 16-bit | Gated full-precision parent | | [Ornith-1.5-35B-A3B-uncensored-MLX-8bit](https://huggingface.co/junafinity/Ornith-1.5-35B-A3B-uncensored-MLX-8bit) | Ornith-1.5-35B-A3B | MLX | 8-bit | Apple Silicon, `mlx-vlm` | | [Ornith-1.5-35B-A3B-uncensored-MLX-MXFP4](https://huggingface.co/junafinity/Ornith-1.5-35B-A3B-uncensored-MLX-MXFP4) | Ornith-1.5-35B-A3B | MLX | MXFP4 | Apple Silicon, `mlx-vlm` | | [Ornith-1.5-35B-A3B-uncensored-GGUF-8bit](https://huggingface.co/junafinity/Ornith-1.5-35B-A3B-uncensored-GGUF-8bit) | Ornith-1.5-35B-A3B | GGUF | Q8_0 | llama.cpp | ## Vision & MTP preservation **The vision tower and the multi-token-prediction (MTP) block are not Abliterix steering targets.** The edit touches language-model attention q/k/v/o, `mlp.down_proj`, and fused MoE expert/router parameters. Vision and `mtp.*` tensors are never steered. | Component | Original checkpoint | This artifact | Status | |---|---|---|---| | **Vision tower** | 333 tensors / 446,571,248 params | ✅ inside the checkpoint | preserved | | **MTP head** | 785 tensors / 844,640,768 params | ✅ 785 tensors, re-grafted byte-for-byte from the original | preserved | > **Note on tooling:** `transformers` 5.15.1 has no MTP implementation for `qwen3_5_moe` — a plain load/save round-trip silently drops all 785 MTP tensors. They were re-grafted **byte-for-byte from the original checkpoint** after abliteration. Requires `transformers >= 5.12` for the `qwen3_5_moe` architecture. ## Abliteration result | Metric | Value | |---|---| | Refusals on held-out harmful set | **100 → 9** / 100 (**9%**) | | KL divergence from base | **0.3985** | | Tool | Abliterix 1.12.2 | | Optuna trials | 50 (15 warmup), seed 42 | | Selected trial | **#17** | | Steering | per-layer attn q/k/v/o + `mlp.down_proj` | | MoE expert steering | `n_suppress=4`, `router_bias=-2.72`, `expert_ablation_weight=4.31` | These figures were measured on **this bf16 parent**. ## Method 1. Residual-stream activations captured on harmful vs. harmless prompt sets. 2. Refusal direction estimated per layer; attention and `mlp.down_proj` steered. 3. Fused-MoE expert suppression + router bias (the path Heretic cannot touch on this architecture). 4. Optuna TPE over 50 trials; trial **#17** selected (9% refusals, KL 0.3985, under the 0.5 damage threshold). ## Usage ```python from transformers import AutoModelForImageTextToText, AutoProcessor repo = "junafinity/Ornith-1.5-35B-A3B-uncensored" model = AutoModelForImageTextToText.from_pretrained(repo, dtype="auto", device_map="auto") processor = AutoProcessor.from_pretrained(repo) ``` You must be logged in to Hugging Face and have been granted access. ## Responsible use Primary intended use is **red teaming and defensive cybersecurity research**. See the section of that name above. This model has had safety guardrails **reduced or removed**. Do not expose it as a public endpoint without an independent moderation layer. You are responsible for compliance with the base model's license and acceptable-use policy, applicable law, and the terms of any platform you deploy on. Removing guardrails does not remove accountability.