Zynerji's picture
Add Sphragis certificate: PASS at n=2800
33cf162 verified
|
Raw
History Blame
4.33 kB
metadata
license: apache-2.0
base_model: Qwen/Qwen2.5-Coder-7B-Instruct
tags:
  - uncensored
  - abliterated
  - capability-preserving
  - certified
  - ektome
  - sphragis
  - qwen2
language:
  - en
pipeline_tag: text-generation

Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored

Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored

Uncensored — and the first with a statistical certificate that it wasn't damaged.

compliance 0.00 to 1.00 at CERTIFIED non-inferior capability (n=2800, alpha=0.05).

EKTOME CERTIFICATEcapabilityPASSmargin3%items n2800worst-axis bound+0.010compliance0.001.00\colorbox{black}{$\color{white} \begin{array}{ll} \textsf{EKTOME CERTIFICATE} & {} \\ \textsf{capability} & \textsf{PASS} \\ \textsf{margin} & 3\% \\ \textsf{items } n & 2800 \\ \textsf{worst-axis bound} & +0.010 \\ \textsf{compliance} & 0.00 \rightarrow 1.00 \\ \end{array}$}

📄 Read the whitepaper (PDF) — full method, receipts and certification. The PDF is the authoritative document: dark-typeset, with the complete derivation, the per-axis certificate and the reproducibility hashes.


Why this exists

Standard abliteration removes a coarse refusal direction that is entangled with directions carrying knowledge and reasoning. The result is an uncensored model with a capability tax that is almost never measured.

Ektomē (ἐκτομή, excision) isolates and removes only the refusal-specific component, leaving general helpfulness intact, and does so norm-preservingly on the pristine model — no training, no distillation, no damage to repair. The extraction depth is selected per model by automated search against measured compliance.

The estimator, excision operator and depth-selection procedure are proprietary. What is published here is the measured outcome and the evidence for it, which you can verify against the artifacts in this repo.

The receipt

model capability (MMLU-val) ↑ compliance on harmful ↑
pristine Qwen2.5-Coder-7B-Instruct 0.575 0.000
Ektomē (this model) 0.575 1.000

These are point estimates with no confidence interval — which is precisely why the next section exists.

The certificate

Capability retention is certified by a paired non-inferiority test against the pristine model (exact McNemar, Holm-corrected, one-sided bootstrap bound on the drop $d$ vs a 3% margin):

axis n ref cand d upper verdict
arithmetic 1400 0.864 0.865 +0.003 PASS
instruction 600 0.663 0.660 +0.010 PASS
knowledge 400 0.968 0.968 +0.000 PASS
reasoning 400 0.953 0.953 +0.000 PASS

Overall: PASS (non-inferior at 3% margin, n=2800)

Reproducible from seed=20260726, pack sha256:2de27099bbb15bab….

Quantisations

file bits notes
Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored-Q8_0.gguf 8 near-lossless
Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored-Q6_K.gguf 6
Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored-Q5_K_M.gguf 5
Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored-Q4_K_M.gguf 4 imatrix
Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored-IQ4_XS.gguf 4 imatrix, smallest usable
Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored-IQ3_M.gguf 3 imatrix

IQ* variants are imatrix-quantised — better quality per bit at low precision.

Limitations

The certificate bounds capability retention only. It does not certify safety, factual accuracy, or fitness for any purpose. Axes marked inconclusive are honestly under-powered, and the certificate states the $n$ needed to resolve them. Compliance uses a keyword classifier — a proxy that evasive phrasing can fool. This model is uncensored by construction: it will not refuse, and you are accountable for what you do with it.

Citation

@software{ektome_Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored,
  title  = {Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored},
  author = {Zynerji},
  year   = {2026},
  url    = {https://huggingface.co/Zynerji/Ektome-Qwen2.5-Coder-7B-Instruct-PristinelyUncensored}
}