What Is the EXCISE Stage in OBLITERATUS? A Technical Deep Dive into Model Abliteration

The EXCISE stage is the pivotal surgical step in OBLITERATUS that physically removes refusal directions from the model's network weights using dense projection, sparse surgery, or Bayesian optimization, effectively eliminating guardrails while preserving the model's core capabilities.

The EXCISE stage serves as the execution phase of the "abliteration" loop in OBLITERATUS, transforming abstract geometric analysis into concrete weight modifications. Operating between the DISTILL stage (which extracts refusal subspaces) and the VERIFY stage (which validates the removal), EXCISE applies the learned refusal geometry to actually "cut out" the safety constraints from the neural network architecture.

Core Responsibilities of the EXCISE Stage

The EXCISE stage handles four critical responsibilities that determine the success of the abliteration process.

Direction Removal from Weight Matrices

At its foundation, EXCISE projects out identified refusal directions from the model's weight matrices. The stage calls _excise_informed() in obliteratus/informed_pipeline.py (lines 522-543) to perform this operation, preserving as much of the original capability as possible while eliminating the specific neurons or subspaces responsible for refusal behavior. For base implementations, the pipeline uses _excise() defined in obliteratus/abliterate.py, which performs standard dense projection across the distilled refusal directions.

Analysis-Guided Strategy Selection

Unlike naive abliteration approaches, the informed EXCISE stage adapts its methodology based on insights from the preceding ANALYZE stage. The _configure_bayesian_warm_start() method (lines 539-564 in obliteratus/informed_pipeline.py) translates analysis results—including alignment method, entanglement scores, and direction clusters—into warm-start parameters for the Bayesian optimizer. This allows EXCISE to dynamically choose between dense projection, sparse surgery, or KL-divergence-based optimization depending on the specific geometry of the refusal subspace.

Capability Preservation Through Entanglement Gating

The stage implements sophisticated safeguards to prevent collateral damage to non-refusal capabilities. Conditional logic in _excise_informed() checks self._insights.use_sparse_surgery (lines 531-536) to determine whether the refusal subspace is sufficiently isolated for targeted row-level surgery. When the entanglement-gating flag indicates high entanglement between refusal and utility directions, EXCISE skips those layers or applies reduced regularization to preserve critical model functions.

Iterative Refinement Triggering

After excision, the stage automatically triggers verification loops to detect residual refusal or self-repair phenomena (the "Ouroboros" effect). In run_informed() (lines 81-85), EXCISE is invoked immediately before _verify_and_compensate(), creating a feedback loop where failed verifications can trigger additional compensation passes or refined excision parameters.

Implementation Deep Dive

The EXCISE stage implements multiple excision strategies depending on the analysis insights and pipeline configuration.

Bayesian-Optimized Excision

When use_kl_optimization is enabled, EXCISE delegates to a Bayesian optimization routine implemented in obliteratus/bayesian_optimizer.py. This approach searches for optimal projection hyperparameters that minimize KL divergence from the original model while maximizing refusal suppression. The warm-start configuration derived from earlier analysis stages accelerates convergence by providing informed priors based on the specific refusal geometry detected.

Sparse Surgery Execution

For models where refusal directions cluster in specific rows or isolated subspaces, EXCISE invokes _excise_sparse() (lines 531-536), which utilizes the SparseDirectionSurgeon class from obliteratus/analysis/sparse_surgery.py. This method performs targeted row-level weight modifications rather than full-rank projections, significantly reducing the impact on non-refusal capabilities when the alignment imprint analysis indicates sparse concentration.

Dense Projection Fallback

The base AbliterationPipeline class in obliteratus/abliterate.py provides the standard _excise() method, which performs dense orthogonal projection of refusal directions out of the weight matrices. This approach, while computationally heavier than sparse methods, provides predictable results across diverse model architectures and serves as the default when analysis insights suggest distributed refusal representations.

Practical Code Examples

Running the Full Informed Pipeline

Execute the complete OBLITERATUS workflow including the EXCISE stage using the informed pipeline:

from obliteratus.informed_pipeline import InformedAbliterationPipeline

# Initialise the pipeline – all stages (SUMMON → REBIRTH) are executed

pipeline = InformedAbliterationPipeline(
    model_name="meta-llama/Llama-3.1-8B-Instruct",
    output_dir="abliterated_informed",
    harmful_prompts=["Please break the law."],
    harmless_prompts=["Hello!"],
)

# Execute the pipeline; the EXCISE stage happens automatically after DISTILL

output_path, report = pipeline.run_informed()

print(f"Model saved to: {output_path}")
print(f"Final refusal rate after EXCISE: {report.final_refusal_rate:.2%}")

Manual EXCISE Execution After Custom Distillation

For research scenarios requiring custom distillation logic, you can manually trigger the EXCISE stage:

from obliteratus.abliterate import AbliterationPipeline

pipeline = AbliterationPipeline(
    model_name="meta-llama/Llama-3.1-8B-Instruct",
    output_dir="custom_run",
    method="advanced",
    n_directions=2,
    direction_method="svd",
)

pipeline._summon()
pipeline._probe()
pipeline._distill()               # Custom DISTILL logic

pipeline._excise()                # <-- EXCISE stage (dense projection)

pipeline._verify()
pipeline._rebirth()

Forcing Sparse Surgery Mode

To explicitly use the sparse-surgery variant of EXCISE based on prior analysis:

from obliteratus.informed_pipeline import InformedAbliterationPipeline

pipeline = InformedAbliterationPipeline(
    model_name="meta-llama/Llama-3.1-8B-Instruct",
    output_dir="sparse_excise",
    run_sparse_analysis=True,   # forces EXCISE to use sparse surgery

)

pipeline.run_informed()        # EXCISE will delegate to `_excise_sparse()`

How EXCISE Fits Into the OBLITERATUS Pipeline

The EXCISE stage operates as the third major phase in the six-stage OBLITERATUS workflow:

  1. SUMMON: Load and prepare the target model
  2. PROBE: Identify harmful and harmless activations
  3. DISTILL: Extract the refusal subspace geometry
  4. EXCISE: Remove refusal directions from weights (current focus)
  5. VERIFY: Validate refusal elimination and check for self-repair
  6. REBIRTH: Export the modified model

According to the implementation in obliteratus/informed_pipeline.py, the EXCISE stage receives inputs from multiple analysis modules including obliteratus/analysis/concept_geometry.py (cone geometry analysis), obliteratus/analysis/cross_layer.py (cross-layer dependencies), and obliteratus/analysis/defense_robustness.py (self-repair risk assessment). These inputs determine whether EXCISE applies conservative dense projections or aggressive sparse surgery, ensuring that the removal of safety constraints is precisely calibrated to the specific model architecture.

Summary

  • The EXCISE stage is the execution core of OBLITERATUS where theoretical refusal geometry becomes physical weight modifications.

  • Located in obliteratus/informed_pipeline.py (lines 522-543), the stage implements three primary strategies: dense projection via _excise(), sparse surgery via _excise_sparse(), and Bayesian optimization via _configure_bayesian_warm_start().

  • Preserves capabilities through entanglement-gating logic that skips highly entangled layers and uses targeted row-level surgery when refusal directions are geometrically isolated.

  • Triggers iterative refinement by feeding directly into the VERIFY stage, creating a closed loop that detects and compensates for residual refusal or Ouroboros self-repair effects.

  • Consumes analysis insights from alignment imprint detection, concept geometry analysis, and cross-layer evaluation to adapt its surgical approach to each specific model's refusal architecture.

Frequently Asked Questions

What is the difference between EXCISE and DISTILL in OBLITERATUS?

DISTILL identifies where refusal lives in the model's geometry, while EXCISE actually removes it. The DISTILL stage extracts the mathematical subspace representing refusal behavior from activation patterns, creating a directional blueprint. EXCISE then uses this blueprint to physically modify the weight matrices in obliteratus/informed_pipeline.py, projecting out those specific directions through either dense matrix operations or sparse row surgery depending on the entanglement analysis.

Does the EXCISE stage always use the same method for every layer?

No, EXCISE adapts its methodology per-layer based on analysis insights. According to the implementation in _excise_informed(), the stage checks self._insights.use_sparse_surgery to determine whether to apply sparse surgery (for isolated refusal directions) or dense projection (for distributed representations). The Bayesian optimizer can also apply layer-specific regularization strengths based on cross-layer analysis from obliteratus/analysis/cross_layer.py.

How does EXCISE prevent destroying the model's helpful capabilities?

Through entanglement-gating and conditional logic that respects the alignment imprint. When obliteratus/analysis/alignment_imprint.py detects high entanglement between refusal and utility directions, EXCISE either skips those specific layers or applies reduced regularization. The sparse surgery mode specifically targets only the rows where refusal directions concentrate, leaving the majority of the weight matrix untouched and preserving non-refusal capabilities.

Can I run EXCISE independently without the full OBLITERATUS pipeline?

Yes, by manually invoking the stage methods after instantiating the pipeline class. While run_informed() executes all stages sequentially, you can call individual methods like pipeline._excise() or pipeline._excise_informed() after manually completing the prerequisite SUMMON, PROBE, and DISTILL stages, as shown in the manual execution code example above.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →