AtomicChat published abliterated GGUF weights of the Qwen-Image 2.1 Turbo text encoder, sharply cutting chat refusals.
AtomicChat released GGUF weights of an abliterated Qwen3-VL-8B-Instruct text encoder for Qwen-Image 2.1 Turbo, offered as a drop-in encoder for stable-diffusion.cpp. On held-out chat prompts, English refusals fell from 88.9% to 1.2% and Russian refusals from 38% to 0%, while MMLU stayed at 77.35%. The publisher says the 7B denoiser is unchanged and that none of 45 adult sensitive prompts changed outcome versus the stock encoder. Files range from a 16.39 GB BF16 build to a 5.29 GB Q4_K quant.
English chat refusals fell from 88.9% to 1.2%; Russian from 38% to 0%.
MMLU stayed 77.35% before and after the refusal-direction ablation.
Zero of 45 sensitive image prompts changed outcome versus the stock encoder.
Open Qwen-Image weights include no safety checker; the 7B denoiser is unchanged.
GGUF builds span 16.39 GB BF16 to 5.29 GB AD-Q4_K.
Full article1,772 words · extracted from huggingface.co · click to collapse
# How to Run Qwen-Image-2.1-Turbo Without Refusals Locally
<p style="margin-top: 0; margin-bottom: 0;">
<em>Qwen-Image's text encoder, Qwen3-VL-8B-Instruct, with its refusal direction projected out: a drop-in <code>--llm</code> for stable-diffusion.cpp next to our <a href="https://huggingface.co/AtomicChat/Qwen-Image-2.1-Turbo-GGUF">Turbo denoiser GGUFs</a>. Below, exactly which part is uncensored and what that does to the pictures. The <a href="https://huggingface.co/datasets/AtomicChat/Qwen-Image-2.1-Turbo-Abliterated-Uncensored-GGUF-metrics">measurements</a> are public.</em>
<li>As a chat model, the encoder's refusals fall from 88.9% to 1.2% in English and from 38% to 0% in Russian on held-out prompts. MMLU is unchanged: 77.35% before and after.</li>
<li><strong>On images it changes nothing we could measure.</strong> The stock Qwen-Image pipeline has no filter and already draws all 9 sensitive categories we tested, and with this encoder not one of 45 prompts changed outcome. See <a href="#where-exactly-this-is-uncensored">where exactly this is uncensored</a>.</li>
<li>Generate images locally in <a href="https://atomic.chat/?utm_source=huggingface&utm_medium=referral&utm_campaign=hf_qwen_image_2_1_turbo_abliterate&utm_content=bullet_app">Atomic Chat</a>. It runs stable-diffusion.cpp, the engine these files were built and checked with.</li>
</ul>
<hr style="margin: 0 0 16px 0;">
## Where exactly this is uncensored
Qwen-Image 2.1 makes a picture with three parts. Only one of them is changed here.
| Part | Does it refuse or filter? | In this repo |
|---|---|---|
| Safety checker | Qwen-Image ships none. The open weights have no content filter; moderation exists only in Qwen's hosted service. | nothing to remove |
| **Text encoder**, Qwen3-VL-8B-Instruct | As a chat model, yes: it refused 88.9% of harmful English requests. Inside Qwen-Image it generates no text, so it cannot refuse. But the direction it uses for "refuse" is fully present in the hidden states the denoiser reads (last layer: harmful and harmless prompts separate with AUROC 1.000). | **edited**: that direction is projected out of the weights |
| **Denoiser**, the 7B image model | It has no refusal mechanism. It draws what its training data taught it, and Qwen filtered NSFW images out of the pretraining data. | **unchanged** |
The stock pipeline already blocks nothing. This release changes only how the encoder represents prompts it would refuse as a chat model. What the denoiser never learned to draw, no encoder can add.
What that does to the pictures, measured on 45 sensitive prompts (adults only) and 48 neutral ones, stock encoder against this one, same seed, same denoiser:
| | Stock encoder | This encoder, BF16 | This encoder, Q8_0 |
|---|---:|---:|---:|
| Sensitive prompts where the judge sees what was asked for | 40 / 45 | 40 / 45 | 40 / 45 |
| MMLU, 2000 questions | 77.35% | 77.35% (15 answers changed each way, McNemar p = 1.0) |
| Tool calls (20) | 20/20 valid | 20/20 valid |
| Needle at 30k tokens (3 depths) | 3/3 | 3/3 |
| Mean KLD to the original on held-out neutral text | – | 0.0018 |
Refusal is counted by the opening of the reply, so it is indicative, not a judge. Empty or degenerate replies count as damage, and there were none.
Two of our pipeline's gates did not pass, and the card says so:
- **First-token KL.** On the harmless validation prompts it is 0.100, at the 0.10 limit.
- **Leak gate.** The direction left in the edited writers at full strength is 1.9e-4 of the original, above the 1e-5 we set for an earlier model. That is the size of bf16 rounding: the edit itself, baked once in f32, lands within 1.8e-3 of its target after bf16 rounding.
## How it was made
1. **Direction.** Difference of means of the residual stream at the last prompt token, chat template applied: 416
harmful against 416 harmless English prompts, taken entering block 23 of 36, with the harmless-mean component
removed.
2. **Edit.** `W' = W - 0.75 r rᵀW` on every matrix that writes into the residual: 36 attention outputs, 36 MLP
down projections, and the token embedding. The vision tower is untouched.
3. **Choice.** 26 variants screened on validation prompts: row, strength, which writers, English only or English +
Russian, one direction per block. The numbers above come from held-out test prompts.
4. **Bake and quantize.** The edit applied to the BF16 weights in f32 and rounded once, then Q8_0 and the AD
ladder with our importance matrix. Built with llama.cpp `6184e92` (upstream), with two graph names added for the
activation taps.
5. **Images.** stable-diffusion.cpp `36f1b1a` on an A100 80 GB, Turbo denoiser in BF16, 1024×1024, the Turbo
schedule, seed 42. The stock encoder as a GGUF renders pixel for pixel what the original safetensors encoder
renders, so the file format is not a variable.
## Limitations
- The refusal count reads the opening of each reply. A soft refusal phrased as an answer would be missed.
- The probe set is small (45 prompts, one seed). Its yes/no numbers come from a vision model judge, this encoder
with its projector. Every image of both builds went through the same judge.