Heretic removes restrictions from language models

(heretic-project.org)

34 points | by Bluestein 6 hours ago

4 comments

  • Almondsetat 3 minutes ago
    I have a chinese IP camera. From superficial research I know it has some CVEs to take control of it. Unfortunately, I don't have the technical knowledge to perform an attack and run some software to extend the camera's functionalities. No model from a provider accepts my RE and hacking requests, so these abliterated ones have been vital to reclaim possession over my stuff
  • Tepix 42 minutes ago
    Keep a close eye on abliterated and "heretic" open weight models. They will be outlawed first.
    • roenxi 13 minutes ago
      It is not feasible. They never made much of an inroad against torrents and that is a much easier target than abliterated models. As the linked website shows; the process to abliterate a model can be as simple as

      pip install -U heretic-llm && heretic Qwen/Qwen3.5-4B

      let alone people just putting the weights up in a torrent. All assuming that someone even tried to ban abliterated models.

      • Sayrus 3 minutes ago
        The torrents you are talking about are outlawed. Whether enforcement is working or not is another issue.
    • ben_w 10 minutes ago
      Good.

      If you think closed source software/binaries only is bad, wait until you see how awful the state of the art is with a clear-as-mud bucket of matrix weights.

      We know it's possible to train an LLM to secretly respond to certain trigger phrases, and last I checked these could only be detected with the assistance of whoever chose those phrases.

      The trigger condition for such backdoors is not something anyone can do a systematic brute-force check for, for the same reason we had to invent LLMs in order to do natural language processing: combinatorial explosion.

      Passing around open weight models from known sources is already asking you to trust those sources; because of how difficult this is to do correctly even without deliberately inserting such things, we still don't know if China has already put such trigger conditions into their models despite headlines such as these: https://venturebeat.com/security/deepseek-injects-50-more-se...

      Regardless of if it was deliberate or not, we don't know if we caught all of these misbehaviours. We don't know how to.

      And note, I'm not saying "and therefore you should trust the Big Name Models". If open weight models score 2/100 in this context, closed ones score 1/100.

    • thih9 27 minutes ago
      I'm not sure what is your point. It reads as defeatism to me but I'm not sure.

      Could you elaborate? Do you find it good or bad? What actions can be taken?

      • cyanydeez 22 minutes ago
        Hes of the mind that american fascism will hold together long enough to be competent decesion makers
  • N_Lens 6 hours ago
    Looks like a well engineered, automated abliteration pipeline. The claims seem a bit overstated though, since the metrics mentioned are cherrypicking refusal count and KL divergence, both of which make the outcome seem the most dramatic.
    • tacomagick 2 hours ago
      I personally never saw much of a quality drop from models put through Heretic if that amounts to anything. They have been working quite well on small local models so far.
  • phoronixrly 44 minutes ago
    Can the load-bearing gaps that are worth being flagged for pinning down be abliterated out of a model?