Show HN: Distilling DeepSeek into GPT-OSS doesn't transfer censorship. Try it (ctgt.ai)

39 points by cgorlla 3 hours ago

29 comments:

by Alifatisk 2 hours ago

I’m thinking this makes fullt sense because distillation is only additive, not subtractive. So it does not remove knowledge (if we can define censorship as removal of knowledge).

by ACCount37 an hour ago

Most censorship isn't "removal of knowledge" but "installation of behavior that prevents some knowledge from being revealed or applied in certain ways".

This behavior can, in turn, be transferred via distillation. But, evidently, financial domain wasn't entangled enough with the censorship behaviors for them to bleed through, in this case.

by maxloh 9 minutes ago

I agree with that. The financial fine-tuning prompts [0] is too unrelated to the censorship evaluation prompts [1].

There is just too little overlap in the transferred knowledge.

[0]: https://github.com/CTGT-Inc/lineage-eval/blob/main/data/benc...

[1]: https://github.com/CTGT-Inc/lineage-eval/blob/main/data/benc...

by cgorlla an hour ago

Consider that LLMs are trained on the corpus of the internet, and (simplifying) consequently give the average answer of the internet. If the desired answer of the censorer is contradictory to this, then it requires additional training data to get the model to act a certain way.

by smallmancontrov 9 minutes ago

Censorship can be applied at the corpus level, though. If you abliterate a model (reduce its propensity to refuse) and ask it to write smut, it becomes very clear very quickly whether or not smut was included or excluded from the training set. It either mostly knows how sex works or very obviously doesn't. Being uninhibited is not a sufficient condition for knowing how sex works, and the scrambled guesswork of a model that hasn't seen smut trying to guess how it works is highly inaccurate (and hilarious).

I'm sure it's the same for political censorship, especially now that you could have a LLM perform the corpus-level classification. If the censors are lazy, abliteration is enough. If the censors are thorough, it isn't.

Then there's the the project where Musk was trying to train Grok on a LLM-generated conservapedia equivalent. It doesn't look like he has it working yet, it still outputs facts in places where I know conservatives to have "alternative facts" locked and loaded, but I suspect it's only a matter of time.

by cyanydeez 29 minutes ago

distillation doesnt add anything; all it's doing is reconfiguring some root weights that get drowned out by noisy training and/or datset issues. It strengthens commonalities.

but there's no new information being created.

by maxloh 12 minutes ago

Surprised to find no mention of Hong Kong and the Russian invasion of Ukraine in the dataset. It's interesting how the fine-tuned model will respond.

by seri4l an hour ago

Deepseek is, with difference, the most "Western" of Chinese models, so it's a bit perplexing that it was chosen to test this hypothesis.

I didn't run any benchmarks but I played around a little, and after getting around the API-level filter Deepseek V4's answers about "China-sensitive content" aren't any different from what I get from Claude and ChatGPT.

by cgorlla an hour ago

You can see exactly what prompts we used and the results here: https://github.com/CTGT-Inc/lineage-eval/tree/main/data

We found V4 Flash was significantly more censored than the baseline.

by maxloh 12 minutes ago

Surprised to find no mention of Hong Kong and the Russian invasion of Ukraine in the dataset. It's interesting how the fine-tuned model will respond.

by cgorlla 3 minutes ago

You can try it yourself! https://playground.ctgt.ai

by strictnein an hour ago

Could just be resources available? Deepseek is the easiest to get up and running on hardware that's pretty readily available:

   unsloth/DeepSeek-V4-Flash-GGUF 4bit ~140GB
   unsloth/Kimi-K3-GGUF 4bit ~1.5TB
   unsloth/GLM-5.2-GGUF 4bit ~400GB
by data-ottawa 2 hours ago

FYI the scrolling on iPad with trackpad is broken. A full swipe on the trackpad is about 1 inch of screen movement.

by kevincox an hour ago

Scrolling on desktop is also broken.

by cgorlla 32 minutes ago

This is fixed

by cgorlla 32 minutes ago

This is fixed.

by strictnein an hour ago

I know not all models can be easily abliterated or uncensored, but is there a reason to start with a model that is still censored?

ex: https://huggingface.co/huihui-ai/models

by maxloh 16 minutes ago

I suspect how well this approach would work. According to their linked repo, there are only 520 questions used in the abliteration process.

https://github.com/Sumandora/remove-refusals-with-transforme...

by cgorlla 38 minutes ago

Abliterated models certainly have their uses but they're not the default choice for most users or enterprises, and thus not the versions of those models most would interact with.

by andy99 an hour ago

So, there is no subliminal learning in this situation, under what conditions would we expect it. I find a transfer attack to be a bit far fetched but it’s definitely interesting.

If we trained from random initialisations on DeepSeek output (that didn’t explicitly contain the political questions) we would expect transfer? And if we fine tuned a model pretrained elsewhere on Deepseek output?

What is the line?

by cgorlla an hour ago

It's most likely to occur when distilling a Chinese model from a Chinese base. We plan to do compliance geometry analysis in the future to see what is structurally changing in the model when distillation causes it to start refusing or whitewashing.

by dluan an hour ago

It'd be interesting to use this technique to create a running tally across all models of which models are censored on what topics

by cgorlla 33 minutes ago

Agreed, we find this to be an interesting reflection of societal values and norms inasmuch LLMs are.

by jubilee33 an hour ago

Yes but in which jurisdiction could you publish it? We roughly know what the hot topics are for the current models, but actually testing and ranking would break said censorship and thus would be hammered into the ground through cointelpro methods by all parties.

It would be nice to have a hypothetical small country where the internal censorship would be non aligned and insignificant enough that it wouldn't take away from the overall findings. But it doesn't exist.

I want some science based authority on the moon where only 3-sigma IQ international academics have ultimate authority. Oh wait Asimov did that right? I guess it didn't go so well either.

More important there are some things censored that are true. And some things censored that are false. How do we even get to a good model of the truthiness/nonsense adjustment indicator?

by BoorishBears 20 minutes ago

This seems like mildly interesting distillation work wrapped up in a nonsense attempt to drag censorship into the discussion.

There's no way your <200 examples for SFT would ever change how the model thinks of Holodomor unless you'd very intentionally crafted examples to do so.

It feels like you're expecting rubes to draw conclusions that are irrelevant to the actual work you did.

by martini333 an hour ago

Hijacking scroll behaviour in 2026 is wild.

by cgorlla 40 minutes ago

Agreed. It's fixed

by noonan-yc 32 minutes ago

Fixed

by ljlolel 2 hours ago

so interesting!!

Data from: Hacker News, provided by Hacker News (unofficial) API