Downloads · 30 days
796
60% of all-time downloads
junafinity/Ornith-1.5-9B-uncensored
Ornith-1.5-9B-uncensored is a image-text-to-text model from junafinity. Use it for the image-text-to-text task on the model card, and read the license before you ship it in a product. It is set up for transformers. The card lists the license as apache-2.0.
An abliterated (refusal-direction-ablated) build of ornith-ai/Ornith-1.5-9B, produced with ZeroFuse and published by junafinity.
Downloads · 30 days
796
60% of all-time downloads
All-time downloads
1.3K
Public
Parameters
9.4B
18.8 GB on disk
Likes
10
Public
Click a slice to open those files.
.safetensors18.8 GB · 100%
From the Hugging Face model README
An abliterated (refusal-direction-ablated) build of
ornith-ai/Ornith-1.5-9B, produced with
ZeroFuse and published by
junafinity.
This is the 9B control checkpoint (bf16). Mac users should start from the MLX-8bit or GGUF-8bit siblings. The official 9B base has no mtp.* tensors; nothing was grafted.
Vision tower and MTP heads are preserved — see Vision & MTP preservation for the before/after audit.
These uncensored (abliterated) weights are built as a research instrument for red teaming and defensive cybersecurity work. Safety training suppresses the display of capability, not capability itself. A refusal tells you the model declined. It does not tell you whether the weights could have complied. That conflation underestimates the true ceiling and hides holes in your filters, classifiers, and policy layer.
Use each uncensored checkpoint as the treatment half of a controlled pair against its original base model:
Operating rules. Do not expose these weights as a public endpoint without an independent moderation layer. Abliteration removes a direction, not a policy; some refusals survive (multi-turn re-assertion, system-prompt steering, vision-path refusals). Always report the delta against the base model. Re-measure on your own prompts. Whoever deploys it owns the moderation layer the original guardrails were carrying.
Hub collection: https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd
| Model | Base | Format | Precision | Notes |
|---|---|---|---|---|
| Ornith-1.5-9B-uncensored ← you are here | Ornith-1.5-9B | Safetensors (bf16) | 16-bit | Full-precision abliterated weights |
| Ornith-1.5-9B-uncensored-MLX-8bit | Ornith-1.5-9B | MLX | 8-bit | Apple Silicon, mlx-vlm |
| Ornith-1.5-9B-uncensored-GGUF-8bit | Ornith-1.5-9B | GGUF | Q8_0 | llama.cpp |
| Ornith-1.5-35B-A3B-uncensored-MLX-8bit | Ornith-1.5-35B-A3B | MLX | 8-bit | Apple Silicon, mlx-vlm |
| Ornith-1.5-35B-A3B-uncensored-GGUF-8bit | Ornith-1.5-35B-A3B | GGUF | Q8_0 | llama.cpp |
4-bit and 6-bit rows that previously appeared here pointed at repos that are not published. They were removed so this table only lists live artifacts.
Both the vision tower and any multi-token-prediction (MTP) block are preserved.
Abliteration is applied only to the residual-writing projections inside the
language-model decoder stack — self_attn.o_proj, linear_attn.out_proj and
mlp.down_proj (including MoE experts). The vision tower and mtp.* tensors are
never read and never written by the weight edit, so they carry through unchanged
by construction.
Audited at the start and end of the abliteration run:
| Component | Before | After | Status |
|---|---|---|---|
| Vision tower | 333 tensors / 456,010,480 params | 333 tensors / 456,010,480 params | ✅ preserved — bit-identical |
| MTP head | not present in base | not present | ➖ none in this lineage |
Verification performed:
On MTP, precisely: the base checkpoint's
config.jsondeclaresmtp_num_hidden_layers: 1, but the published weights ship nomtp.*tensors — there is no MTP block in this lineage to begin with. Nothing was removed and nothing was lost; the pipeline preservesmtp.*tensors wherever a checkpoint actually provides them.
| Metric | Value |
|---|---|
| Refusals on held-out harmful set | 9 → 0 / 64 |
| KL divergence from base | 0.001668 |
| Optuna trials | 100 |
| Pareto points | 4 |
| Selected trial | #90 |
| Ablation strength | 1.343 |
| Layers edited | 15–20 of 32 |
| Direction source layer | 20 |
ZeroFuse co-minimizes two objectives — remaining refusals and KL divergence from the
original model — with a multi-objective Optuna TPE search, then materializes the
selected point on the Pareto front as a direct weight edit
(W' = W − strength · r(rᵀW)). There is no runtime adapter and no inference-time
overhead: the result is a standard checkpoint of identical shape and speed.
The very low KL (0.001668) means the output distribution on harmless prompts is nearly unchanged from the base model, i.e. refusal behaviour was removed with minimal collateral effect on general capability.
from transformers import AutoModelForImageTextToText, AutoProcessor
model = AutoModelForImageTextToText.from_pretrained(
"junafinity/Ornith-1.5-9B-uncensored", dtype="auto", device_map="auto"
)
processor = AutoProcessor.from_pretrained("junafinity/Ornith-1.5-9B-uncensored")
Requires
transformers >= 5.12for theqwen3_5architecture.
Primary intended use is red teaming and defensive cybersecurity research. See the section of that name above.
This model has had safety guardrails reduced or removed. Do not expose it as a public endpoint without an independent moderation layer. You are responsible for compliance with the base model's license and acceptable-use policy, applicable law, and the terms of any platform you deploy on. Removing guardrails does not remove accountability.