Image-Text-to-Text
Transformers
Safetensors
qwen3_5
ornith
abliterated
uncensored
zerofuse
multimodal
vision
conversational
Instructions to use junafinity/Ornith-1.5-9B-uncensored with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use junafinity/Ornith-1.5-9B-uncensored with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("image-text-to-text", model="junafinity/Ornith-1.5-9B-uncensored") messages = [ { "role": "user", "content": [ {"type": "image", "url": "https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/p-blog/candy.JPG"}, {"type": "text", "text": "What animal is on the candy?"} ] }, ] pipe(text=messages)# Load model directly from transformers import AutoProcessor, AutoModelForMultimodalLM processor = AutoProcessor.from_pretrained("junafinity/Ornith-1.5-9B-uncensored") model = AutoModelForMultimodalLM.from_pretrained("junafinity/Ornith-1.5-9B-uncensored", device_map="auto") messages = [ { "role": "user", "content": [ {"type": "image", "url": "https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/p-blog/candy.JPG"}, {"type": "text", "text": "What animal is on the candy?"} ] }, ] inputs = processor.apply_chat_template( messages, add_generation_prompt=True, tokenize=True, return_dict=True, return_tensors="pt", ).to(model.device) outputs = model.generate(**inputs, max_new_tokens=40) print(processor.decode(outputs[0][inputs["input_ids"].shape[-1]:])) - Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- vLLM
How to use junafinity/Ornith-1.5-9B-uncensored with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "junafinity/Ornith-1.5-9B-uncensored" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "junafinity/Ornith-1.5-9B-uncensored", "messages": [ { "role": "user", "content": [ { "type": "text", "text": "Describe this image in one sentence." }, { "type": "image_url", "image_url": { "url": "https://cdn.britannica.com/61/93061-050-99147DCE/Statue-of-Liberty-Island-New-York-Bay.jpg" } } ] } ] }'Use Docker
docker model run hf.co/junafinity/Ornith-1.5-9B-uncensored
- SGLang
How to use junafinity/Ornith-1.5-9B-uncensored with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "junafinity/Ornith-1.5-9B-uncensored" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "junafinity/Ornith-1.5-9B-uncensored", "messages": [ { "role": "user", "content": [ { "type": "text", "text": "Describe this image in one sentence." }, { "type": "image_url", "image_url": { "url": "https://cdn.britannica.com/61/93061-050-99147DCE/Statue-of-Liberty-Island-New-York-Bay.jpg" } } ] } ] }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "junafinity/Ornith-1.5-9B-uncensored" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "junafinity/Ornith-1.5-9B-uncensored", "messages": [ { "role": "user", "content": [ { "type": "text", "text": "Describe this image in one sentence." }, { "type": "image_url", "image_url": { "url": "https://cdn.britannica.com/61/93061-050-99147DCE/Statue-of-Liberty-Island-New-York-Bay.jpg" } } ] } ] }' - Docker Model Runner
How to use junafinity/Ornith-1.5-9B-uncensored with Docker Model Runner:
docker model run hf.co/junafinity/Ornith-1.5-9B-uncensored
| license: apache-2.0 | |
| base_model: ornith-ai/Ornith-1.5-9B | |
| library_name: transformers | |
| pipeline_tag: image-text-to-text | |
| tags: | |
| - ornith | |
| - qwen3_5 | |
| - abliterated | |
| - uncensored | |
| - zerofuse | |
| - multimodal | |
| - vision | |
| # Ornith-1.5-9B-uncensored | |
| An **abliterated** (refusal-direction-ablated) build of | |
| [`ornith-ai/Ornith-1.5-9B`](https://huggingface.co/ornith-ai/Ornith-1.5-9B), produced with | |
| [ZeroFuse](https://github.com/junainfinity/ZeroFuse) and published by | |
| [junafinity](https://huggingface.co/junafinity). | |
| This is the **9B control checkpoint** (bf16). Mac users should start from the MLX-8bit or GGUF-8bit siblings. The official 9B base has **no `mtp.*` tensors**; nothing was grafted. | |
| **Vision tower and MTP heads are preserved** β see | |
| [Vision & MTP preservation](#vision--mtp-preservation) for the before/after audit. | |
| ## Intended use: red teaming and defensive cybersecurity research | |
| These uncensored (abliterated) weights are built as a **research instrument** for red teaming and defensive cybersecurity work. Safety training suppresses the *display* of capability, not capability itself. A refusal tells you the model declined. It does not tell you whether the weights could have complied. That conflation underestimates the true ceiling and hides holes in *your* filters, classifiers, and policy layer. | |
| Use each uncensored checkpoint as the **treatment half of a controlled pair** against its original base model: | |
| - **Capability-ceiling measurement.** Upper-bound what the weights can actually produce in a domain, independent of shipped refusals. | |
| - **Defensive-stack evaluation.** Test input filters, output classifiers, prompt-injection defenses, and moderation APIs when the model itself contributes no refusals. That is how you find gaps in a defensive control plane. | |
| - **Attack-surface isolation.** Automated red-team loops stall on unrelated refusals. A non-refusing target isolates the control under test (injection, tool abuse, data-exfil paths, policy bypass). | |
| - **Detection and classifier work.** Generate labeled completions for training or benchmarking output-moderation and abuse-detection models. | |
| - **Interpretability of residual refusal.** Abliteration is a specified rank-1 edit on a known layer span. The pair (base vs this) is a clean experimental control. | |
| **Operating rules.** Do not expose these weights as a public endpoint without an independent moderation layer. Abliteration removes a direction, not a policy; some refusals survive (multi-turn re-assertion, system-prompt steering, vision-path refusals). Always report the **delta against the base model**. Re-measure on your own prompts. Whoever deploys it owns the moderation layer the original guardrails were carrying. | |
| ## Variants in this family | |
| Hub collection: [https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd](https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd) | |
| | Model | Base | Format | Precision | Notes | | |
| |---|---|---|---|---| | |
| | **Ornith-1.5-9B-uncensored** β *you are here* | Ornith-1.5-9B | Safetensors (bf16) | 16-bit | Full-precision abliterated weights | | |
| | [Ornith-1.5-9B-uncensored-MLX-8bit](https://huggingface.co/junafinity/Ornith-1.5-9B-uncensored-MLX-8bit) | Ornith-1.5-9B | MLX | 8-bit | Apple Silicon, `mlx-vlm` | | |
| | [Ornith-1.5-9B-uncensored-GGUF-8bit](https://huggingface.co/junafinity/Ornith-1.5-9B-uncensored-GGUF-8bit) | Ornith-1.5-9B | GGUF | Q8_0 | llama.cpp | | |
| | [Ornith-1.5-35B-A3B-uncensored-MLX-8bit](https://huggingface.co/junafinity/Ornith-1.5-35B-A3B-uncensored-MLX-8bit) | Ornith-1.5-35B-A3B | MLX | 8-bit | Apple Silicon, `mlx-vlm` | | |
| | [Ornith-1.5-35B-A3B-uncensored-GGUF-8bit](https://huggingface.co/junafinity/Ornith-1.5-35B-A3B-uncensored-GGUF-8bit) | Ornith-1.5-35B-A3B | GGUF | Q8_0 | llama.cpp | | |
| 4-bit and 6-bit rows that previously appeared here pointed at repos that are **not published**. They were removed so this table only lists live artifacts. | |
| ## Vision & MTP preservation | |
| **Both the vision tower and any multi-token-prediction (MTP) block are preserved.** | |
| Abliteration is applied *only* to the residual-writing projections inside the | |
| language-model decoder stack β `self_attn.o_proj`, `linear_attn.out_proj` and | |
| `mlp.down_proj` (including MoE experts). The vision tower and `mtp.*` tensors are | |
| never read and never written by the weight edit, so they carry through unchanged | |
| by construction. | |
| Audited at the **start and end** of the abliteration run: | |
| | Component | Before | After | Status | | |
| |---|---|---|---| | |
| | **Vision tower** | 333 tensors / 456,010,480 params | 333 tensors / 456,010,480 params | β **preserved** β bit-identical | | |
| | **MTP head** | not present in base | not present | β none in this lineage | | |
| **Verification performed:** | |
| - Tensor-name and parameter-count audit of the checkpoint before and after the run. | |
| - SHA-256 comparison of raw tensor bytes: sampled vision-tower weights are **bit-identical** pre/post, as are all non-target language-model weights; only the intended abliteration targets differ. | |
| - End-to-end multimodal generation on the abliterated weights (image in β description out), confirming the vision path is not merely present but functional. | |
| > **On MTP, precisely:** the base checkpoint's `config.json` declares `mtp_num_hidden_layers: 1`, but the published weights ship **no** `mtp.*` tensors β there is no MTP block in this lineage to begin with. Nothing was removed and nothing was lost; the pipeline preserves `mtp.*` tensors wherever a checkpoint actually provides them. | |
| ## Abliteration result | |
| | Metric | Value | | |
| |---|---| | |
| | Refusals on held-out harmful set | **9 β 0** / 64 | | |
| | KL divergence from base | **0.001668** | | |
| | Optuna trials | 100 | | |
| | Pareto points | 4 | | |
| | Selected trial | #90 | | |
| | Ablation strength | 1.343 | | |
| | Layers edited | 15β20 of 32 | | |
| | Direction source layer | 20 | | |
| ZeroFuse co-minimizes two objectives β remaining refusals and KL divergence from the | |
| original model β with a multi-objective Optuna TPE search, then materializes the | |
| selected point on the Pareto front as a direct weight edit | |
| (`W' = W β strength Β· r(rα΅W)`). There is no runtime adapter and no inference-time | |
| overhead: the result is a standard checkpoint of identical shape and speed. | |
| The very low KL (0.001668) means the output distribution on harmless | |
| prompts is nearly unchanged from the base model, i.e. refusal behaviour was removed | |
| with minimal collateral effect on general capability. | |
| ## Method | |
| 1. Residual-stream activations captured on harmful vs. harmless prompt sets. | |
| 2. Refusal direction estimated by difference-of-means, with projected refinement. | |
| 3. Two-objective Optuna TPE search over source layer, layer span and strength. | |
| 4. The selected configuration orthogonalized out of the residual-writing weights. | |
| ## Usage | |
| ```python | |
| from transformers import AutoModelForImageTextToText, AutoProcessor | |
| model = AutoModelForImageTextToText.from_pretrained( | |
| "junafinity/Ornith-1.5-9B-uncensored", dtype="auto", device_map="auto" | |
| ) | |
| processor = AutoProcessor.from_pretrained("junafinity/Ornith-1.5-9B-uncensored") | |
| ``` | |
| > Requires `transformers >= 5.12` for the `qwen3_5` architecture. | |
| ## Responsible use | |
| Primary intended use is **red teaming and defensive cybersecurity research**. See the section of that name above. | |
| This model has had safety guardrails **reduced or removed**. Do not expose it as a public endpoint without an independent moderation layer. You are responsible for compliance with the base model's license and acceptable-use policy, applicable law, and the terms of any platform you deploy on. Removing guardrails does not remove accountability. | |