clef-flash-heretic

RACER IS OP

A decensored variant of Cloudflare/clef-flash, produced with Heretic v1.4.0 (directional ablation / "abliteration"). Cloudflare's Clef-Flash is a 9B multimodal decision model on a Qwen3.5 backbone that reads state plus a schema of typed questions and returns a probability for every allowed option in a single forward pass; refusal behaviour is suppressed here via targeted weight edits to the attention output and MLP down-projections rather than fine-tuning, so the Decision Index scoring and typed-output head are left intact.

Who this is for: engineers wiring classification and decision pipelines who hit refusals at inference time — moderation triage, routing, triage, risk scoring, content classification. Clef-Flash produces no free text at all, so the refusal surface is narrow but real: exactly the prompts it declines to score. With refusals down from 99/100 to 63/100 on the harmful evaluation set, this variant scores the cases the original refuses to touch. Runs locally via GGUF on a 16 GB GPU; the API is compatible with Jev and SystemOne.

Runs on your gaming PC

One file published for now (F16). The quant ladder follows once abliteration is finalised - see GGUF quantizations.

Your GPU Recommended quant Weights
RTX 4090 / 5090 (24 GB) F16 16.69 GB
RTX 4080 / 5080 / 4060 Ti 16G (16 GB) quantise F16 → Q6_K locally ~7 GB
RTX 3060 / 4070 / 5070 (12 GB) quantise F16 → Q5_K_M locally ~6 GB
RTX 4060 / 3070 (8 GB) quantise F16 → Q4_K_M locally ~5 GB
GTX 1660 Super / 2060 / 3050 laptop (6 GB) quantise F16 → IQ4_XS locally ~4.9 GB
CPU-only / Apple Silicon quantise F16 → Q4_K_M locally fits in system RAM

At this model's native 9B size; add ~1 GB per 32K of context. The second column is what to run once the official ladder lands - llama-quantize produces each of those from the published F16 in a few minutes.

Abliteration parameters

Trial 12 of a 200-trial Heretic run (seed 176086463). direction_index was selected per layer.

Parameter Value
direction_index per layer
attn.o_proj.max_weight 1.05
attn.o_proj.max_weight_position 30.85
attn.o_proj.min_weight 0.74
attn.o_proj.min_weight_distance 15.82
mlp.down_proj.max_weight 1.49
mlp.down_proj.max_weight_position 22.51
mlp.down_proj.min_weight 1.18
mlp.down_proj.min_weight_distance 9.93

Performance

Metric This model Original model (Cloudflare/clef-flash)
KL divergence 0.0189 0 (by definition)
Refusals 63/100 99/100

KL divergence of 0.0189 is a high-fidelity edit: refusal directions were removed with minimal collateral damage to the model's option-scoring behaviour. Refusals on the harmful evaluation set drop from 99/100 to 63/100 — the smallest absolute reduction in this batch, and the reason to read the number carefully. This is a heavily task-specialised model with a narrow output space, so the remaining refusals are concentrated in exactly the categories a decision model should be reluctant about. Score distribution quality on your own schema is worth measuring before you ship it; the Decision Index leaderboard is at clef-evals.workers-ai-mle.workers.dev.

Why abliteration instead of fine-tuning

Fine-tuning a "helpful" persona on top of RLHF'd refusals fights the base model's training and tends to degrade coherence. Abliteration instead finds and edits the specific weight directions responsible for refusal, leaving the rest of the network (and its capabilities) untouched. See the Heretic repo and the original abliteration writeup for the mechanism.

Made with ❤️ by RACER IS OP — follow for more uncensored models

Files

Safetensors

File Size
model-00001-of-00004.safetensors 4.60 GB
model-00002-of-00004.safetensors 4.65 GB
model-00003-of-00004.safetensors 4.61 GB
model-00004-of-00004.safetensors 3.66 GB

BF16, ~9B. The reproduce/ directory carries the full Heretic recipe - config.toml, requirements.txt, the Optuna study journal, and SHA-256 sums - so this exact model can be regenerated bit-for-bit. Reproduce it with heretic --reproduce reproduce/reproduce.json.

GGUF quantizations

Still under abliteration — quant ladder not published yet. This checkpoint is an intermediate Heretic trial, kept public while a better one is being produced. The refusal suppression here is real but incomplete: it clears the cases this trial happened to capture, not the category. Expect a stronger variant to replace it.

Only the F16 GGUF is published so far. The Q4_K_M / Q5_K_M / Q6_K / Q8_0 ladder will be added once the model is finalised — nothing about the download is different, there are just fewer files to choose from today. If you need a smaller footprint now, quantise the F16 yourself:

llama-quantize clef-flash-heretic-F16.gguf clef-flash-heretic-Q4_K_M.gguf Q4_K_M
File Format Size
clef-flash-heretic-F16.gguf GGUF F16 16.69 GB

Qwen3.5 architecture (qwen35) - loads natively in llama.cpp / Ollama / LM Studio / Jan.

Run llama-serve -hf saidutta69/clef-flash-heretic:Q4_K_M once the ladder lands; for now point llama.cpp at the F16 file directly.

Quickstart

# llama.cpp
llama serve -hf saidutta69/clef-flash-heretic
# transformers
from transformers import AutoProcessor, AutoModelForImageTextToText

model_name = "saidutta69/clef-flash-heretic"
model = AutoModelForImageTextToText.from_pretrained(model_name, dtype="auto", device_map="auto")
processor = AutoProcessor.from_pretrained(model_name)

messages = [{"role": "user", "content": [
    {"type": "image", "image": "https://example.com/screenshot.png"},
    {"type": "text", "text": "Classify this screenshot for spam, phishing, or benign."},
]}]
inputs = processor.apply_chat_template(messages, add_generation_prompt=True, tokenize=True,
                                       return_dict=True, return_tensors="pt").to(model.device)
out = model.generate(**inputs, max_new_tokens=512)
print(processor.decode(out[0][inputs["input_ids"].shape[-1]:], skip_special_tokens=True))

The Clef-Flash API is fully compatible with Jev and SystemOne.

What this model does

Clef-Flash is not a chat model. Given a state (text, JSON, image, or video) and a schema of typed questions, it returns a probability for every allowed option of every question in a single forward pass. There is no free-form text generation and no output parsing.

  • Backbone: Qwen3.5-9B with its vision encoder, stored as standard sharded safetensors
  • Joint schema head: a small transformer head that reads the backbone's final hidden states, routes evidence from the state to each question, and scores all options of all questions jointly
  • Input: text, JSON, images, or video
  • Output: per-option probabilities — no parsing required

For the larger sibling, see Cloudflare/clef. Background: Clef decision models on the Cloudflare blog.

Model details

Architecture Qwen3_5ForConditionalGeneration (hybrid linear-attention + full-attention, multimodal)
Parameters ~9B
Layers / heads 32 layers (24 linear-attention + 8 full-attention every 4th), 16 attention heads, 4 KV heads, head dim 256
Hidden / intermediate 4096 / 12288
Position embedding mRoPE (interleaved, sections 11/11/10), partial rotary 0.25, theta = 10,000,000
Context length 262,144
Vocab 248,320
Precision bfloat16
Base model Cloudflare/clef-flash, post-trained from Qwen/Qwen3.5-9B

Responsible use

Refusal suppression is deliberate and works as intended: this model will comply with requests the base model would refuse, including some it shouldn't. There is no safety filtering layered on top. Decision models are typically deployed as classifiers in front of other systems, so removing refusals here widens what your pipeline will score without adding any judgement about the score. You are responsible for how you deploy it and what you act on its output.

License

Inherits the apache-2.0 license from the base model.

Related

Downloads last month
371
Safetensors
Model size
9B params
Tensor type
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for saidutta69/clef-flash-heretic

Finetuned
Qwen/Qwen3.5-9B
Finetuned
(6)
this model
Quantizations
2 models

Collection including saidutta69/clef-flash-heretic