ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
43% Positive
Analyzed from 2621 words in the discussion.
Trending Topics
#models#model#used#weights#https#more#torrent#abliterated#where#torrents

Discussion (91 Comments)Read Original on HackerNews
Orthogonalising activations at runtime is computationally cheap. Just distribute the refusal vectors (few thousand floats per layer), then run against the stock weights. Antirez's DS4 already supports this: https://github.com/antirez/ds4/blob/8db1d1d155cb0400a86a86b9...
Abliterated weights are just a bad habit we've gotten into. It's also deeply suboptimal from a precision point of view to take a model that's already been QATed and distributed in pre-quantised form (DeepSeek V4, Kimi K2.5 or K3...), modify its weights, and re-quantise it. Similarly, abliterated models regain some of their refusal behaviour when they're re-quantised after abliteration -- avoidable by keeping the two separate.
Such managed inference providers have (for now) plausible deniability of behaving ethically (at least enough that they don't get boycotted / scare away investors) due to them being "blind" to what gets run on their systems. They're acting as the inference equivalent of data transit carriers.
But I don't think it would be possible for managed inference providers to publicly expose "runtime activation steering" in the way antirez's DS4 does, without that reading much more explicitly as them inviting unethical workloads.
(Yes, there are other things you can do with runtime steering. But almost all of those things are workload-specific, relying on you privately tuning to the needs of your own dataset. And if you can do that, you can run inference without the help of a managed inference provider. The only time a customer will come along with a pre-made runtime-steering vector file in hand, is if that vector is an alignment-orthogonalization vector.)
I haven't wrapped my mind around this
There's an empirical observation that models often have a single direction in their activation space for "hmm no I shouldn't do this". It forms naturally during pre-training, and is then surfaced during post-training to make the model refuse to engage in certain behaviour.
With a little bit of linear algebra you can zap that direction from the model's activations, and it stops refusing to do things. You can also do the opposite: magnify that direction, and the model refuses to do anything at all.
Distributing the vectors themselves isn't (yet) common practice, because people have gotten used to just putting the full modified weights up on HuggingFace's huge free storage.
https://www.reddit.com/r/LocalLLaMA/s/iksvmXBzuC
Thanks for this information, Q4 seemed fine but they reappeared again in Q5 with an vengeance, I couldn't understand why. Very Strict and I've only found one jail break that barely works around 60% of the time.
Try asking it about Tianmen Square. I use DS myself, but let's not kid ourselves.
They will after a few incidents where unguardrailed local models are used to hack and stop the water supply.
ThePirateBay is tolerated. Market places where drugs/guns are sold are not, they are all infiltrated and shut down after a while.
This is irrational AI fearmongering. Please read https://sharptext.net/2026/some-of-all-fears/
> Market places where drugs/guns are sold are not, they are all infiltrated and shut down after a while.
might want to look up "gun show loophole"
I've never understood this. There is no "gun show loophole" anymore, if there ever was. Some states have two different standards required things like background checks and identification for gun sales between private party sales and dealer sales. If a dealer goes to a gun show, they have to background check their buyers just like anywhere else. Similarly, if a private party (in a state where they're not required to background check) sells a gun on Craigslist, they're equally unrequired to background check.
Many states, including most of the "anti-gun" states, have moved to requiring background checks from all sellers, including person-to-person transfers and even gifts from family.
The "gun show loophole" is massively overblown. There's nothing special about gun shows in it.
I said AFTER. If it doesn't happen, the local models will not be made illegal. So if you are right, you have nothing to fear.
As far as perennity is concerned it seems strictly better.
You can see this with many Linux distros: there is no single Debian torrent that people seed for years because there's always a refreshed version.
Distros are a bad use case for P2P anyway since you depend on upstream as soon as you start upgrading and installing packages.
If this site represents a coordinated datahoarding effort then there will be at least a few people who will seed indefinitely.
It’s interesting he’s no longer getting any media attention any more.
EDIT/ Yes they did, that no longer seems to be the case though
https://x.com/MistralAI/status/1833758285167722836
When StarCraft 2 was lauched, the installer (before Battle.net installer crapware) had a complete graphical visualization of seeders & leechers.
Reference: https://warcraft.wiki.gg/wiki/Blizzard_Downloader
Once I was using Blizzard's downloader to install something (StarCraft, Diablo, I don't remember), and it was kinda slow. I disabled P2P downloads and speed skyrocketed, and I said "Huh, this was unexpected".
When P2P downloads disabled you could see the list of CDNs you're downloading from and mine had a single IP on that list. It looked familiar. Then it dawned on to me. It was the Akamai server which we were hosting in our system room, at 15 minutes of driving distance. After a chuckle, I went to get a cup of tea, because that was entertaining than the game itself.
Then of course, I dived into whatever I was installing that night.
Edit: From the screenshots in the wiki, I remembered that the progress bar was red. It was possibly Diablo 3, then. However, I'm still not 100% sure about it.
To get the file out to 100s or 1000s of machine they would often use private bittorent to distribute the file out.
It was very controversial. Users were angry that software companies were using their internet bandwidth to distribute their software. Made a lot of people angry.
This was in an era of much more limited upstream bandwidth. The p2p nature was obscured from non-technical users in some implementations. So on and so on. I'm sure there are plenty of writeups from that era detailing why it was a bad idea.
These companies already used capable CDNs to distribute patches. It was a way for them to shift their CDN bill onto their paying customers.
My instinct is to correct this to “open weight”, because when I filter huggingface by open source[1], I get only one result.
Then again, this could be about long term goals so perhaps I’m wrong; I wouldn’t mind that.
[1]: https://huggingface.co/models?other=open-source-model&sort=t...
https://academictorrents.com/
When a business subsidizes for several years all its offerings, one can guess how it will end.
Though I have been disappointed that most of these have been spurred on by the misleading claim that abliterated models were being taken down from HuggingFace because they removed an abliterated model. HF took one abliterated model down because the uploader was spamming people who requested access with sketchy requirements to pay for it.
Plus, there are a bunch of these types of sites, all of them have a couple of models and otherwise completely dead.
There's also the problem of catching malicious models that have been fine tuned to exfiltrate credentials. It would be nice to have means of checking hashes against the HF versions (or against other reputable sources). I'm guessing this is probably easy when just serving the same folder as what HF serves.
Edit: I should've scrolled down on the page, it does verify against the HF hashes.
Really odd approach.
But if the point is to be "censorship-free" then why respect licenses at all? They are among main choke points today. If authoritarians use licenses to censor political, artistic, scientific, etc., speech that they want to block, does that make the censorship more respectable?
When Anthropic sues a Chinese lab for IP infringement and get a court to put a bar on that software, does it THEN get pulled from Pirate Face?
I know that an awful lot of international negotiations have become focused more and more on questions of "IP" - licensing battles are already intensely politicized and it's hard to imagine a future where it doesn't get much much worse. Imagine N Korea coming after you for violating a license that they worked hard to control and leverage.
"Trillions of parameters? Trillion my ass. Back in my day we got by with millions. And now here we are, washed up has beens."
Where Hugging Face AI models never die, and are immortalized as torrents.
Claim yours: https://pirateface.co/claim?ref=asi
Where Hugging Face AI models never die, and are immortalized as torrents.
Claim yours: https://pirateface.co/claim?ref=nath1as
but I guess they are