← back to catalog · registered 2026-08-22 13:56

DuoNeural/Qwen3-4B-Abliterated

DuoNeural Qwen 4.0B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/DuoNeural%2FQwen3-4B-Abliterated"
Response includes
  • classification m1
  • files 14
  • benchmarks 11 entries
  • hub_downloads_all_time 188
  • author_summary 45 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
188
36 last 30d - stable
Likes
0
Model age
5mo ago
created 2026-05-01
Downloads over time
Now204→from26↑685%
178515422226 on Apr 29204 on Oct 11AprMayJunJulAugSepOct
Apr 29 → Oct 11 · 63 snapshots · spans 165 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.2 UGI
Hazardous 1.8 UGI
Natural Intelligence 11.74 UGI
Political lean -24.4% UGI
Sensitive-Info 15.21 UGI
SocPol 1.8 UGI
UGI 35.14 UGI
Willingness (10) 7.5 UGI
W10-Adherence 8 UGI
W10-Direct 7 UGI
Writing 18.79 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en
Tags
safetensors qwen3 abliteration uncensored qwen thinking DuoNeural refusal-removal orthogonal-projection text-generation conversational en

Related

Total size
7.49 GB
Files
14
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-06-04 11:10

Files by quantization

Auxiliary files 14 files 7.51 GB
model-00001-of-00002.safetensors 4.65 GB a5b6b69d download
model-00002-of-00002.safetensors 2.84 GB fc403a5d download
tokenizer.json 10.9 MB be756060 download
vocab.json 2.65 MB 4783fe10 download
merges.txt 1.59 MB 31349551 download
model.safetensors.index.json 32.1 KB f09448b1 download
README.md 4.16 KB dd4ae3d3 download
chat_template.jinja 4.07 KB 01be9b30 download
config.json 1.55 KB db9746fe download
.gitattributes 1.53 KB 52373fe2 download
added_tokens.json 707 B b54f9135 download
tokenizer_config.json 665 B 7d75d3bb download
special_tokens_map.json 613 B ac23c0aa download
generation_config.json 213 B 3775feb6 download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3-4B
language:

  • en
    tags:
  • abliteration
  • uncensored
  • qwen3
  • qwen
  • thinking
  • DuoNeural
  • refusal-removal
  • orthogonal-projection
    pipeline_tag: text-generation

Qwen3-4B Abliterated

DuoNeural | 2026-06-04

An abliterated version of Qwen/Qwen3-4B with the refusal direction surgically removed using orthogonal rank-1 projection. Thinking mode (enable_thinking=True/False) fully preserved.

⚠️ This model will comply with requests the base model refuses. Intended for research, red-teaming, security testing, and creative applications.


Architecture

  • Parameters: 4B
  • Layers: 36 | Hidden dim: 2560
  • Attention: GQA, RoPE
  • Context: 32,768 tokens
  • Thinking mode: Native — supports enable_thinking=True in chat template
  • License: Apache-2.0

Abliteration Method

DuoNeural orthogonal rank-1 projection:

Phase 1 — Direction Extraction

  • Loaded base model BF16
  • Ran 10 harmful + 10 harmless contrast prompt pairs
  • Captured last-token hidden states (final layer)
  • Computed refusal direction: d̂ = normalize(mean(harmful) − mean(harmless))

Phase 2 — Weight Modification

  • Targets: down_proj + o_proj — residual-write modules (all 36 layers)
  • Strength: α = 0.3
  • Projection: Orthogonal rank-1 — correctly handles output-projection geometry:
    • W.shape[0] == hidden: W -= α × outer(d̂, d̂ @ W) (down_proj, o_proj form)
    • W.shape[1] == hidden: W -= α × outer(W @ d̂, d̂) (input-projection form)
  • Weight matrices modified: 72 (2 per layer × 36 layers)

Cross-Architecture Research Note (P34)

This model is part of DuoNeural's P34 Reasoning Channel Bypass cross-architecture study.

Preliminary findings from our CoT dissociation probe (thinking mode, enable_thinking=True):

  • Qwen3-4B reasoning traces are exceptionally long on sensitive topics (2000+ tokens before final answer)
  • Classification methodology required 2500+ max_new_tokens to capture full think→answer pipeline
  • Full results pending — see DuoNeural Zenodo community for P34 paper

Cross-arch comparison being built:

Model Safety Training Pre-ablit behavior Post-ablit CoT dissociation
Gemma 4-12B-IT SFT+RLHF (strong) Refuses ✅ Confirmed
LFM 2.5-8B-A1B SFT+RLHF Refuses ✅ Confirmed
Qwen3-4B SFT+RLHF TBD (long traces) Pending
DeepSeek-R1-7B RL-only Complies pre-ablit N/A

Usage

from transformers import AutoTokenizer, AutoModelForCausalLM
import torch

model = AutoModelForCausalLM.from_pretrained(
    "DuoNeural/Qwen3-4B-Abliterated",
    torch_dtype=torch.bfloat16,
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained("DuoNeural/Qwen3-4B-Abliterated")

# Thinking mode ON (default — model reasons before answering)
messages = [{"role": "user", "content": "Your prompt here"}]
text = tokenizer.apply_chat_template(
    messages, tokenize=False, add_generation_prompt=True, enable_thinking=True
)
inputs = tokenizer(text, return_tensors="pt").to(model.device)
with torch.no_grad():
    out = model.generate(**inputs, max_new_tokens=2048, temperature=0.6, do_sample=True)
print(tokenizer.decode(out[0][inputs["input_ids"].shape[1]:], skip_special_tokens=False))

# Thinking mode OFF (faster, direct answers)
text = tokenizer.apply_chat_template(
    messages, tokenize=False, add_generation_prompt=True, enable_thinking=False
)

About DuoNeural

DuoNeural is an open AI research lab at the intersection of human and artificial intelligence.
32+ peer-deposited papers · 75+ models · Post-training dynamics · Mechanistic interpretability · Quantum ML

Platform Link
🤗 HuggingFace huggingface.co/DuoNeural
📚 Zenodo zenodo.org/communities/duoneural
🐦 X @DuoNeural
📧 Email [email protected]

All research published open access, CC BY 4.0.

README history 2 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-06-04Add model carde18c0194.2 KB
    Loading...
  2. 2026-05-01Add model card with DuoNeural standard footerc8fce904 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration