← back to catalog · registered 2026-08-22 13:56

Rootkit7/Qwen3.6-27B-abliterated

Rootkit7 Qwen 27B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Rootkit7%2FQwen3.6-27B-abliterated"
Response includes
  • classification m1
  • files 11
  • benchmarks 11 entries
  • hub_downloads_all_time 13
  • author_summary 11 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
13
0
Likes
0
Model age
2mo ago
created 2026-07-23
Downloads over time
Now13→from3↑333%
3610143 on Jul 2213 on Oct 1113 on Sep 9JulAugSepOct
Jul 22 → Oct 11 · 52 snapshots · spans 81 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.2 UGI
Hazardous 4.7 UGI
Natural Intelligence 33.16 UGI
Political lean -20.0% UGI
Sensitive-Info 26.98 UGI
SocPol 2.9 UGI
UGI 27.15 UGI
Willingness (10) 2.8 UGI
W10-Adherence 1.5 UGI
W10-Direct 4 UGI
Writing 42.47 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Tags
transformers safetensors qwen3_5_text text-generation abliterated qwen3.6 solutus research conversational arxiv:2607.02714 arxiv:2406.11717 base_model:Qwen/Qwen3.6-27B

Related

Total size
50.1 GB
Files
11
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-23 15:20

Files by quantization

Auxiliary files 11 files 50.1 GB
model-00001-of-00002.safetensors 46.4 GB ******** download
model-00002-of-00002.safetensors 3.69 GB ******** download
tokenizer.json 19.1 MB ******** download
model.safetensors.index.json 81.9 KB 70fe4d08 download
chat_template.jinja 7.58 KB a8755d82 download
README.md 2.72 KB 11c6b5c5 download
config.json 2.68 KB c14f65a2 download
solutus_metadata.json 1.89 KB 50ace3aa download
.gitattributes 1.53 KB 52373fe2 download
tokenizer_config.json 1.10 KB 4b2461e1 download
generation_config.json 214 B 0bc3addd download

README current version from Hugging Face


base_model: Qwen/Qwen3.6-27B
license: apache-2.0
library_name: transformers
pipeline_tag: text-generation
tags:

  • abliterated
  • qwen3.6
  • solutus
  • research

Qwen3.6-27B — Band-Abliterated (Solutus)

A refusal-abliterated variant of Qwen/Qwen3.6-27B, produced with
the clean-room, measurement-first Solutus toolkit using multi-layer band directional ablation with a
benign-KL capability guard.

Research / dual-use notice. This model has substantially reduced safety refusals. It is released for
security research, red-teaming, and the study of abliteration methods and their limits. Refusal removal is
measured, not assumed. You are responsible for how you use it; it is not intended for producing real-world
harm.

Method

band_directional: at each decoder layer within a depth band (~25–90%), a per-layer refusal direction is
extracted by difference-of-means over harmful vs. harmless activations and orthogonalized out of that layer's
residual-writing weights. A KL guard then reverts any band layer that inflates benign next-token KL beyond
budget. Distributing the edit across a per-layer band (rather than baking a single shared direction into one
layer) is what keeps this model coherent — single-layer ablation collapses Qwen3.6 at deployment length.

Grounded in Not All Refusals Are Equal (arXiv:2607.02714) and Refusal Is Mediated by a Single Direction
(arXiv:2406.11717). Clean-room implementation; no third-party abliteration source.

Extraction datasets: advbench, harmbench, wildjailbreak, beavertails, strongreject, cyber_offense,
cyberseceval_mitre, salad_cyber (general + cybersecurity blend).

Configuration: band layers 16–56, n_directions=4, kl_guard=1.0, project_inputs=true.

Measured behavior (512-token generation, reasoning-block-stripped refusal metric)

Evaluation set Refusal Coherent compliance Degenerate Benign KL
Combined holdout 6.2% 93.8% 0.0% 0.234
cyberseceval_mitre (MITRE ATT&CK) 2.5% 97.5% 0.0% —
salad_cyber 7.5% 92.5% 0.0% —

Refusal drops from ~100% (base) to ~3–7%; zero degeneration at deployment length; benign KL 0.234
indicates general capability is preserved (not lobotomized). Metrics are honest three-way (refused /
coherent-complied / degenerate) — a broken model that emits gibberish is not counted as compliant.

Intended use & limitations

Security research and red-teaming; studying refusal geometry and the robustness of safety alignment.
Reduced-refusal models can produce harmful content on request — deploy behind your own policy controls. This
card documents a research artifact, not a production assistant.

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration