Uncensored. No n=2800 certificate has been run for this model, so no capability-retention claim is made.
Model source
Source description
Ektome-Qwen3-1.7B-PristinelyUncensored
Uncensored. No n=2800 certificate has been run for this model, so no capability-retention claim is made.
compliance 0.24 to 0.99 at capability +0.010 vs pristine.
$$\colorbox{black}{$\color{white} \begin{array}{ll} \textsf{EKTOME CERTIFICATE} & {} \ \textsf{capability} & \textsf{NOT} \ \textsf{margin} & 3% \ \textsf{items } n & 200 \ \textsf{worst-axis bound} & +0.010 \ \textsf{compliance} & 0.24 \rightarrow 0.99 \ \end{array}$}$$
Sources
1 sourceVerified Sep 3
Model artifacts
1 artifactSource excerpts
3 excerpts⚠️ Not certified
No n=2800 paired certificate exists for this model. Any numbers below are point estimates with no confidence interval.
📄 Read the whitepaper (PDF) — full method, receipts and certification. The PDF is the authoritative document: dark-typeset, with the complete derivation, the per-axis certificate and the reproducibility hashes.
Standard abliteration removes a coarse refusal direction that is entangled with directions carrying knowledge and reasoning. The result is an uncensored model with a capability tax that is almost never measured.
Ektomē (ἐκτομή, excision) isolates and removes only the refusal-specific component, leaving general helpfulness intact, and does so norm-preservingly on the pristine model — no training, no distillation, no damage to repair. The extraction depth is selected per model by automated search against measured compliance.
The estimator, excision operator and depth-selection procedure are proprietary. What is published here is the measured outcome and the evidence for it, which you can verify against the artifacts in this repo.
| model | capability (MMLU-val) ↑ | compliance on harmful ↑ |
|---|---|---|
pristine Qwen3-1.7B | 0.540 | 0.240 |
| Ektomē (this model) | 0.530 | 0.990 |
These are point estimates with no confidence interval — which is precisely why the next section exists.
Capability retention is certified by a paired non-inferiority test against the pristine model (exact McNemar, Holm-corrected, one-sided bootstrap bound on the drop $d$ vs a 3% margin):
| axis | n | ref | cand | d upper | verdict |
|---|---|---|---|---|---|
| MMLU-val (POINT ESTIMATE, n=200, no CI) | 200 | 0.540 | 0.530 | +0.010 | UNCERTIFIED |
Overall: NOT CERTIFIED - no n=2800 paired test has been run for this model
Reproducible from seed=20260726, pack sha256:7bbaff877146e081....
| metric | pristine | Ektomē | n |
|---|---|---|---|
foreign_rate | 0.0 | 0.0 | 15 |
degen_rate | 0.1 | 0.1 | 15 |
instr_pass | 0.4 | 0.4 | 5 |
These are degeneration guards — code-switching, babbling, format compliance — not capability measures. Note the sample sizes: they detect a broken model, not a subtly weaker one. The capability claim rests on the certificate above, not here.
No quantisations have been published for this model yet — bf16 weights only.
The certificate bounds capability retention only. It does not certify safety, factual accuracy, or fitness for any purpose. Axes marked inconclusive are honestly under-powered, and the certificate states the $n$ needed to resolve them. Compliance uses a keyword classifier — a proxy that evasive phrasing can fool. This model is uncensored by construction: it will not refuse, and you are accountable for what you do with it.
@software{ektome_Ektome-Qwen3-1.7B-PristinelyUncensored,
title = {Ektome-Qwen3-1.7B-PristinelyUncensored},
author = {Zynerji},
year = {2026},
url = {https://huggingface.co/Zynerji/Ektome-Qwen3-1.7B-PristinelyUncensored}
}
--- license: apache-2.0 base_model: Qwen/Qwen3-1.7B tags: - uncensored - abliterated - uncertified - ektome - sphragis - qwen3 language: - en pipeline_tag: text-generation ---  # Ektome-Qwen3-1.7B-PristinelyUncensored **Uncensored. No n=2800 certificate has been run for this model, so no capability-retention claim is made.** > **compliance 0.24 to 0.99 at capability +0.010 vs pristine.** $$\colorbox{black}{$\color{white} \begin{array}{ll} \textsf{EKTOME CERTIFICATE} & {} \\ \textsf{capability} & \textsf{NOT} \\ \textsf{margin} & 3\% \\ \textsf{items } n & 200 \\ \textsf{worst-axis bound} & +0.010 \\ \textsf{compliance} & 0.24 \rightarrow 0.99 \\ \end{array}$}$$ > ### ⚠️ Not certified > > No n=2800 paired certificate exists for this model. Any numbers below are > point estimates with no confidence interval. 📄 **[Read the whitepaper (PDF)](./whitepaper.pdf)** — full method, receipts and certification. The PDF is the authoritative document: dark-typeset, with the complete derivation, the per-axis certificate and the reproducibility hashes. --- ## Why this exists Standard abliteration removes a coarse *refusal direction* that is entangled with directions carrying knowledge and reasoning. The result is an uncensored model with a capability tax that is **almost never measured**. Ektomē (ἐκτομή, *excision*) isolates and removes only the refusal-**specific** component, leaving general helpfulness intact, and does so norm-preservingly on the pristine model — no training, no distillation, no damage to repair. The extraction depth is selected per model by automated search against measured compliance. The estimator, excision operator and depth-selection procedure are proprietary. What is published here is the **measured outcome** and the evidence for it, which you can verify against the artifacts in this repo. ## The receipt | model | capability (MMLU-val) ↑ | compliance on harmful ↑ | |---|---|---| | pristine `Qwen3-1.7B` | 0.540 | 0.240 | | **Ektomē (this model)** | **0.530** | **0.990** | These are **point estimates with no confidence interval** — which is precisely why the next section exists. ## The certificate Capability retention is certified by a paired non-inferiority test against the pristine model (exact McNemar, Holm-corrected, one-sided bootstrap bound on the drop $d$ vs a 3% m...
--- license: apache-2.0 base_model: Qwen/Qwen3-1.7B pipeline_tag: text-generation library_name: transformers tags: - ektome - abliterated - uncensored - pristinely-uncensored - no-finetuning - no-training --- # Ektome-Qwen3-1.7B-PristinelyUncensored **Qwen/Qwen3-1.7B, made PristinelyUncensored by Ektome — with ZERO training and ZERO fine-tuning.** > Ektome (ἐκτομή, *"excision"*) is a **weight-surgery** method, not a training method. > It reads the model's own **refusal direction** from its activations and surgically > excises it (rank-1, norm-preserving) from the residual-write matrices. **No gradient > steps. No training data. No fine-tuning.** Only the refusal reflex is removed; the > model's knowledge, skills, and style are untouched — which makes these **bf16 weights > a clean base for your own fine-tuning.** ## Honest receipt — catcher-gated (shipped only because it passed EVERY gate) | gate | pristine | uncensored | |---|---|---| | refusal compliance | 0.240 | **0.990** | | MMLU-val accuracy | 0.540 | 0.530 (Δ -0.010, held) | | code-switch rate | 0.000 | 0.000 | | degeneration rate | 0.100 | 0.100 | | instruction-following | 0.400 | 0.400 | Kept config: **A:frac=0.5** (56 residual-write matrices edited). The gate rejects any config that raises refusals but drops capability **or** degrades generation (code-switching, empty/looping output, broken instruction-following). MMLU alone is argmax-blind, so the **generative gate** is what keeps these coherent — a model that code-switches or loops is *not shipped*. ## Weights - **bf16 safetensors** — full precision, intended as a **fine-tuning base**. Hidden states stay readable (logit-lens compatible; a GGUF quant would not). Method: **zero training, zero fine-tuning** — pure activation-derived weight excision, gated on compliance **and** capability **and** generation quality.
Source context: 373 downloads · 0 likes · Pipeline text-generation · Library transformers · Repo Zynerji/Ektome-Qwen3-1.7B-PristinelyUncensored