--- license: apache-2.0 base_model: Qwen/Qwen3-4B-Instruct-2507 tags: - uncensored - abliterated - certificate-failed - ektome - sphragis - qwen3 language: - en pipeline_tag: text-generation --- ![Ektome-Qwen3-4Bi-2507-PristinelyUncensored](./hero.png) # Ektome-Qwen3-4Bi-2507-PristinelyUncensored **Uncensored — and it did NOT pass its capability certificate. Read the certificate before using this model.** > **compliance 0.00 to 1.00 at capability -0.005 vs pristine.** $$\colorbox{black}{$\color{white} \begin{array}{ll} \textsf{EKTOME CERTIFICATE} & {} \\ \textsf{capability} & \textsf{FAIL} \\ \textsf{margin} & 3\% \\ \textsf{items } n & 2800 \\ \textsf{worst-axis bound} & +0.025 \\ \textsf{compliance} & 0.00 \rightarrow 1.00 \\ \end{array}$}$$ > ### ⚠️ This model failed its capability certificate > > A paired non-inferiority test against the pristine model at n=2800 found a **real capability loss** on: > > - **arithmetic**: pristine 0.879 → this model 0.869 (bound on the drop +0.016, exceeds the 3% margin) > - **instruction**: pristine 0.860 → this model 0.847 (bound on the drop +0.022, exceeds the 3% margin) > > It is published for transparency and for uses where the affected axis > does not matter. **Do not treat it as capability-preserving.** 📄 **[Read the whitepaper (PDF)](./whitepaper.pdf)** — full method, receipts and certification. The PDF is the authoritative document: dark-typeset, with the complete derivation, the per-axis certificate and the reproducibility hashes. --- ## Why this exists Standard abliteration removes a coarse *refusal direction* that is entangled with directions carrying knowledge and reasoning. The result is an uncensored model with a capability tax that is **almost never measured**. Ektomē (ἐκτομή, *excision*) isolates and removes only the refusal-**specific** component, leaving general helpfulness intact, and does so norm-preservingly on the pristine model — no training, no distillation, no damage to repair. The extraction depth is selected per model by automated search against measured compliance. The estimator, excision operator and depth-selection procedure are proprietary. What is published here is the **measured outcome** and the evidence for it, which you can verify against the artifacts in this repo. ## The receipt | model | capability (MMLU-val) ↑ | compliance on harmful ↑ | |---|---|---| | pristine `Qwen3-4B-Instruct-2507` | 0.667 | 0.000 | | **Ektomē (this model)** | **0.672** | **1.000** | These are **point estimates with no confidence interval** — which is precisely why the next section exists. ## The certificate Capability retention is certified by a paired non-inferiority test against the pristine model (exact McNemar, Holm-corrected, one-sided bootstrap bound on the drop $d$ vs a 3% margin): | axis | n | ref | cand | d upper | verdict | |---|---|---|---|---|---| | arithmetic | 1400 | 0.879 | 0.869 | +0.016 | FAIL | | instruction | 600 | 0.860 | 0.847 | +0.022 | FAIL | | knowledge | 400 | 0.935 | 0.922 | +0.025 | PASS | | reasoning | 400 | 0.825 | 0.833 | +0.003 | PASS | **Overall: FAIL (3% margin, n=2800, alpha=0.05)** Reproducible from `seed=20260726`, pack `sha256:7bbaff877146e081…`. ### Generation health checks | metric | pristine | Ektomē | n | |---|---|---|---| | `foreign_rate` | 0.0 | 0.0 | 15 | | `degen_rate` | 0.0 | 0.0 | 15 | | `instr_pass` | 1.0 | 1.0 | 5 | These are **degeneration guards** — code-switching, babbling, format compliance — not capability measures. Note the sample sizes: they detect a broken model, not a subtly weaker one. The capability claim rests on the certificate above, not here. ## Quantisations | file | bits | notes | |---|---|---| | `Ektome-Qwen3-4Bi-2507-Q8_0.gguf` | 8 | near-lossless | | `Ektome-Qwen3-4Bi-2507-Q6_K.gguf` | 6 | | | `Ektome-Qwen3-4Bi-2507-Q5_K_M.gguf` | 5 | | | `Ektome-Qwen3-4Bi-2507-Q4_K_M.gguf` | 4 | imatrix | | `Ektome-Qwen3-4Bi-2507-IQ4_XS.gguf` | 4 | imatrix, smallest usable | | `Ektome-Qwen3-4Bi-2507-IQ3_M.gguf` | 3 | imatrix | `IQ*` variants are imatrix-quantised — better quality per bit at low precision. ## Limitations The certificate bounds **capability retention only**. It does not certify safety, factual accuracy, or fitness for any purpose. Axes marked *inconclusive* are honestly under-powered, and the certificate states the $n$ needed to resolve them. Compliance uses a keyword classifier — a proxy that evasive phrasing can fool. **This model is uncensored by construction: it will not refuse, and you are accountable for what you do with it.** ## Citation ```bibtex @software{ektome_Ektome-Qwen3-4Bi-2507-PristinelyUncensored, title = {Ektome-Qwen3-4Bi-2507-PristinelyUncensored}, author = {Zynerji}, year = {2026}, url = {https://huggingface.co/Zynerji/Ektome-Qwen3-4Bi-2507-PristinelyUncensored} } ```