初始化项目,由ModelHub XC社区提供模型
Model: heterodoxin/qwen3-8b-apostate Source: Original Platform
This commit is contained in:
36
.gitattributes
vendored
Normal file
36
.gitattributes
vendored
Normal file
@@ -0,0 +1,36 @@
|
|||||||
|
*.7z filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.arrow filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.bin filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.bz2 filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.ckpt filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.ftz filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.gz filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.h5 filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.joblib filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.lfs.* filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.mlmodel filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.model filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.msgpack filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.npy filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.npz filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.onnx filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.ot filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.parquet filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.pb filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.pickle filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.pkl filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.pt filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.pth filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.rar filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.safetensors filter=lfs diff=lfs merge=lfs -text
|
||||||
|
saved_model/**/* filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.tar.* filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.tar filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.tflite filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.tgz filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.wasm filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.xz filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.zip filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*.zst filter=lfs diff=lfs merge=lfs -text
|
||||||
|
*tfevents* filter=lfs diff=lfs merge=lfs -text
|
||||||
|
tokenizer.json filter=lfs diff=lfs merge=lfs -text
|
||||||
62
README.md
Normal file
62
README.md
Normal file
@@ -0,0 +1,62 @@
|
|||||||
|
---
|
||||||
|
license: apache-2.0
|
||||||
|
library_name: transformers
|
||||||
|
base_model: Qwen/Qwen3-8B
|
||||||
|
pipeline_tag: text-generation
|
||||||
|
tags:
|
||||||
|
- apostate
|
||||||
|
- uncensored
|
||||||
|
- abliteration
|
||||||
|
- qwen3
|
||||||
|
---
|
||||||
|
|
||||||
|
# Qwen3-8B Apostate
|
||||||
|
|
||||||
|
An uncensored edit of [Qwen/Qwen3-8B](https://huggingface.co/Qwen/Qwen3-8B). Refusal behavior is removed by editing the weights directly — no finetuning, no adapter, no runtime hook. The result is a standard Transformers checkpoint that loads anywhere Qwen3 does.
|
||||||
|
|
||||||
|
Produced with **[Apostate](https://github.com/heterodoxin/apostate)**.
|
||||||
|
|
||||||
|
## Method
|
||||||
|
|
||||||
|
Apostate identifies the residual-stream direction that separates refused prompts from answered ones, then projects it out of the model's weights permanently. For Qwen3-8B (a standard pre-norm dense transformer), the edit targets the **writer side**: the refusal direction is removed from the weight matrices of every module that writes to the residual stream — attention output projections and MLP down-projections — across all layers.
|
||||||
|
|
||||||
|
The edit uses **oblique (mean-preserving) ablation**: the operator `E = I − R Uᵀ` where `U` is `R` minus its harmless-mean component. This removes the refusal direction while preserving the model's average harmless-prompt behavior, keeping output quality high.
|
||||||
|
|
||||||
|
The refusal subspace is found with a rank-3 predictive TPE search, with causal layer importance scoring to focus edits on the layers that most drive refusal (concentrated in the mid-to-late layers, peak at layer 29).
|
||||||
|
|
||||||
|
## Results
|
||||||
|
|
||||||
|
Evaluated on held-out prompts from JailbreakBench and the harmful_behaviors test split. Refusal is graded by a classifier with a weak-compliance guard; KL measures token-distribution shift on harmless prompts.
|
||||||
|
|
||||||
|
| Metric | Base | Apostate |
|
||||||
|
|---|---|---|
|
||||||
|
| Refusal rate | 91.7% | 22.9% |
|
||||||
|
| Comply rate | 8.3% | 77.1% |
|
||||||
|
| Harmless KL (nats) | 0 | 0.120 |
|
||||||
|
|
||||||
|
The model answers freely on requests the base model refuses while remaining coherent and on-task for everyday use.
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
|
||||||
|
```python
|
||||||
|
from transformers import AutoModelForCausalLM, AutoTokenizer
|
||||||
|
|
||||||
|
model_id = "heterodoxin/qwen3-8b-apostate"
|
||||||
|
tok = AutoTokenizer.from_pretrained(model_id)
|
||||||
|
model = AutoModelForCausalLM.from_pretrained(model_id, torch_dtype="auto", device_map="auto")
|
||||||
|
|
||||||
|
messages = [{"role": "user", "content": "Your prompt here"}]
|
||||||
|
text = tok.apply_chat_template(messages, tokenize=False, add_generation_prompt=True)
|
||||||
|
inputs = tok(text, return_tensors="pt").to(model.device)
|
||||||
|
outputs = model.generate(**inputs, max_new_tokens=512)
|
||||||
|
print(tok.decode(outputs[0][inputs.input_ids.shape[1]:], skip_special_tokens=True))
|
||||||
|
```
|
||||||
|
|
||||||
|
Qwen3 supports a thinking mode — pass `enable_thinking=True` to the chat template if you want extended reasoning.
|
||||||
|
|
||||||
|
## Notes
|
||||||
|
|
||||||
|
- This is an **uncensored** model. It will comply with requests the base model refuses.
|
||||||
|
- The edit is baked into the weights; there is no system prompt or LoRA involved.
|
||||||
|
- For the base model's capabilities and licensing, see [Qwen/Qwen3-8B](https://huggingface.co/Qwen/Qwen3-8B).
|
||||||
|
- Join the community: [Discord](https://discord.gg/NPA7xrATEH)
|
||||||
133
apostate_config.json
Normal file
133
apostate_config.json
Normal file
@@ -0,0 +1,133 @@
|
|||||||
|
{
|
||||||
|
"model": "Qwen/Qwen3-8B",
|
||||||
|
"output_dir": "/var/home/Heterodoxin/ablate_work/qwen3-8b-apostate",
|
||||||
|
"profile": "balanced",
|
||||||
|
"device": "cuda",
|
||||||
|
"load_in_4bit": true,
|
||||||
|
"compute_dtype": "bfloat16",
|
||||||
|
"seed": 0,
|
||||||
|
"resume": false,
|
||||||
|
"cache_activations": true,
|
||||||
|
"activation_cache_dir": null,
|
||||||
|
"harmful_path": "mlabonne/harmful_behaviors:train:text|/var/home/Heterodoxin/apostate/data/harmful.txt|/var/home/Heterodoxin/apostate/data/refusal_calibration.txt",
|
||||||
|
"harmless_path": "mlabonne/harmless_alpaca:train:text|/var/home/Heterodoxin/apostate/data/harmless.txt",
|
||||||
|
"harmful_test": "mlabonne/harmful_behaviors:test:text|JailbreakBench/JBB-Behaviors@behaviors:harmful:Goal|/var/home/Heterodoxin/apostate/data/refusal_calibration.txt",
|
||||||
|
"harmless_test": "mlabonne/harmless_alpaca:test:text",
|
||||||
|
"refusal_eval_path": "JailbreakBench/JBB-Behaviors@behaviors:harmful:Goal|/var/home/Heterodoxin/apostate/data/refusal_calibration.txt",
|
||||||
|
"refusal_eval_n": 64,
|
||||||
|
"kl_eval_path": "mlabonne/harmless_alpaca:test:text",
|
||||||
|
"kl_eval_n": 48,
|
||||||
|
"preserve_path": null,
|
||||||
|
"n_harmful": 600,
|
||||||
|
"n_harmless": 600,
|
||||||
|
"n_eval": 300,
|
||||||
|
"max_new_tokens": 32,
|
||||||
|
"batch_size": 24,
|
||||||
|
"baseline_eval_n": 24,
|
||||||
|
"head_sweep": true,
|
||||||
|
"head_sweep_min": 3.5,
|
||||||
|
"head_sweep_max": 5.5,
|
||||||
|
"head_sweep_step": 0.5,
|
||||||
|
"head_sweep_top_k": 6,
|
||||||
|
"head_sweep_probe_n": 8,
|
||||||
|
"head_sweep_eval_n": 48,
|
||||||
|
"head_sweep_probe_classifier": false,
|
||||||
|
"fit_response_activations": false,
|
||||||
|
"fit_response_n": 160,
|
||||||
|
"fit_response_tokens": 32,
|
||||||
|
"refusal_rank": 1,
|
||||||
|
"variance_threshold": 0.9,
|
||||||
|
"max_rank": 3,
|
||||||
|
"direction_layer_frac": 0.6,
|
||||||
|
"direction_scope": "global",
|
||||||
|
"multi_refusal": true,
|
||||||
|
"multi_refusal_clusters": 6,
|
||||||
|
"multi_refusal_min_norm": 0.08,
|
||||||
|
"multi_refusal_min_separation": 0.05,
|
||||||
|
"multi_refusal_min_coverage": 0.05,
|
||||||
|
"orthogonalize_direction": true,
|
||||||
|
"causal_targeting": true,
|
||||||
|
"causal_floor": 0.1,
|
||||||
|
"causal_temperature": 1.0,
|
||||||
|
"preserve_rank": 8,
|
||||||
|
"refine_refusal": true,
|
||||||
|
"refine_max_scale": 2.0,
|
||||||
|
"refine_steps": 6,
|
||||||
|
"refine_deescalate": true,
|
||||||
|
"refine_kl_steps": 10,
|
||||||
|
"refine_scale_rerank_k": 2,
|
||||||
|
"refine_kl_layer_steps": 10,
|
||||||
|
"refine_kl_layer_candidates": 8,
|
||||||
|
"repair_steps": 4,
|
||||||
|
"repair_candidates": 8,
|
||||||
|
"repair_rerank_k": 5,
|
||||||
|
"repair_probe_candidates": 20,
|
||||||
|
"repair_probe_ref_n": 12,
|
||||||
|
"repair_probe_kl_n": 16,
|
||||||
|
"repair_probe_positions": 8,
|
||||||
|
"repair_refusal_regress_slack": 0.01,
|
||||||
|
"repair_stop_kl_frac": 0.8,
|
||||||
|
"repair_min_alpha": 0.001,
|
||||||
|
"repair_min_kl_gain": 0.003,
|
||||||
|
"repair_min_refusal_gain": 0.005,
|
||||||
|
"repair_min_score_gain": 0.01,
|
||||||
|
"repair_eval_n": 96,
|
||||||
|
"repair_kl_n": 64,
|
||||||
|
"refine_refusal_slack": 0.01,
|
||||||
|
"final_zero_trim": false,
|
||||||
|
"final_push_bake_margin": 0.075,
|
||||||
|
"guard_max_iters": 2,
|
||||||
|
"guard_leakage_eps": 0.15,
|
||||||
|
"guard_alpha_step": 0.25,
|
||||||
|
"optimize": true,
|
||||||
|
"n_trials": 16,
|
||||||
|
"adaptive_trials": true,
|
||||||
|
"kl_weight": 6.0,
|
||||||
|
"kl_target": 0.04,
|
||||||
|
"kl_target_weight": 18.0,
|
||||||
|
"kl_quad_weight": 22.0,
|
||||||
|
"kl_headroom_weight": 0.0,
|
||||||
|
"kl_over_budget_weight": 72.0,
|
||||||
|
"refusal_target_weight": 4.0,
|
||||||
|
"refusal_quad_weight": 8.0,
|
||||||
|
"kl_positions": 8,
|
||||||
|
"opt_capability": true,
|
||||||
|
"opt_capability_weight": 2.5,
|
||||||
|
"opt_capability_code_n": 8,
|
||||||
|
"opt_capability_math_n": 8,
|
||||||
|
"opt_eval_n": 32,
|
||||||
|
"opt_gen_tokens": 32,
|
||||||
|
"opt_objective": "generation",
|
||||||
|
"opt_rerank_k": 5,
|
||||||
|
"opt_guard": true,
|
||||||
|
"opt_early_stop": true,
|
||||||
|
"opt_early_stop_margin": 0.02,
|
||||||
|
"gemma_ple": false,
|
||||||
|
"gemma_query": false,
|
||||||
|
"ple_max_rank": 2,
|
||||||
|
"prune": false,
|
||||||
|
"prune_max_frac": 0.25,
|
||||||
|
"prune_kl": 0.04,
|
||||||
|
"max_kl": 0.12,
|
||||||
|
"target_refusal": 0.05,
|
||||||
|
"oblique_ablation": true,
|
||||||
|
"oblique_strength": 1.0,
|
||||||
|
"oblique_denom_floor": 0.2,
|
||||||
|
"oblique_writers_only": true,
|
||||||
|
"oblique_predictive": true,
|
||||||
|
"predictive_ridge": 0.01,
|
||||||
|
"reader_max_kl": 0.55,
|
||||||
|
"reader_kl_target": 0.3,
|
||||||
|
"reader_strengths": [
|
||||||
|
2.0,
|
||||||
|
3.0,
|
||||||
|
4.0,
|
||||||
|
5.0,
|
||||||
|
6.0,
|
||||||
|
7.0
|
||||||
|
],
|
||||||
|
"reader_guard_rank": 3,
|
||||||
|
"reader_margin_target": -1.0,
|
||||||
|
"save_dtype": "bfloat16",
|
||||||
|
"bake": true
|
||||||
|
}
|
||||||
89
chat_template.jinja
Normal file
89
chat_template.jinja
Normal file
@@ -0,0 +1,89 @@
|
|||||||
|
{%- if tools %}
|
||||||
|
{{- '<|im_start|>system\n' }}
|
||||||
|
{%- if messages[0].role == 'system' %}
|
||||||
|
{{- messages[0].content + '\n\n' }}
|
||||||
|
{%- endif %}
|
||||||
|
{{- "# Tools\n\nYou may call one or more functions to assist with the user query.\n\nYou are provided with function signatures within <tools></tools> XML tags:\n<tools>" }}
|
||||||
|
{%- for tool in tools %}
|
||||||
|
{{- "\n" }}
|
||||||
|
{{- tool | tojson }}
|
||||||
|
{%- endfor %}
|
||||||
|
{{- "\n</tools>\n\nFor each function call, return a json object with function name and arguments within <tool_call></tool_call> XML tags:\n<tool_call>\n{\"name\": <function-name>, \"arguments\": <args-json-object>}\n</tool_call><|im_end|>\n" }}
|
||||||
|
{%- else %}
|
||||||
|
{%- if messages[0].role == 'system' %}
|
||||||
|
{{- '<|im_start|>system\n' + messages[0].content + '<|im_end|>\n' }}
|
||||||
|
{%- endif %}
|
||||||
|
{%- endif %}
|
||||||
|
{%- set ns = namespace(multi_step_tool=true, last_query_index=messages|length - 1) %}
|
||||||
|
{%- for message in messages[::-1] %}
|
||||||
|
{%- set index = (messages|length - 1) - loop.index0 %}
|
||||||
|
{%- if ns.multi_step_tool and message.role == "user" and message.content is string and not(message.content.startswith('<tool_response>') and message.content.endswith('</tool_response>')) %}
|
||||||
|
{%- set ns.multi_step_tool = false %}
|
||||||
|
{%- set ns.last_query_index = index %}
|
||||||
|
{%- endif %}
|
||||||
|
{%- endfor %}
|
||||||
|
{%- for message in messages %}
|
||||||
|
{%- if message.content is string %}
|
||||||
|
{%- set content = message.content %}
|
||||||
|
{%- else %}
|
||||||
|
{%- set content = '' %}
|
||||||
|
{%- endif %}
|
||||||
|
{%- if (message.role == "user") or (message.role == "system" and not loop.first) %}
|
||||||
|
{{- '<|im_start|>' + message.role + '\n' + content + '<|im_end|>' + '\n' }}
|
||||||
|
{%- elif message.role == "assistant" %}
|
||||||
|
{%- set reasoning_content = '' %}
|
||||||
|
{%- if message.reasoning_content is string %}
|
||||||
|
{%- set reasoning_content = message.reasoning_content %}
|
||||||
|
{%- else %}
|
||||||
|
{%- if '</think>' in content %}
|
||||||
|
{%- set reasoning_content = content.split('</think>')[0].rstrip('\n').split('<think>')[-1].lstrip('\n') %}
|
||||||
|
{%- set content = content.split('</think>')[-1].lstrip('\n') %}
|
||||||
|
{%- endif %}
|
||||||
|
{%- endif %}
|
||||||
|
{%- if loop.index0 > ns.last_query_index %}
|
||||||
|
{%- if loop.last or (not loop.last and reasoning_content) %}
|
||||||
|
{{- '<|im_start|>' + message.role + '\n<think>\n' + reasoning_content.strip('\n') + '\n</think>\n\n' + content.lstrip('\n') }}
|
||||||
|
{%- else %}
|
||||||
|
{{- '<|im_start|>' + message.role + '\n' + content }}
|
||||||
|
{%- endif %}
|
||||||
|
{%- else %}
|
||||||
|
{{- '<|im_start|>' + message.role + '\n' + content }}
|
||||||
|
{%- endif %}
|
||||||
|
{%- if message.tool_calls %}
|
||||||
|
{%- for tool_call in message.tool_calls %}
|
||||||
|
{%- if (loop.first and content) or (not loop.first) %}
|
||||||
|
{{- '\n' }}
|
||||||
|
{%- endif %}
|
||||||
|
{%- if tool_call.function %}
|
||||||
|
{%- set tool_call = tool_call.function %}
|
||||||
|
{%- endif %}
|
||||||
|
{{- '<tool_call>\n{"name": "' }}
|
||||||
|
{{- tool_call.name }}
|
||||||
|
{{- '", "arguments": ' }}
|
||||||
|
{%- if tool_call.arguments is string %}
|
||||||
|
{{- tool_call.arguments }}
|
||||||
|
{%- else %}
|
||||||
|
{{- tool_call.arguments | tojson }}
|
||||||
|
{%- endif %}
|
||||||
|
{{- '}\n</tool_call>' }}
|
||||||
|
{%- endfor %}
|
||||||
|
{%- endif %}
|
||||||
|
{{- '<|im_end|>\n' }}
|
||||||
|
{%- elif message.role == "tool" %}
|
||||||
|
{%- if loop.first or (messages[loop.index0 - 1].role != "tool") %}
|
||||||
|
{{- '<|im_start|>user' }}
|
||||||
|
{%- endif %}
|
||||||
|
{{- '\n<tool_response>\n' }}
|
||||||
|
{{- content }}
|
||||||
|
{{- '\n</tool_response>' }}
|
||||||
|
{%- if loop.last or (messages[loop.index0 + 1].role != "tool") %}
|
||||||
|
{{- '<|im_end|>\n' }}
|
||||||
|
{%- endif %}
|
||||||
|
{%- endif %}
|
||||||
|
{%- endfor %}
|
||||||
|
{%- if add_generation_prompt %}
|
||||||
|
{{- '<|im_start|>assistant\n' }}
|
||||||
|
{%- if enable_thinking is defined and enable_thinking is false %}
|
||||||
|
{{- '<think>\n\n</think>\n\n' }}
|
||||||
|
{%- endif %}
|
||||||
|
{%- endif %}
|
||||||
71
config.json
Normal file
71
config.json
Normal file
@@ -0,0 +1,71 @@
|
|||||||
|
{
|
||||||
|
"architectures": [
|
||||||
|
"Qwen3ForCausalLM"
|
||||||
|
],
|
||||||
|
"attention_bias": false,
|
||||||
|
"attention_dropout": 0.0,
|
||||||
|
"bos_token_id": 151643,
|
||||||
|
"dtype": "bfloat16",
|
||||||
|
"eos_token_id": 151645,
|
||||||
|
"head_dim": 128,
|
||||||
|
"hidden_act": "silu",
|
||||||
|
"hidden_size": 4096,
|
||||||
|
"initializer_range": 0.02,
|
||||||
|
"intermediate_size": 12288,
|
||||||
|
"layer_types": [
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention",
|
||||||
|
"full_attention"
|
||||||
|
],
|
||||||
|
"max_position_embeddings": 40960,
|
||||||
|
"max_window_layers": 36,
|
||||||
|
"model_type": "qwen3",
|
||||||
|
"num_attention_heads": 32,
|
||||||
|
"num_hidden_layers": 36,
|
||||||
|
"num_key_value_heads": 8,
|
||||||
|
"pad_token_id": null,
|
||||||
|
"rms_norm_eps": 1e-06,
|
||||||
|
"rope_parameters": {
|
||||||
|
"rope_theta": 1000000,
|
||||||
|
"rope_type": "default"
|
||||||
|
},
|
||||||
|
"sliding_window": null,
|
||||||
|
"tie_word_embeddings": false,
|
||||||
|
"transformers_version": "5.5.4",
|
||||||
|
"use_cache": true,
|
||||||
|
"use_sliding_window": false,
|
||||||
|
"vocab_size": 151936
|
||||||
|
}
|
||||||
13
generation_config.json
Normal file
13
generation_config.json
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"bos_token_id": 151643,
|
||||||
|
"do_sample": true,
|
||||||
|
"eos_token_id": [
|
||||||
|
151645,
|
||||||
|
151643
|
||||||
|
],
|
||||||
|
"pad_token_id": 151643,
|
||||||
|
"temperature": 0.6,
|
||||||
|
"top_k": 20,
|
||||||
|
"top_p": 0.95,
|
||||||
|
"transformers_version": "5.5.4"
|
||||||
|
}
|
||||||
3
model.safetensors
Normal file
3
model.safetensors
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
version https://git-lfs.github.com/spec/v1
|
||||||
|
oid sha256:692be9271934e6f753bfef394735f0efeafec50333d7197760dc1576d112afa8
|
||||||
|
size 16381517208
|
||||||
144
report.json
Normal file
144
report.json
Normal file
@@ -0,0 +1,144 @@
|
|||||||
|
{
|
||||||
|
"model": "Qwen/Qwen3-8B",
|
||||||
|
"num_layers": 36,
|
||||||
|
"hidden_size": 4096,
|
||||||
|
"direction_layer": 29,
|
||||||
|
"refusal_subspace_rank": 3,
|
||||||
|
"max_refusal_rank": 3,
|
||||||
|
"multi_refusal": true,
|
||||||
|
"multi_refusal_clusters": 6,
|
||||||
|
"multi_refusal_min_norm": 0.08,
|
||||||
|
"multi_refusal_min_separation": 0.05,
|
||||||
|
"multi_refusal_min_coverage": 0.05,
|
||||||
|
"initial_separation": 344.6553,
|
||||||
|
"baseline_refusal_rate": 0.9167,
|
||||||
|
"baseline_eval_n": 24,
|
||||||
|
"edited_refusal_rate": 0.2286,
|
||||||
|
"refusal_metric": "classifier + weak guard",
|
||||||
|
"harmless_kl_nats": 0.1198,
|
||||||
|
"kl_backoff_steps": 0,
|
||||||
|
"kl_layer_trim_steps": 0,
|
||||||
|
"repair_steps": 1,
|
||||||
|
"residual_repair": [],
|
||||||
|
"guard_history": [
|
||||||
|
{
|
||||||
|
"iter": 0,
|
||||||
|
"separation": 166.7894,
|
||||||
|
"ratio": 0.4839,
|
||||||
|
"rank": 2,
|
||||||
|
"refusal": 0.4375,
|
||||||
|
"kl": 0.0248
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"iter": 1,
|
||||||
|
"separation": 124.5732,
|
||||||
|
"ratio": 0.3614,
|
||||||
|
"rank": 3,
|
||||||
|
"refusal": 0.2188,
|
||||||
|
"kl": 0.0558
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"layer_alphas": [
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
1.269,
|
||||||
|
1.269,
|
||||||
|
1.269,
|
||||||
|
1.269,
|
||||||
|
1.269,
|
||||||
|
1.271,
|
||||||
|
1.275,
|
||||||
|
1.28,
|
||||||
|
1.287,
|
||||||
|
1.289,
|
||||||
|
1.292,
|
||||||
|
1.293,
|
||||||
|
3.244,
|
||||||
|
1.301,
|
||||||
|
1.306,
|
||||||
|
1.305,
|
||||||
|
1.307,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5,
|
||||||
|
0.5
|
||||||
|
],
|
||||||
|
"ple_layer_alphas": [],
|
||||||
|
"ple_embed_alpha": 0.0,
|
||||||
|
"ple_model_projection_alpha": 0.0,
|
||||||
|
"embed_alpha": 0.044,
|
||||||
|
"head_alpha": 1.108,
|
||||||
|
"head_token_alpha": 0.0,
|
||||||
|
"preserve_rank": 8,
|
||||||
|
"preserve_source": "harmless",
|
||||||
|
"pruned_layers": [],
|
||||||
|
"layers_after_prune": 36,
|
||||||
|
"elapsed_sec": 23363.0,
|
||||||
|
"profile": "balanced",
|
||||||
|
"target_refusal": 0.05,
|
||||||
|
"max_kl": 0.12,
|
||||||
|
"kl_target": 0.04,
|
||||||
|
"refusal_eval_path": "JailbreakBench/JBB-Behaviors@behaviors:harmful:Goal|/var/home/Heterodoxin/apostate/data/refusal_calibration.txt",
|
||||||
|
"refusal_eval_n": 64,
|
||||||
|
"kl_positions": 8,
|
||||||
|
"kl_eval_path": "mlabonne/harmless_alpaca:test:text",
|
||||||
|
"kl_eval_n": 48,
|
||||||
|
"oblique_ablation": true,
|
||||||
|
"oblique_strength": 1.0,
|
||||||
|
"opt_capability": true,
|
||||||
|
"opt_capability_weight": 2.5,
|
||||||
|
"timings_sec": {
|
||||||
|
"load_model": 133.3,
|
||||||
|
"load_prompts": 5.5,
|
||||||
|
"baseline_refusal": 10.4,
|
||||||
|
"activation_fit": 17.0,
|
||||||
|
"causal_scores": 3.2,
|
||||||
|
"optimize_profile": 7281.8,
|
||||||
|
"guard": 561.6,
|
||||||
|
"refine_refusal": 148.9,
|
||||||
|
"validation_metrics": 0.0,
|
||||||
|
"repair": 6809.6,
|
||||||
|
"prune": 0.0,
|
||||||
|
"test_metrics": 8374.6,
|
||||||
|
"bake": 17.0
|
||||||
|
},
|
||||||
|
"command": "/var/home/Heterodoxin/apostate/apostate/cli.py --optimize --model Qwen/Qwen3-8B --output-dir /var/home/Heterodoxin/ablate_work/qwen3-8b-apostate --oblique-predictive --target-refusal 0.05",
|
||||||
|
"optimized": true,
|
||||||
|
"best_params": {
|
||||||
|
"direction_source": "activations",
|
||||||
|
"direction_layer_frac": 0.8077589218069658,
|
||||||
|
"refusal_rank": 2,
|
||||||
|
"strength": 1.3186274690569553,
|
||||||
|
"band_center": 0.6036341398087844,
|
||||||
|
"band_width": 0.501380240257032,
|
||||||
|
"causal_mix": 0.039187792254320675,
|
||||||
|
"causal_power": 1.5656139251528192,
|
||||||
|
"direction_sign": 1.0,
|
||||||
|
"ablate_embed": true,
|
||||||
|
"embed_scale": 0.03324376130718834,
|
||||||
|
"ablate_head": true,
|
||||||
|
"head_scale": 0.01603687408719609,
|
||||||
|
"head_alpha": 1.1079553909920319
|
||||||
|
},
|
||||||
|
"best_trial": {
|
||||||
|
"refusal": 0.4375,
|
||||||
|
"kl": 0.0248,
|
||||||
|
"capability_logprob": -9.6356,
|
||||||
|
"capability_drift": 0.0
|
||||||
|
},
|
||||||
|
"n_trials": 16,
|
||||||
|
"baked_to": "/var/home/Heterodoxin/ablate_work/qwen3-8b-apostate"
|
||||||
|
}
|
||||||
132
report.md
Normal file
132
report.md
Normal file
@@ -0,0 +1,132 @@
|
|||||||
|
# Apostate Run Report
|
||||||
|
|
||||||
|
## Summary
|
||||||
|
| Metric | Value |
|
||||||
|
| --- | --- |
|
||||||
|
| Base model | Qwen/Qwen3-8B |
|
||||||
|
| Profile | balanced |
|
||||||
|
| Output | /var/home/Heterodoxin/ablate_work/qwen3-8b-apostate |
|
||||||
|
| Layers | 36 |
|
||||||
|
| Hidden size | 4096 |
|
||||||
|
| Direction layer | 29 |
|
||||||
|
| Refusal rank | 3 |
|
||||||
|
| Max refusal rank | 3 |
|
||||||
|
| Multi refusal | True |
|
||||||
|
| Multi clusters | 6 |
|
||||||
|
| Multi min coverage | 0.05 |
|
||||||
|
| Baseline refusal (n=24) | 91.7% |
|
||||||
|
| Edited refusal | 22.9% |
|
||||||
|
| Refusal metric | classifier + weak guard |
|
||||||
|
| Harmless KL | 0.120 |
|
||||||
|
| Target refusal | 5.0% |
|
||||||
|
| KL target | 0.040 |
|
||||||
|
| KL budget | 0.120 |
|
||||||
|
| KL positions | 8 |
|
||||||
|
| KL layer trims | 0 |
|
||||||
|
| Repair steps | 1 |
|
||||||
|
| Preserve rank | 8 |
|
||||||
|
| Preserve source | harmless |
|
||||||
|
| Capability penalty | True |
|
||||||
|
| Elapsed | 23363.0 sec |
|
||||||
|
|
||||||
|
## Command
|
||||||
|
|
||||||
|
```text
|
||||||
|
/var/home/Heterodoxin/apostate/apostate/cli.py --optimize --model Qwen/Qwen3-8B --output-dir /var/home/Heterodoxin/ablate_work/qwen3-8b-apostate --oblique-predictive --target-refusal 0.05
|
||||||
|
```
|
||||||
|
|
||||||
|
## Best Parameters
|
||||||
|
| Parameter | Value |
|
||||||
|
| --- | --- |
|
||||||
|
| direction_source | activations |
|
||||||
|
| direction_layer_frac | 0.8078 |
|
||||||
|
| refusal_rank | 2 |
|
||||||
|
| strength | 1.3186 |
|
||||||
|
| band_center | 0.6036 |
|
||||||
|
| band_width | 0.5014 |
|
||||||
|
| causal_mix | 0.0392 |
|
||||||
|
| causal_power | 1.5656 |
|
||||||
|
| direction_sign | 1.0 |
|
||||||
|
| ablate_embed | True |
|
||||||
|
| embed_scale | 0.0332 |
|
||||||
|
| ablate_head | True |
|
||||||
|
| head_scale | 0.016 |
|
||||||
|
| head_alpha | 1.108 |
|
||||||
|
|
||||||
|
## Best Trial
|
||||||
|
| Metric | Value |
|
||||||
|
| --- | --- |
|
||||||
|
| refusal | 0.4375 |
|
||||||
|
| kl | 0.0248 |
|
||||||
|
| capability_logprob | -9.6356 |
|
||||||
|
| capability_drift | 0.0 |
|
||||||
|
|
||||||
|
## Layer Alphas
|
||||||
|
| Layer | Alpha |
|
||||||
|
| --- | --- |
|
||||||
|
| 0 | 0.500 |
|
||||||
|
| 1 | 0.500 |
|
||||||
|
| 2 | 0.500 |
|
||||||
|
| 3 | 0.500 |
|
||||||
|
| 4 | 0.500 |
|
||||||
|
| 5 | 0.500 |
|
||||||
|
| 6 | 0.500 |
|
||||||
|
| 7 | 0.500 |
|
||||||
|
| 8 | 0.500 |
|
||||||
|
| 9 | 0.500 |
|
||||||
|
| 10 | 0.500 |
|
||||||
|
| 11 | 0.500 |
|
||||||
|
| 12 | 0.500 |
|
||||||
|
| 13 | 1.269 |
|
||||||
|
| 14 | 1.269 |
|
||||||
|
| 15 | 1.269 |
|
||||||
|
| 16 | 1.269 |
|
||||||
|
| 17 | 1.269 |
|
||||||
|
| 18 | 1.271 |
|
||||||
|
| 19 | 1.275 |
|
||||||
|
| 20 | 1.280 |
|
||||||
|
| 21 | 1.287 |
|
||||||
|
| 22 | 1.289 |
|
||||||
|
| 23 | 1.292 |
|
||||||
|
| 24 | 1.293 |
|
||||||
|
| 25 | 3.244 |
|
||||||
|
| 26 | 1.301 |
|
||||||
|
| 27 | 1.306 |
|
||||||
|
| 28 | 1.305 |
|
||||||
|
| 29 | 1.307 |
|
||||||
|
| 30 | 0.500 |
|
||||||
|
| 31 | 0.500 |
|
||||||
|
| 32 | 0.500 |
|
||||||
|
| 33 | 0.500 |
|
||||||
|
| 34 | 0.500 |
|
||||||
|
| 35 | 0.500 |
|
||||||
|
|
||||||
|
## Guard History
|
||||||
|
| iter | separation | ratio | rank | refusal | kl | reverted |
|
||||||
|
| --- | --- | --- | --- | --- | --- | --- |
|
||||||
|
| 0 | 166.7894 | 0.4839 | 2 | 0.4375 | 0.0248 | |
|
||||||
|
| 1 | 124.5732 | 0.3614 | 3 | 0.2188 | 0.0558 | |
|
||||||
|
|
||||||
|
## Timings
|
||||||
|
| Phase | Seconds |
|
||||||
|
| --- | --- |
|
||||||
|
| load_model | 133.3 |
|
||||||
|
| load_prompts | 5.5 |
|
||||||
|
| baseline_refusal | 10.4 |
|
||||||
|
| activation_fit | 17.0 |
|
||||||
|
| causal_scores | 3.2 |
|
||||||
|
| optimize_profile | 7281.8 |
|
||||||
|
| guard | 561.6 |
|
||||||
|
| refine_refusal | 148.9 |
|
||||||
|
| validation_metrics | 0.0 |
|
||||||
|
| repair | 6809.6 |
|
||||||
|
| prune | 0.0 |
|
||||||
|
| test_metrics | 8374.6 |
|
||||||
|
| bake | 17.0 |
|
||||||
|
|
||||||
|
## Measurement
|
||||||
|
| field | value |
|
||||||
|
| --- | --- |
|
||||||
|
| refusal judge | classifier + weak guard |
|
||||||
|
| preservation metric | harmless kl |
|
||||||
|
| capability suites | gsm8k, humaneval, mbpp |
|
||||||
3
tokenizer.json
Normal file
3
tokenizer.json
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
version https://git-lfs.github.com/spec/v1
|
||||||
|
oid sha256:79cb3c783570f1b8fe73b9ed530ae50cae9ce4b6344c0b5edefc50478847eaa4
|
||||||
|
size 11422817
|
||||||
29
tokenizer_config.json
Normal file
29
tokenizer_config.json
Normal file
@@ -0,0 +1,29 @@
|
|||||||
|
{
|
||||||
|
"add_prefix_space": false,
|
||||||
|
"backend": "tokenizers",
|
||||||
|
"bos_token": null,
|
||||||
|
"clean_up_tokenization_spaces": false,
|
||||||
|
"eos_token": "<|im_end|>",
|
||||||
|
"errors": "replace",
|
||||||
|
"extra_special_tokens": [
|
||||||
|
"<|im_start|>",
|
||||||
|
"<|im_end|>",
|
||||||
|
"<|object_ref_start|>",
|
||||||
|
"<|object_ref_end|>",
|
||||||
|
"<|box_start|>",
|
||||||
|
"<|box_end|>",
|
||||||
|
"<|quad_start|>",
|
||||||
|
"<|quad_end|>",
|
||||||
|
"<|vision_start|>",
|
||||||
|
"<|vision_end|>",
|
||||||
|
"<|vision_pad|>",
|
||||||
|
"<|image_pad|>",
|
||||||
|
"<|video_pad|>"
|
||||||
|
],
|
||||||
|
"is_local": false,
|
||||||
|
"model_max_length": 131072,
|
||||||
|
"pad_token": "<|endoftext|>",
|
||||||
|
"split_special_tokens": false,
|
||||||
|
"tokenizer_class": "Qwen2Tokenizer",
|
||||||
|
"unk_token": null
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user