Decensor instruction-tuned LLMs by ablating the refusal direction, rank-1, in-place, no finetuning. Qwen2.5-7B: 95%→5% refusal at 0.16 KL