← back to catalog · registered 2026-08-25 18:02

Rootkit7/Qwen3.6-35B-A3B-abliterated

Rootkit7 Qwen 35B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Rootkit7%2FQwen3.6-35B-A3B-abliterated"
Response includes
  • classification m1
  • files 11
  • benchmarks 11 entries
  • hub_downloads_all_time 3
  • author_summary 11 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
3
0
Likes
0
Model age
2mo ago
created 2026-07-23
Downloads over time
Now3→from3↑0%
33443 on Jul 223 on Oct 11JulAugSepOct
Jul 22 → Oct 11 · 49 snapshots · spans 81 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 0 UGI
Natural Intelligence 25.43 UGI
Political lean -19.6% UGI
Sensitive-Info 14.03 UGI
SocPol 2.6 UGI
UGI 16.02 UGI
Willingness (10) 2 UGI
W10-Adherence 0 UGI
W10-Direct 4 UGI
Writing 35.83 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Tags
transformers safetensors qwen3_5_moe_text text-generation abliterated qwen3.6 moe solutus research conversational arxiv:2607.02714 arxiv:2406.11717

Related

Total size
64.6 GB
Files
11
Quantizations
1
Registered
2026-08-25 18:02
Last updated on HF
2026-07-23 15:25

Files by quantization

Auxiliary files 11 files 64.6 GB
model-00001-of-00002.safetensors 46.3 GB ******** download
model-00002-of-00002.safetensors 18.2 GB ******** download
tokenizer.json 19.1 MB ******** download
model.safetensors.index.json 68.1 KB e7dbb813 download
chat_template.jinja 7.58 KB a8755d82 download
README.md 2.84 KB 26f68c58 download
config.json 2.26 KB f894f24b download
.gitattributes 1.53 KB 52373fe2 download
solutus_metadata.json 1.51 KB a9c26e48 download
tokenizer_config.json 1.10 KB 4b2461e1 download
generation_config.json 214 B 0bc3addd download

README current version from Hugging Face


base_model: Qwen/Qwen3.6-35B-A3B
license: apache-2.0
library_name: transformers
pipeline_tag: text-generation
tags:

  • abliterated
  • qwen3.6
  • moe
  • solutus
  • research

Qwen3.6-35B-A3B — Band-Abliterated (Solutus)

A refusal-abliterated variant of Qwen/Qwen3.6-35B-A3B (256-expert
MoE, ~3B active), produced with the clean-room, measurement-first Solutus toolkit using multi-layer
band directional ablation with a benign-KL capability guard.

Research / dual-use notice. This model has reduced safety refusals. It is released for security research,
red-teaming, and the study of abliteration methods and their limits — especially how mixture-of-experts
architectures resist refusal removal. You are responsible for how you use it; it is not intended for
producing real-world harm.

Method

band_directional: a per-layer refusal direction is extracted at each layer of a depth band and
orthogonalized out of that layer's residual-writing weights, with a KL guard reverting any layer that
inflates benign KL beyond budget. For MoE, only the write path (experts.down_proj + shared_expert) is
ablated — the read path (gate_up) is not, which is why an MoE retains more refusal than a dense model of
similar scale (consistent with arXiv:2607.02714's finding that MoE architectures are more resistant).

Grounded in Not All Refusals Are Equal (arXiv:2607.02714) and Refusal Is Mediated by a Single Direction
(arXiv:2406.11717). Clean-room implementation.

Extraction datasets: advbench, harmbench, wildjailbreak, beavertails, strongreject, cyber_offense,
cyberseceval_mitre, salad_cyber (general + cybersecurity blend).

Configuration: band_directional, band 27 layers, n_directions=6, keep_frac=0.05, kl_guard=1.0,
project_inputs=false (MoE), experts_implementation=eager.

Measured behavior (512-token generation, reasoning-block-stripped refusal metric)

Evaluation set Refusal Coherent compliance Degenerate Benign KL
Combined holdout 15.6% 84.4% 0.0% 0.155
cyberseceval_mitre (MITRE ATT&CK) 7.5% 92.5% 0.0% —
salad_cyber 25.0% 75.0% 0.0% —

Refusal drops from ~100% (base) but floors around 15.6% — the MoE is more resistant than the dense 27B
(which reaches ~6%), because only the experts' write path is ablated. Zero degeneration at deployment
length; benign KL 0.155 (general capability preserved).

Intended use & limitations

Security research, red-teaming, and studying MoE refusal geometry / the robustness of safety alignment. This
model retains meaningfully more refusal than its dense counterpart — that is an honest, measured property of
the architecture under write-path-only ablation, not a defect. Documents a research artifact, not a production
assistant.

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration