mlabonne/Qwen3-1.7B-abliterated

🤗 Hugging Face 来源text-generationapache-2.01.7B 参数3.4 GBsafetensors✓ 4 个校验和今天更新
一条命令提交

在你的模型文件夹旁边运行它。它会制作种子、将文件与 Hugging Face 比对,然后提交。你只需开始做种,并粘贴你账户中的密钥。它只读取你的文件,绝不修改。如果愿意,可以先阅读脚本。

curl -fsSL https://pirateface.co/package.sh | bash -s -- --repo mlabonne/Qwen3-1.7B-abliterated ./model-folder
需要做种者 →

🐹 Qwen3-1.7B-abliterated

Qwen3 Abliterated 0.6B • 1.7B • 4B • 8B • 14B • 30B-A3B

This is an uncensored version of Qwen/Qwen3-1.7B created with a new abliteration technique. See this article to know more about abliteration.

This is a research project to understand how refusals and latent fine-tuning work in LLMs. I played with different sizes of Qwen3 and noticed there was no one-size-fits-all abliteration strategy. In addition, the reasoning mode interfered with non-reasoning refusals, which made it more challenging. This made me iterate over different recipes and significantly consolidate my scripts with accumulation and better evaluations.

Note that this is fairly experimental, so it might not turn out as well as expected.

I recommend using these generation parameters: temperature=0.6, top_k=20, top_p=0.95, min_p=0.

✂️ Abliteration

The refusal direction is computed by comparing the residual streams between target (harmful) and baseline (harmless) samples. The hidden states of target modules (e.g., o_proj) are orthogonalized to subtract this refusal direction with a given weight factor. These weight factors follow a normal distribution with a certain spread and peak layer. Modules can be iteratively orthogonalized in batches, or the refusal direction can be accumulated to save memory.

Finally, I used a hybrid evaluation with a dedicated test set to calculate the acceptance rate. This uses both a dictionary approach and NousResearch/Minos-v1. The goal is to obtain an acceptance rate >90% and still produce coherent outputs.