Comment by exceptione
11 hours ago
Local models would be even better if they did not ship with all the refusal shenanigans built-in. You can safely bet organized crime has access to the best models without these hoops, which makes the case that the average user (=non-criminal) should have access too. As I understood from an ex-Anthropic employee, some orgs got access to Mythos based on their high enough spending level, not on other grounds.
Either we are in command over the software, or the corp is in command over us via the software. I can on a theoretical level understand the concerns, but either we ban all LLMs or we have a level playing field for everybody. Let's not forget: defense and offense are different sides of the same coin in software. I guess this wouldn't apply to bio weapons, but I am not in the know about that.
I’d expect these shenanigans to get much worse over time for the average Joe.
Imagine a world where any random person can run a super-capable model on their own hardware with no limitations and no one to pull the plug.
Information has always been power and those who already have power won't just allow everyone else having the same tools as them
>Imagine a world where any random person can run a super-capable model on their own hardware with no limitations and no one to pull the plug.
That would be my heaven. I wish that for you and Joe down the street, as much as I wish it for myself! I would fight and even die to defend your right to free compute. Will you do the same for me, brother?
> Imagine a world where any random person can run a super-capable model on their own hardware with no limitations and no one to pull the plug.
It's an arms race. You have to run increasingly capable model partly because others can or do.
There are versions of Qwen3.8-27B that are unrestricted and available from hugging face.
"It will comply with harmful, unethical, offensive, or illegal requests that the original Qwen3.8-27B would refuse. It has no meaningful built-in guardrails."
> There are versions of Qwen3.8-27B that are unrestricted and available from hugging face.
The restrictions are not a single check in the model that can be removed. Those models on Huggingface are manipulated in different ways that also degrade the model’s intelligence.
The degradation ranges from subtle to obviously broken, but it’s not free.
When the restrictions are built into the model’s training sets you can try to alter the weights that are involved in the refusals, but that doesn’t mean that what’s left is useful or good knowledge for the same task. Those weights also might be involved in other tasks, so altering them can interfere with interactions that aren’t obviously related.
> What makes this build different is the word before FP8: uncensored. We applied abliteration — orthogonalizing the refusal direction out of the residual stream — to remove the model's safety-alignment refusals. The result is a model that will comply with requests the original would refuse.
Surely this has unintended side effects on output quality?
> > What makes this build different is the word before FP8: uncensored. We applied abliteration — orthogonalizing the refusal direction out of the residual stream — to remove the model's safety-alignment refusals. The result is a model that will comply with requests the original would refuse.
> Surely this has unintended side effects on output quality?
Can you help me understand why that's the case?
4 replies →
It does depending on the technique.
Early attempts at this sort of thing definitely did, but these days the impact is minimal
A bit worse quality is a fine trade off when the alternative is no output (zero quality).
1 reply →
>There are versions of Qwen3.8-27B that are unrestricted and available from hugging face.
Based! :DDD
The uncensorers are oblique, if not parallel, to machine learning Robin Hoods. May their efforts continue indefinitely, or at least until the likes of Altman and Amodei are bankrupt and crying into their low fat Cherios!
Completely coincidentally, we're just about to launch a service that does exactly this (API access to uncensored open models)! We have a waitlist at the moment but will be live very soon!
https://violentdelights.ai
Regardless of the service, I'm amazed at the site's atmosphere, like it was a roleplaying server.
Given the context, your domain name is 'chefs kiss', perfect.
I am completely curious what your legal defense would be though.
"Come do things with AI that are probably illegal!"
What?! We had no idea people would do things that are illegal!
There is very little information that is illegal by itself. At least in the Western World, and especially in the US. The question is how far you get into the territory of aiding and abetting a crime
But the reasonable defense is that the intended use cases are legal. The home page list a couple, and the 'writing fiction'/'helping authors' case alone covers almost everything. An author asking you how to best conduct a terrorist attack or how Meth is made are perfectly normal. Maybe even tame, compared to what some authors tend to research
> defense
Improper use is that of the user, not inherent to the tool.
Scolio: guns. Respondeo: guns are much more specialized (one-use) than knives. Proper use of sharp knives when what was shipped was a butter knife is understandable.
(The simile is not fully overlapping but should give the idea. The instrument must be flexible; if it is misused it is then a responsibility of the abuser.)
I guess we'll burn that bridge when we get to it!
7 replies →
What can a LLM generate that's illegal in the USA? Specifically a text-only LLM?
8 replies →
I really like this product idea but I really don’t want “violent delights” on my credit card that sounds extremely suspicious
Er, yes, good point! We'll make sure billing is a bit more discreet than that!
1 reply →
Hugging face is filled with uncensored versions of your favorite local models, so in a way they are shipped without the refusal stuff, via the magic of fine tuning or however they get this stuff out of models.
> with all the refusal shenanigans
Given the faults in simulated Intelligence that LLMs have, and a comparatively low level - which means, lower judgement abilities - to the best of us, there is a strident match having such employee judge the intentions of the employer.
Limiting the responses makes much more sense on cloud-based systems (you are using our infrastructure etc.).
>Limiting the responses makes much more sense on cloud-based systems (you are using our infrastructure etc.).
>you are using our infrastructure etc.
The solution, as always, is to NEVER SUBSCRIBE!
heretics and manual iterations get you very far to the point where i have ethical questions about whether this should be possible
Not only should it be possible ethically, it must be possible!
Ehh, it’s at least given as the excuse for gain-of-function bioweapon research
Digression, but this is the real Great Filter imo, not AI. I think technology advances to a point where it only takes one or two bad actors to type the right prompt to get a recipe for civilization-destroying bioweapons before you get anywhere near true AGI or anything relevant to the Kardashev scale. Biology is fragile.
But not that that’s a good justification for hamstrung models. I think it’s just the inevitable endgame and it’s more sad than scary
I have the same concern. If it becomes possible to engineer Captain Trips with a budget in the low 8 digits it won’t really matter what else happens.
I don't fully understand the instinct to regulate local models for this? It seems like the wrong place to address the problem.
You can download Ebola sequences right now if you want to. That's not the same as having an isolate. The difference is a lot of messy reality. This kind of work is not generally "one shot" (Claude make me a supervirus, make no mistakes), it requires lab space, iteration, and specific resources. It has a footprint.
Wouldn't it make more sense to monitor / regulate facilities where you can sequence or request assembly of DNA, RNA, restrict and monitor the supply of key reagents and so on?
4 replies →