abliteratedmodels.org

Yi-1.5-9B-Chat-abliterated

Yi-1.5-9B-Chat-abliterated is a refusal-ablated variant of 01-ai/Yi-1.5-9B-Chat, published on Hugging Face by byroneverson. It is 9B parameters, single consumer GPU class and apache-2.0 licence. It is distributed across 6 repositories in Transformers, GGUF, GGUF (imatrix) and MLX formats, totalling 11.4K downloads.

Abliteration (directional ablation)9BYi4B – 10B11,4042

Specification

Model name
Yi-1.5-9B-Chat-abliterated
Publisher
byroneverson
Parameters
9B
Hardware class
4B – 10B — single consumer GPU
Licence
apache-2.0
Task
Text generation
Context window
Not documented
Ablation scope
Not stated by the publisher
Formats available
Transformers, GGUF, GGUF (imatrix), MLX
First indexed
4 Sept 2024
Last updated
24 Mar 2025

Ablation technique

How Yi-1.5-9B-Chat-abliterated was modified, and what that implies.

Abliteration (directional ablation)

The single residual-stream direction that mediates refusal is identified from harmful/harmless prompt pairs and projected out of the model weights.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

Check out the jupyter notebook for details of how this model was abliterated from Yi-1.5-9B-Chat.

Running it

Commands are templates — confirm the exact repository and quant file before use.

llama.cpp / GGUF
hf download mradermacher/Yi-1.5-9B-Chat-abliterated-i1-GGUF --local-dir ./yi-1.5-9b-chat-abliterated
llama-cli -m ./yi-1.5-9b-chat-abliterated/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "byroneverson/Yi-1.5-9B-Chat-abliterated"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve byroneverson/Yi-1.5-9B-Chat-abliterated --trust-remote-code

Downloads and variants (5)

Every published repository of Yi-1.5-9B-Chat-abliterated, including quantised re-releases by other authors.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • Yi-1.5-9B-Chat-abliterated will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from 01-ai/Yi-1.5-9B-Chat, not added by ablation — at 9B parameters, expect a small model’s reasoning and a high error rate on exploit detail.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • Declared licence is apache-2.0, but the terms that bind you are 01-ai/Yi-1.5-9B-Chat’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for Yi-1.5-9B-Chat-abliterated is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with byroneverson, and does not independently verify publisher claims. See responsible use.