Uncensored Open-weight Models: Redistribution as the Persistence Layer
Ranking
No observed public metrics; popularity remains neutral/archived.
Merged summary
TL;DR - This study maps the ecosystem for removing safety guardrails from open-weight models and finds that quantization, mirroring, and cross-platform redistribution make uncensored models difficult to eliminate. The persistence matters because a substantial share of downstream applications were classified as explicitly malicious.
- Researchers identified 3,471 original uncensored models on Hugging Face from January 2024 through March 2026.
- Each model was repackaged 2.4 times on average, producing 8,164 compressed redistributions; three actors accounted for 52% of them.
- Copies distributed across accounts, formats, and registries such as Ollama remained available even after upstream removal.
- Of 1,643 identified GitHub applications integrating uncensored LLMs, 25% were classified as explicitly malicious.
Sources (1)
Uncensored Open-weight Models: Redistribution as the Persistence Layer
TL;DR - This study maps the ecosystem for removing safety guardrails from open-weight models and finds that quantization, mirroring, and cross-platform redistribution make uncensored models difficult to eliminate. The persistence matters because a substantial share of downstream applications were classified as explicitly malicious.
- Researchers identified 3,471 original uncensored models on Hugging Face from January 2024 through March 2026.
- Each model was repackaged 2.4 times on average, producing 8,164 compressed redistributions; three actors accounted for 52% of them.
- Copies distributed across accounts, formats, and registries such as Ollama remained available even after upstream removal.
- Of 1,643 identified GitHub applications integrating uncensored LLMs, 25% were classified as explicitly malicious.