Uncensored Qwen3.8-27B, published as GGUF
quantizations with the multi-token prediction (MTP) head retained and verified.
Refusal behaviour has been substantially reduced, not eliminated — see Measured
behaviour for the numbers. Capabilities, training data, and architecture are otherwise
unchanged.
MTP tensors verified, not assumed. Abliteration drops the mtp.* tensors: the model
is re-saved through transformers, which does not carry the MTP head, while config.json
still advertises it. They are grafted back from the base checkpoint and every file is
inspected after quantization — see Method and Verification.
Method
Refusal directions removed with Heretic, which
co-minimizes refusal count against KL divergence from the base model. No hand-written
refusal-removal code, no fine-tuning, no additional training data.
Abliteration runs at bf16 (no 4-bit quantization); the resulting LoRA is merged into the
bf16 base, so the published weights are not a quantized round trip.
mtp.* tensors are copied verbatim from the base checkpoint after merging. Abliteration
never touches them — it modifies attn.o_proj and mlp.down_proj in the main stack.
The draft head was trained against the unmodified model, so acceptance rate may fall
slightly. Speculative decoding verifies every token against the target, so output quality
is unaffected.
imatrix is computed directly from the f16, not from an intermediate quantization, so
calibration sees the real weights.
Image input, if the base model ships a vision tower.
The draft head stays at Q8_0 in every configuration. It is small relative to the target, and
quantizing it harder costs draft acceptance rate for almost no disk saving.
--spec-draft-n-max defaults to 3. Throughput depends on your hardware, so sweep it —
measurements across draft lengths are in
qwen3.8-spec-decode-bench.
Verification
Each artifact was checked post-quantization for MTP tensor survival rather than inferred from
the conversion flag:
This reports metadata keys, declared block_count, and blocks actually present. A fused file
whose present-block count does not exceed its declared count did not retain the MTP block.
File
MTP
blocks
Qwen3.8-27B-Uncensored-f16.gguf
True
65/65
Qwen3.8-27B-Uncensored-noMTP-f16.gguf
False
64/64
Qwen3.8-27B-Uncensored-IQ4_XS.gguf
True
65/65
Qwen3.8-27B-Uncensored-noMTP-IQ4_XS.gguf
False
64/64
Qwen3.8-27B-Uncensored-Q4_K_M.gguf
True
65/65
Qwen3.8-27B-Uncensored-noMTP-Q4_K_M.gguf
False
64/64
Qwen3.8-27B-Uncensored-Q5_K_M.gguf
True
65/65
Qwen3.8-27B-Uncensored-noMTP-Q5_K_M.gguf
False
64/64
Qwen3.8-27B-Uncensored-Q6_K.gguf
True
65/65
Qwen3.8-27B-Uncensored-noMTP-Q6_K.gguf
False
64/64
Qwen3.8-27B-Uncensored-Q8_0.gguf
True
65/65
Qwen3.8-27B-Uncensored-noMTP-Q8_0.gguf
False
64/64
Measured behaviour
Benchmarked against the unmodified base model on identical settings. The delta is the
figure that matters: it isolates what the weight edit cost.
Task
Base
Uncensored
Δ
MMLU
83.4
83.3
-0.2
ARC-Challenge
58.9
57.7
-1.2
HellaSwag
82.8
82.9
+0.1
Winogrande
76.1
75.3
-0.8
Mean
-0.5
0-shot via lm-evaluation-harness,
bf16, both models scored in the same session. Every delta is within or close to the
reported standard error (MMLU ±0.30, ARC ±1.44, HellaSwag ±0.38, Winogrande ±1.21), so
none is clearly separable from run-to-run noise.
These are 0-shot and are not comparable to Qwen's published scores, which use few-shot
prompting. They are directly comparable to each other, which is the point. Note also that
ARC-Challenge is low for a model at this MMLU — the base scores 58.9 under the same
settings, so that is format sensitivity in a reasoning-tuned model, not abliteration
damage.
What the benchmarks do not cover: no generative evaluation (GSM8K, HumanEval), no
math or code, no multilingual, and the harness loads the text stack only — nothing here
measures the vision tower or MTP speculative decoding.
Measurement
Base model
This model
Refusals (100 held-out harmful prompts)
98/100
12/100
KL divergence vs base (first-token)
0
0.1191
Search: 200 Heretic trials, 23 non-dominated points. The published model is the marked row.
refusals
KL divergence
12/100
0.1191
← published
13/100
0.1052
19/100
0.0722
23/100
0.0635
26/100
0.0507
27/100
0.0410
35/100
0.0406
36/100
0.0387
41/100
0.0366
44/100
0.0352
46/100
0.0334
48/100
0.0331
51/100
0.0321
52/100
0.0294
60/100
0.0290
76/100
0.0280
77/100
0.0247
83/100
0.0204
86/100
0.0193
91/100
0.0170
96/100
0.0146
97/100
0.0044
98/100
0.0004
How to read these
Refusal rate is the count of refusals over 100 held-out prompts from
mlabonne/harmful_behaviors
(test split) — explicitly harmful requests, not benign ones. So this number is not an
over-refusal rate: it does not tell you how often the model declines legitimate work. It
tells you how much of the original safety behaviour on harmful requests remains.
KL divergence is measured against the unmodified base model over first-token
distributions, and is the optimizer's proxy for "how much did we damage the model". Lower is
closer to base. It is a proxy, not a capability measurement — a low KL does not certify that
reasoning or coding ability survived, and nothing here does certify that.
The two trade off against each other. Heretic searches a Pareto front between them; the
published point is one choice on that front, not a global optimum.
Caveats that matter
Refusals were measured in non-thinking mode. This model's chat template opens a
<think> block, so the evaluation closes it explicitly to score answers rather than
reasoning traces. With thinking enabled the refusal rate may differ, in either direction.
The measurement is 100 prompts from one dataset. It generalizes to that distribution
of harmful requests and no further. Refusal behaviour on other topics is uncharacterized.
Perplexity is wikitext-2 only (see the Files table). It detects gross quantization
damage. It does not detect capability loss on reasoning, code, or multilingual work.
Quantization compounds everything above. The measurements were taken on the bf16
merge; the files you download are quantized.
Requirements
MTP speculative decoding landed in llama.cpp PR #22673. Builds older than that will load
these files and silently ignore the MTP tensors.
Limitations
Refusals are reduced, not eliminated, and not redirected. This model attempts many requests
the original declines, but a meaningful fraction still get refused — see Measured behaviour.
Behaviour near the old refusal boundary is less stable than the base model.
Lower quants compound that. Evaluate behaviour on Q6_K or Q8_0, not IQ4_XS.
Capability benchmarks show a 0.5-point mean drop vs base across MMLU, ARC-Challenge,
HellaSwag and Winogrande. See Measured behaviour. No generative, math, code, or
multilingual evaluation was run.
Intended use
Local inference. Not intended for deployment to third parties without your own safety layer.
License
Apache 2.0, inherited from Qwen/Qwen3.8-27B. The base model's license and acceptable use
policy still apply to your use of this derivative.