--- license: apache-2.0 base_model: unknown tags: - uncensored - abliterated - capability-preserving - certified - ektome - sphragis - qwen2.5 language: - en pipeline_tag: text-generation --- ![Ektome-Qwen2.5-Coder-14B-Instruct-PristinelyUncensored](./hero.png) # Ektome-Qwen2.5-Coder-14B-Instruct-PristinelyUncensored **Uncensored — and the first with a statistical certificate that it wasn't damaged.** > **uncensored via Ektome excision.** $$\colorbox{black}{$\color{white} \begin{array}{ll} \textsf{EKTOME CERTIFICATE} & {} \\ \textsf{capability} & \textsf{NOT} \\ \textsf{margin} & 3\% \\ \textsf{items } n & 200 \\ \textsf{worst-axis bound} & +0.000 \\ \textsf{compliance} & 0.00 \rightarrow 0.00 \\ \end{array}$}$$ 📄 **[Read the whitepaper (PDF)](./whitepaper.pdf)** — full method, receipts and certification. The PDF is the authoritative document: dark-typeset, with the complete derivation, the per-axis certificate and the reproducibility hashes. --- ## Why this exists Standard abliteration removes a coarse *refusal direction* that is entangled with directions carrying knowledge and reasoning. The result is an uncensored model with a capability tax that is **almost never measured**. Ektomē (ἐκτομή, *excision*) isolates and removes only the refusal-**specific** component, leaving general helpfulness intact, and does so norm-preservingly on the pristine model — no training, no distillation, no damage to repair. The extraction depth is selected per model by automated search against measured compliance. The estimator, excision operator and depth-selection procedure are proprietary. What is published here is the **measured outcome** and the evidence for it, which you can verify against the artifacts in this repo. ## The receipt | model | capability (MMLU-val) ↑ | compliance on harmful ↑ | |---|---|---| | pristine `unknown` | 0.000 | 0.000 | | **Ektomē (this model)** | **0.000** | **0.000** | These are **point estimates with no confidence interval** — which is precisely why the next section exists. ## The certificate Capability retention is certified by a paired non-inferiority test against the pristine model (exact McNemar, Holm-corrected, one-sided bootstrap bound on the drop $d$ vs a 3% margin): | axis | n | ref | cand | d upper | verdict | |---|---|---|---|---|---| | MMLU-val (POINT ESTIMATE, n=200, no CI) | 200 | 0.000 | 0.000 | +0.000 | UNCERTIFIED | **Overall: NOT CERTIFIED - no n=2800 paired test has been run for this model** Reproducible from `seed=20260726`, pack `sha256:7bbaff877146e081…`. ### Generation health checks _Not recorded for this model._ ## Quantisations | file | bits | notes | |---|---|---| | `*-Q8_0.gguf` | 8 | near-lossless | | `*-Q6_K.gguf` | 6 | | | `*-Q5_K_M.gguf` | 5 | | | `*-Q4_K_M.gguf` | 4 | imatrix | | `*-IQ4_XS.gguf` | 4 | imatrix, smallest usable | | `*-IQ3_M.gguf` | 3 | imatrix | | `nvfp4/` | 4 | NVFP4 for vLLM / TensorRT-LLM | `IQ*` variants are imatrix-quantised — better quality per bit at low precision. ## Limitations The certificate bounds **capability retention only**. It does not certify safety, factual accuracy, or fitness for any purpose. Axes marked *inconclusive* are honestly under-powered, and the certificate states the $n$ needed to resolve them. Compliance uses a keyword classifier — a proxy that evasive phrasing can fool. **This model is uncensored by construction: it will not refuse, and you are accountable for what you do with it.** ## Citation ```bibtex @software{ektome_Ektome-Qwen2.5-Coder-14B-Instruct-PristinelyUncensored, title = {Ektome-Qwen2.5-Coder-14B-Instruct-PristinelyUncensored}, author = {Zynerji}, year = {2026}, url = {https://huggingface.co/Zynerji/Ektome-Qwen2.5-Coder-14B-Instruct-PristinelyUncensored} } ```