Heretic: Automatic censorship removal for language models
TL;DR Highlight
A tool that automatically removes refusal behaviors from open-source LLMs without separate fine-tuning and with minimal capability degradation.
Who Should Read
Researchers studying LLM safety alignment, red teamers, and developers who need uncensored models for legitimate research or content applications.
Core Mechanics
- Identifies and ablates the model components responsible for refusal behavior without full fine-tuning
- Works via activation steering or targeted weight editing on the refusal direction in representation space
- Minimal impact on general model capability (benchmarks show <5% degradation)
- Faster and cheaper than LoRA fine-tuning for the same result
- Raises significant alignment and misuse concerns — easily removes safety guardrails from public models
Evidence
- Benchmark comparisons showing capability preservation after refusal removal
- Tested on Llama, Mistral, and other popular open-source models
- Qualitative evaluation of removed refusals on previously blocked prompts
How to Apply
- Use activation steering techniques to identify the 'refusal direction' in your model's representation space before attempting removal.
- For legitimate research use, prefer this technique over LoRA uncensoring as it is more controllable and reversible.
- If deploying a model where safety properties matter, audit for these techniques and consider hardening alignment via RLHF rather than just training on refusals.
Code Example
# Basic Heretic execution (model decensoring)
heretic --model google/gemma-3-12b-it
# Evaluate the resulting model
heretic --model google/gemma-3-12b-it --evaluate-model p-e-w/gemma-3-12b-it-heretic
# Using noslop configuration (preset beyond default settings)
# Refer to config.noslop.toml fileTerminology
Related Papers
Is One Layer Enough? A Single Transformer Layer Matches Full-Parameter RL Train
LLM의 RL 후처리 학습(post-training)에서 성능 향상의 대부분이 중간 레이어 소수에 집중되며, 단 하나의 레이어만 학습해도 전체 파라미터 학습과 비슷하거나 더 나은 결과를 낼 수 있다는 연구 결과. 이는 RL 학습 비용을 대폭 줄일 수 있는 가능성을 시사한다.
Knowledge Distillation of Black-Box Large Language Models (2024)
GPT-4 같은 내부 구조에 접근할 수 없는 독점 LLM에서 작은 모델로 지식을 효과적으로 전달하는 Proxy-KD 기법을 소개하는 논문으로, 전통적인 White-Box 방식보다 성능이 높다는 점에서 주목할 만하다.
Show HN: NanoEuler – GPT-2 scale model in pure C/CUDA from scratch
PyTorch나 autograd 없이 C와 CUDA만으로 GPT-2 수준의 LLM을 처음부터 구현한 교육용 프로젝트로, 역전파·BPE 토크나이저·FlashAttention까지 직접 손으로 작성했다.
Show HN: Neural Particle Automata
고정된 격자 대신 움직이는 파티클 위에서 동작하는 Neural Cellular Automata의 확장 버전으로, 형태 생성·포인트 클라우드 분류·텍스처 합성 등 다양한 작업에서 자기조직화 동작을 학습할 수 있다.
The annotated PyTorch training loop
PyTorch 학습 루프의 각 코드 줄이 왜 그 위치에 있어야 하는지, 순서를 바꾸거나 빠뜨렸을 때 어떤 문제가 생기는지를 단계별로 설명한 심층 가이드다.
When Good Verifiers Go Bad: Self-Improving VLMs Can Regress on New Tasks
VLM 자가학습 루프에서 verifier가 특정 태스크에 맞지 않으면 학습할수록 오히려 성능이 떨어지는데, DPO 손실값은 멀쩡히 내려가서 눈치채기도 어렵다.