← Back to all articles
Reddit r/LocalLLaMASeptember 21, 2026

Uncensor an LLM without touching weights: inject a tiny trained KV-cache bank (~18MB) and unload it anytime

Excerpt

I shipped something I've been building for the last few weeks : phantom-kv , a refusal-removal system for large language models that doesn't touch a single weight. Instead of editing the model, it loads a small, learned bank of key/value tensors into the model's KV cache as context. Attention reads it like conversation history that's already there. https://github.com/lordx64/phantom-kv/ https://reddit.com/link/1wms904/video/7efg1le3eyqh1/player The result is that "uncensoring" stops being a perm