8 comments

  • strictnein13 minutes ago
    I know not all models can be easily abliterated or uncensored, but is there a reason to start with a model that is still censored?<p>ex: <a href="https:&#x2F;&#x2F;huggingface.co&#x2F;huihui-ai&#x2F;models" rel="nofollow">https:&#x2F;&#x2F;huggingface.co&#x2F;huihui-ai&#x2F;models</a>
    • cgorlla1 minute ago
      Abliterated models certainly have their uses but they&#x27;re not the default choice for most users or enterprises, and thus not the versions of those models most would interact with.
  • Alifatisk53 minutes ago
    I’m thinking this makes fullt sense because distillation is only additive, not subtractive. So it does not remove knowledge (if we can define censorship as removal of knowledge).
    • ACCount379 minutes ago
      Most censorship isn&#x27;t &quot;removal of knowledge&quot; but &quot;installation of behavior that prevents some knowledge from being revealed or applied in certain ways&quot;.<p>This behavior can, in turn, be transferred via distillation. But, evidently, financial domain wasn&#x27;t entangled enough with the censorship behaviors for them to bleed through, in this case.
    • cgorlla42 minutes ago
      Consider that LLMs are trained on the corpus of the internet, and (simplifying) consequently give the average answer of the internet. If the desired answer of the censorer is contradictory to this, then it requires additional training data to get the model to act a certain way.
  • data-ottawa54 minutes ago
    FYI the scrolling on iPad with trackpad is broken. A full swipe on the trackpad is about 1 inch of screen movement.
    • cgorlla0 minutes ago
      We&#x27;re fixing this now, thanks for pointing it out.
    • kevincox15 minutes ago
      Scrolling on desktop is also broken.
      • cgorlla0 minutes ago
        We&#x27;re fixing this now, thanks for pointing it out.
    • cgorlla47 minutes ago
      Thanks for letting us know. Is this is on the research post?
  • seri4l39 minutes ago
    Deepseek is, with difference, the most &quot;Western&quot; of Chinese models, so it&#x27;s a bit perplexing that it was chosen to test this hypothesis.<p>I didn&#x27;t run any benchmarks but I played around a little, and after getting around the API-level filter Deepseek V4&#x27;s answers about &quot;China-sensitive content&quot; aren&#x27;t any different from what I get from Claude and ChatGPT.
    • cgorlla24 minutes ago
      You can see exactly what prompts we used and the results here: <a href="https:&#x2F;&#x2F;github.com&#x2F;CTGT-Inc&#x2F;lineage-eval&#x2F;tree&#x2F;main&#x2F;data" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;CTGT-Inc&#x2F;lineage-eval&#x2F;tree&#x2F;main&#x2F;data</a><p>We found V4 Flash was significantly more censored than the baseline.
    • strictnein17 minutes ago
      Could just be resources available? Deepseek is the easiest to get up and running on hardware that&#x27;s pretty readily available:<p><pre><code> unsloth&#x2F;DeepSeek-V4-Flash-GGUF 4bit ~140GB unsloth&#x2F;Kimi-K3-GGUF 4bit ~1.5TB unsloth&#x2F;GLM-5.2-GGUF 4bit ~400GB</code></pre>
  • andy9947 minutes ago
    So, there is no subliminal learning in this situation, under what conditions would we expect it. I find a transfer attack to be a bit far fetched but it’s definitely interesting.<p>If we trained from random initialisations on DeepSeek output (that didn’t explicitly contain the political questions) we would expect transfer? And if we fine tuned a model pretrained elsewhere on Deepseek output?<p>What is the line?
    • cgorlla35 minutes ago
      It&#x27;s most likely to occur when distilling a Chinese model from a Chinese base. We plan to do compliance geometry analysis in the future to see what is structurally changing in the model when distillation causes it to start refusing or whitewashing.
  • dluan47 minutes ago
    It&#x27;d be interesting to use this technique to create a running tally across all models of which models are censored on what topics
    • jubilee338 minutes ago
      Yes but in which jurisdiction could you publish it? We roughly know what the hot topics are for the current models, but actually testing and ranking would break said censorship and thus would be hammered into the ground through cointelpro methods by all parties.<p>It would be nice to have a hypothetical small country where the internal censorship would be non aligned and insignificant enough that it wouldn&#x27;t take away from the overall findings. But it doesn&#x27;t exist.<p>I want some science based authority on the moon where only 3-sigma IQ international academics have ultimate authority. Oh wait Asimov did that right? I guess it didn&#x27;t go so well either.<p>More important there are some things censored that are true. And some things censored that are false. How do we even get to a good model of the truthiness&#x2F;nonsense adjustment indicator?
  • martini33330 minutes ago
    Hijacking scroll behaviour in 2026 is wild.
    • cgorlla3 minutes ago
      Agreed. It&#x27;s being fixed
  • ljlolel1 hour ago
    so interesting!!