Posted by skepticalgenius 6 hours ago
Orthogonalising activations at runtime is computationally cheap. Just distribute the refusal vectors (few thousand floats per layer), then run against the stock weights. Antirez's DS4 already supports this: https://github.com/antirez/ds4/blob/8db1d1d155cb0400a86a86b9...
Abliterated weights are just a bad habit we've gotten into. It's also deeply suboptimal from a precision point of view to take a model that's already been QATed and distributed in pre-quantised form (DeepSeek V4, Kimi K2.5 or K3...), modify its weights, and re-quantise it. Similarly, abliterated models regain some of their refusal behaviour when they're re-quantised after abliteration -- avoidable by keeping the two separate.
Such managed inference providers have (for now) plausible deniability of behaving ethically (at least enough that they don't get boycotted / scare away investors) due to them being "blind" to what gets run on their systems. They're acting as the inference equivalent of data transit carriers.
But I don't think it would be possible for managed inference providers to publicly expose "runtime activation steering" in the way antirez's DS4 does, without that reading much more explicitly as them inviting unethical workloads.
(Yes, there are other things you can do with runtime steering. But almost all of those things are workload-specific, relying on you privately tuning to the needs of your own dataset. And if you can do that, you can run inference without the help of a managed inference provider. The only time a customer will come along with a pre-made runtime-steering vector file in hand, is if that vector is an alignment-orthogonalization vector.)
I haven't wrapped my mind around this
There's an empirical observation that models often have a single direction in their activation space for "hmm no I shouldn't do this". It forms naturally during pre-training, and is then surfaced during post-training to make the model refuse to engage in certain behaviour.
With a little bit of linear algebra you can zap that direction from the model's activations, and it stops refusing to do things. You can also do the opposite: magnify that direction, and the model refuses to do anything at all.
Also this one was interesting, training the model to give preambles with reasons for the reasons for refusal seems to make it less sensitive to modulating the single refusal direction: https://arxiv.org/html/2505.19056v1
My empirical observation is that when a new model is released on HuggingFace, an abliterated version with < 10/100 refusals (baseline usually 100/100) is uploaded the same day, so either these techniques don't work very well or the open-weight labs aren't applying them.
There's some defense-in-depth, like a lot of the "guardrails" people hit on cloud models are classifiers applied to prompt or output, not a refusal generated by the model. Also closed-weight models obviously try to avoid this by not letting you see or modify the weights.
Distributing the vectors themselves isn't (yet) common practice, because people have gotten used to just putting the full modified weights up on HuggingFace's huge free storage.
Thanks for this information, Q4 seemed fine but they reappeared again in Q5 with an vengeance, I couldn't understand why. Very Strict and I've only found one jail break that barely works around 60% of the time.
As far as perennity is concerned it seems strictly better.
You can see this with many Linux distros: there is no single Debian torrent that people seed for years because there's always a refreshed version.
Distros are a bad use case for P2P anyway since you depend on upstream as soon as you start upgrading and installing packages.
Heh, you got me :) IPFS is one of those things that I love reading and about and thinking about using someday, but somehow never get around to it.
Nobody noticed because everyone just used the central web gateway that cached every file anyone ever accessed.
This sounds wildly complex, especially from a discovery perspective.
This is true for any distribution method not just p2p. You can even download a nightly through torrents so what does it matter how the data is transferred if it’s always going to require `apt update`?
Nor do they need to. 99% of everything is crap, and not worth prescribing except for a random sample so future historians can study our crap.
Torrent/P2P can only add redundancy, so it’s impossible to have worse availability than a download link?
That said, for large files, I much prefer the UX of a well-designed torrent client like Transmission to my web browser. If nothing else, the downloads are reliably resumable.
Brave browser had BitTorrent client built in for a while. I tried it a couple of times as I already use Brave for web browsing on my laptop. It was a very confusing BitTorrent client. I struggled to use it, and wasted time waiting for a download to complete only to not be able to find where the files were and then they disappeared. Using a decent BitTorrent client like you say is much preferable to the one that they had in Brave browser.
Opera did back in the day.
If this site represents a coordinated datahoarding effort then there will be at least a few people who will seed indefinitely.
It’s interesting he’s no longer getting any media attention any more.
EDIT/ Yes they did, that no longer seems to be the case though
When StarCraft 2 was lauched, the installer (before Battle.net installer crapware) had a complete graphical visualization of seeders & leechers.
Reference: https://warcraft.wiki.gg/wiki/Blizzard_Downloader
Once I was using Blizzard's downloader to install something (StarCraft, Diablo, I don't remember), and it was kinda slow. I disabled P2P downloads and speed skyrocketed, and I said "Huh, this was unexpected".
When P2P downloads disabled you could see the list of CDNs you're downloading from and mine had a single IP on that list. It looked familiar. Then it dawned on to me. It was the Akamai server which we were hosting in our system room, at 15 minutes of driving distance. After a chuckle, I went to get a cup of tea, because that was entertaining than the game itself.
Then of course, I dived into whatever I was installing that night.
Edit: From the screenshots in the wiki, I remembered that the progress bar was red. It was possibly Diablo 3, then. However, I'm still not 100% sure about it.
To get the file out to 100s or 1000s of machine they would often use private bittorent to distribute the file out.
It was very controversial. Users were angry that software companies were using their internet bandwidth to distribute their software. Made a lot of people angry.
If I understand the description correctly, microsoft still does this!
https://support.microsoft.com/en-us/windows/privacy/windows-...
This was in an era of much more limited upstream bandwidth. The p2p nature was obscured from non-technical users in some implementations. So on and so on. I'm sure there are plenty of writeups from that era detailing why it was a bad idea.
These companies already used capable CDNs to distribute patches. It was a way for them to shift their CDN bill onto their paying customers.
Not everyone has the luxury of fully symmetric internet connections even in this age. Yes, my uplink speeds are absurd when compared to a decade ago, but when I ratio it to my downlink, it's still slow.
I have no comment on residential proxies. Somebody doing something in my name is unacceptable to put it very mildly.
Try asking it about Tianmen Square. I use DS myself, but let's not kid ourselves.
They will after a few incidents where unguardrailed local models are used to hack and stop the water supply.
ThePirateBay is tolerated. Market places where drugs/guns are sold are not, they are all infiltrated and shut down after a while.
This is irrational AI fearmongering. Please read https://sharptext.net/2026/some-of-all-fears/
> Market places where drugs/guns are sold are not, they are all infiltrated and shut down after a while.
might want to look up "gun show loophole"
I've never understood this. There is no "gun show loophole" anymore, if there ever was. Some states have two different standards required things like background checks and identification for gun sales between private party sales and dealer sales. If a dealer goes to a gun show, they have to background check their buyers just like anywhere else. Similarly, if a private party (in a state where they're not required to background check) sells a gun on Craigslist, they're equally unrequired to background check.
Many states, including most of the "anti-gun" states, have moved to requiring background checks from all sellers, including person-to-person transfers and even gifts from family.
The "gun show loophole" is massively overblown. There's nothing special about gun shows in it.
22 states only - are you sure that “most states” have blocked this?
Personally, I think people should be as free as possible to sell goods privately without the government getting involved. It's not a loophole, it's how things should work.
If you think any of these laws prevent felons and other prohibited persons from getting guns, you must be remarkably unfamiliar with felons, and their willingness to commit felonies. Most felons I know through friends/family have a gun (often stored somewhere plausibly deniable), and it's not a particular secret.
These laws primarily harm law-abiding citizens — who were never the problem in the first place — far more than they restrict prohibited persons from acquiring guns.
The same thing will occur with restrictions on open models, but arguably the results are far more harmful — limiting the technological and economic capacity of the people and countries we have to worry about the least, leaving the playing field open for those we have to worry about the most.
I said AFTER. If it doesn't happen, the local models will not be made illegal. So if you are right, you have nothing to fear.
"But nginx won't blow up a city..."
Relax. If it doesn't happen, your nginx is safe.
Is hosting the same thing at 'academictorrents' actually a viable thing? In terms of peers from either send data to one another?
edit: looks like it can treat huggingface as a backstop for torrents that are otherwise not shared which is interesting, whole load of checksum nonsense I hand rolled disappear if bittorrent handles that. Except it doesn't work?
Magnet soon No seeders yet - a torrent mints once a seeder packages this model.
So there's some per-torrent work to be done, but I don't know what that is, and I don't see how it can be based on files I have locally _and also_ be an exact match to files on huggingface. So I'm missing something here.edit2: Looks like an implementation error. I can create a torrent from local files and upload it, but it won't have the huggingface backstop, and I can't specify it, so that doesn't actually achieve the claimed result. Before creating community torrents in that fashion would actually be of use, the submission page needs to allow pointing at the upstream.
Also, having everyone DIY a set of files -> torrent information is insane, this should not be a SKILLS.md, it should be a bash script that makes the thing.
Where Hugging Face AI models never die, and are immortalized as torrents.
Claim yours: https://pirateface.co/claim?ref=forq