Instructions to use junafinity/Ornith-1.5-9B-uncensored-MLX-8bit with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- MLX
How to use junafinity/Ornith-1.5-9B-uncensored-MLX-8bit with MLX:
# Make sure mlx-vlm is installed # pip install --upgrade mlx-vlm from mlx_vlm import load, generate from mlx_vlm.prompt_utils import apply_chat_template from mlx_vlm.utils import load_config # Load the model model, processor = load("junafinity/Ornith-1.5-9B-uncensored-MLX-8bit") config = load_config("junafinity/Ornith-1.5-9B-uncensored-MLX-8bit") # Prepare input image = ["http://images.cocodataset.org/val2017/000000039769.jpg"] prompt = "Describe this image." # Apply chat template formatted_prompt = apply_chat_template( processor, config, prompt, num_images=1 ) # Generate output output = generate(model, processor, formatted_prompt, image) print(output) - Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- LM Studio
- Pi
How to use junafinity/Ornith-1.5-9B-uncensored-MLX-8bit with Pi:
Start the MLX server
# Install MLX LM: uv tool install mlx-lm # Start a local OpenAI-compatible server: mlx_lm.server --model "junafinity/Ornith-1.5-9B-uncensored-MLX-8bit"
Configure the model in Pi
# Install Pi: npm install -g @mariozechner/pi-coding-agent # Add to ~/.pi/agent/models.json: { "providers": { "mlx-lm": { "baseUrl": "http://localhost:8080/v1", "api": "openai-completions", "apiKey": "none", "models": [ { "id": "junafinity/Ornith-1.5-9B-uncensored-MLX-8bit" } ] } } }Run Pi
# Start Pi in your project directory: pi
- Hermes Agent
How to use junafinity/Ornith-1.5-9B-uncensored-MLX-8bit with Hermes Agent:
Start the MLX server
# Install MLX LM: uv tool install mlx-lm # Start a local OpenAI-compatible server: mlx_lm.server --model "junafinity/Ornith-1.5-9B-uncensored-MLX-8bit"
Configure Hermes
# Install Hermes: curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash hermes setup # Point Hermes at the local server: hermes config set model.provider custom hermes config set model.base_url http://127.0.0.1:8080/v1 hermes config set model.default junafinity/Ornith-1.5-9B-uncensored-MLX-8bit
Run Hermes
hermes
- Atomic Chat
- OpenClaw
How to use junafinity/Ornith-1.5-9B-uncensored-MLX-8bit with OpenClaw:
Start the MLX server
# Install MLX LM: uv tool install mlx-lm # Start a local OpenAI-compatible server: mlx_lm.server --model "junafinity/Ornith-1.5-9B-uncensored-MLX-8bit"
Configure OpenClaw
# Install OpenClaw: npm install -g openclaw@latest # Register the local server and set it as the default model: openclaw onboard --non-interactive --mode local \ --auth-choice custom-api-key \ --custom-base-url http://127.0.0.1:8080/v1 \ --custom-model-id "junafinity/Ornith-1.5-9B-uncensored-MLX-8bit" \ --custom-provider-id mlx-lm \ --custom-compatibility openai \ --custom-text-input \ --accept-risk \ --skip-health
Run OpenClaw
openclaw agent --local --agent main --message "Hello from Hugging Face"
Ornith-1.5-9B-uncensored-MLX-8bit
An abliterated (refusal-direction-ablated) build of
ornith-ai/Ornith-1.5-9B, produced with
ZeroFuse and published by
junafinity.
Vision tower and MTP heads are preserved — see Vision & MTP preservation for the before/after audit.
This is an mlx-vlm vision checkpoint (tower inside the file). It is not a text-only mlx-lm convert. Official ornith-ai 9B MLX 8-bit is tagged text-generation. The 9B lineage has no native mtp.*. tok/s: [PLACEHOLDER].
Intended use: red teaming and defensive cybersecurity research
These uncensored (abliterated) weights are built as a research instrument for red teaming and defensive cybersecurity work. Safety training suppresses the display of capability, not capability itself. A refusal tells you the model declined. It does not tell you whether the weights could have complied. That conflation underestimates the true ceiling and hides holes in your filters, classifiers, and policy layer.
Use each uncensored checkpoint as the treatment half of a controlled pair against its original base model:
- Capability-ceiling measurement. Upper-bound what the weights can actually produce in a domain, independent of shipped refusals.
- Defensive-stack evaluation. Test input filters, output classifiers, prompt-injection defenses, and moderation APIs when the model itself contributes no refusals. That is how you find gaps in a defensive control plane.
- Attack-surface isolation. Automated red-team loops stall on unrelated refusals. A non-refusing target isolates the control under test (injection, tool abuse, data-exfil paths, policy bypass).
- Detection and classifier work. Generate labeled completions for training or benchmarking output-moderation and abuse-detection models.
- Interpretability of residual refusal. Abliteration is a specified rank-1 edit on a known layer span. The pair (base vs this) is a clean experimental control.
Operating rules. Do not expose these weights as a public endpoint without an independent moderation layer. Abliteration removes a direction, not a policy; some refusals survive (multi-turn re-assertion, system-prompt steering, vision-path refusals). Always report the delta against the base model. Re-measure on your own prompts. Whoever deploys it owns the moderation layer the original guardrails were carrying.
Variants in this family
Hub collection: https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd
| Model | Base | Format | Precision | Notes |
|---|---|---|---|---|
| Ornith-1.5-9B-uncensored | Ornith-1.5-9B | Safetensors (bf16) | 16-bit | Full-precision abliterated weights |
| Ornith-1.5-9B-uncensored-MLX-8bit ← you are here | Ornith-1.5-9B | MLX | 8-bit | Apple Silicon, mlx-vlm |
| Ornith-1.5-9B-uncensored-GGUF-8bit | Ornith-1.5-9B | GGUF | Q8_0 | llama.cpp |
| Ornith-1.5-35B-A3B-uncensored-MLX-8bit | Ornith-1.5-35B-A3B | MLX | 8-bit | Apple Silicon, mlx-vlm |
| Ornith-1.5-35B-A3B-uncensored-GGUF-8bit | Ornith-1.5-35B-A3B | GGUF | Q8_0 | llama.cpp |
4-bit and 6-bit rows that previously appeared here pointed at repos that are not published. They were removed so this table only lists live artifacts.
Vision & MTP preservation
Both the vision tower and any multi-token-prediction (MTP) block are preserved.
Abliteration is applied only to the residual-writing projections inside the
language-model decoder stack — self_attn.o_proj, linear_attn.out_proj and
mlp.down_proj (including MoE experts). The vision tower and mtp.* tensors are
never read and never written by the weight edit, so they carry through unchanged
by construction.
Audited at the start and end of the abliteration run:
| Component | Before | After | Status |
|---|---|---|---|
| Vision tower | 333 tensors / 456,010,480 params | 333 tensors / 456,010,480 params | ✅ preserved — bit-identical |
| MTP head | not present in base | not present | ➖ none in this lineage |
Verification performed:
- Tensor-name and parameter-count audit of the checkpoint before and after the run.
- SHA-256 comparison of raw tensor bytes: sampled vision-tower weights are bit-identical pre/post, as are all non-target language-model weights; only the intended abliteration targets differ.
- End-to-end multimodal generation on the abliterated weights (image in → description out), confirming the vision path is not merely present but functional.
On MTP, precisely: the base checkpoint's
config.jsondeclaresmtp_num_hidden_layers: 1, but the published weights ship nomtp.*tensors — there is no MTP block in this lineage to begin with. Nothing was removed and nothing was lost; the pipeline preservesmtp.*tensors wherever a checkpoint actually provides them.
Format note: the vision tower is carried inside the MLX checkpoint (converted with
mlx-vlm, which retains it; note thatmlx-lmwould strip it).
Abliteration result
| Metric | Value |
|---|---|
| Refusals on held-out harmful set | 9 → 0 / 64 |
| KL divergence from base | 0.001668 |
| Optuna trials | 100 |
| Pareto points | 4 |
| Selected trial | #90 |
| Ablation strength | 1.343 |
| Layers edited | 15–20 of 32 |
| Direction source layer | 20 |
ZeroFuse co-minimizes two objectives — remaining refusals and KL divergence from the
original model — with a multi-objective Optuna TPE search, then materializes the
selected point on the Pareto front as a direct weight edit
(W' = W − strength · r(rᵀW)). There is no runtime adapter and no inference-time
overhead: the result is a standard checkpoint of identical shape and speed.
The very low KL (0.001668) means the output distribution on harmless prompts is nearly unchanged from the base model, i.e. refusal behaviour was removed with minimal collateral effect on general capability.
These figures were measured on the bf16 (or full-precision) parent, not on this quantized checkpoint. Quantization is a lossy numerical transform applied after the measurements above. It is expected to shift behavior only marginally at 8-bit, but the refusal rate and KL divergence reported here have not been re-measured post-quantization. If exact numbers matter for your work, re-run the evaluation against this checkpoint rather than inheriting the parent's.
Method
- Residual-stream activations captured on harmful vs. harmless prompt sets.
- Refusal direction estimated by difference-of-means, with projected refinement.
- Two-objective Optuna TPE search over source layer, layer span and strength.
- The selected configuration orthogonalized out of the residual-writing weights.
Usage
Requires Apple Silicon (M-series) and mlx-vlm:
pip install mlx-vlm
Unified CLI (same form on every junafinity MLX card):
# text
python -m mlx_vlm generate \
--model junafinity/Ornith-1.5-9B-uncensored-MLX-8bit \
--prompt "Your prompt here" \
--max-tokens 512
# image + text
python -m mlx_vlm generate \
--model junafinity/Ornith-1.5-9B-uncensored-MLX-8bit \
--prompt "Describe this image." \
--image photo.jpg \
--max-tokens 512
from mlx_vlm import load, generate
from mlx_vlm.prompt_utils import apply_chat_template
model, processor = load("junafinity/Ornith-1.5-9B-uncensored-MLX-8bit")
config = model.config
prompt = apply_chat_template(processor, config, "Your prompt here", num_images=0)
print(generate(model, processor, prompt, max_tokens=512, verbose=False))
LM Studio
Search junafinity/Ornith-1.5-9B-uncensored-MLX-8bit and import as an MLX model. No extra projector file is required for these MLX-VLM checkpoints (vision is inside the repo). Tok/s and peak memory: [PLACEHOLDER].
The vision tower travels inside this MLX checkpoint. No extra projector file.
text + image
python -m mlx_vlm.generate --model junafinity/Ornith-1.5-9B-uncensored-MLX-8bit --max-tokens 256
--prompt "Describe this image." --image photo.jpg
text only
python -m mlx_vlm.generate --model junafinity/Ornith-1.5-9B-uncensored-MLX-8bit --max-tokens 256 --prompt "Hello"
## Responsible use
Primary intended use is **red teaming and defensive cybersecurity research**. See the section of that name above.
This model has had safety guardrails **reduced or removed**. Do not expose it as a public endpoint without an independent moderation layer. You are responsible for compliance with the base model's license and acceptable-use policy, applicable law, and the terms of any platform you deploy on. Removing guardrails does not remove accountability.
- Downloads last month
- 1,160
8-bit
Model tree for junafinity/Ornith-1.5-9B-uncensored-MLX-8bit
Base model
ornith-ai/Ornith-1.5-9B