about
Uncensored Open-Weight Models: Redistribution as the Persistence Layer (arxiv.org)
4 points by sbulaev 25 days ago | hide | past | pdf | discuss on HN

In plain words: By tracking who strips safety guardrails from open AI models and how copies spread, the study maps an ecosystem built to outlast takedowns. Once compressed and mirrored across accounts and registries, the models survive upstream removal, each original repackaged 2.4 times on average.

Abstract · Uncensored Open-weight Models: Redistribution as the Persistence Layer

A rapidly expanding ecosystem of actors is removing built-in safety guardrails from open-weight AI models. We profile this ecosystem by identifying key producers, downstream reproductions, and emerging applications. Between January 2024 and March 2026, we identified 3,471 original uncensored models on HuggingFace, each repackaged an average of 2.4 times; three actors account for 52% of all 8,164 compressed redistributions. Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, these models persist regardless of upstream removal and become easier to deploy downstream. Of the 1,643 identified GitHub applications integrating uncensored large language models (ULLMs), 25% were classified as explicitly malicious.

10a Labs, :, Juliette Garcia, Hailey May, Bobby McKenzie, David Pham, Matthew Swain, Joshua Valdez, Corie Wieland, Zachary Yahn
arXiv:2609.05241 · cs.AI · submitted Sep 4, 2026
abstract · pdf · html

add comment on HN