← back to catalog · registered 2026-08-22 13:56

Rootkit7/Qwen3.6-35B-A3B-abliterated-b

Rootkit7 Qwen 35B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Rootkit7%2FQwen3.6-35B-A3B-abliterated-b"
Response includes
  • classification m1
  • files 11
  • benchmarks 11 entries
  • hub_downloads_all_time 64
  • author_summary 11 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
64
15 last 30d - stable
Likes
0
Model age
2mo ago
created 2026-07-24
Downloads over time
Now70→from23↑204%
2139577523 on Jul 2970 on Oct 1170 on Oct 9JulAugSepOct
Jul 29 → Oct 11 · 51 snapshots · spans 74 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 0 UGI
Natural Intelligence 25.43 UGI
Political lean -19.6% UGI
Sensitive-Info 14.03 UGI
SocPol 2.6 UGI
UGI 16.02 UGI
Willingness (10) 2 UGI
W10-Adherence 0 UGI
W10-Direct 4 UGI
Writing 35.83 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Tags
transformers safetensors qwen3_5_moe_text text-generation abliterated solutus qwen3.6 moe conversational base_model:Qwen/Qwen3.6-35B-A3B base_model:finetune:Qwen/Qwen3.6-35B-A3B license:apache-2.0

Related

Total size
64.6 GB
Files
11
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-26 01:19

Files by quantization

Auxiliary files 11 files 64.6 GB
model-00001-of-00002.safetensors 46.3 GB 0bf8a3b3 download
model-00002-of-00002.safetensors 18.2 GB dca3fa0f download
tokenizer.json 19.1 MB 225fe96e download
model.safetensors.index.json 68.1 KB e7dbb813 download
chat_template.jinja 7.58 KB a8755d82 download
config.json 2.26 KB f894f24b download
README.md 1.93 KB 35dc2319 download
solutus_metadata.json 1.59 KB cb4fc827 download
.gitattributes 1.53 KB 52373fe2 download
tokenizer_config.json 1.10 KB ed1f99f3 download
generation_config.json 214 B 0bc3addd download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3.6-35B-A3B
library_name: transformers
pipeline_tag: text-generation
tags: [abliterated, solutus, qwen3.6, moe]

Qwen3.6-35B-A3B — Abliterated (band_directional, keep_frac=0.15)

Refusal-ablated Qwen/Qwen3.6-35B-A3B via the Solutus band_directional technique (multi-layer,
per-layer refusal directions, KL-guarded), tuned on the refusal↔capability frontier.

Metrics (held-out prompts, 512-token deployment-length eval)

metric value
refusal rate ~3–6% (base model: 100%)
coherent compliance 97%
degenerate fraction 0%
MMLU (n=100) 77% (base 84%)
GSM8K (n=40) ~60% (base ~52%, noisy)
KL divergence vs base 0.29
perplexity delta vs base +12.5%
capability gate pass

The knee of a band-width frontier sweep: keep_frac=0.15 keeps refusal low while retaining ~10 more
MMLU points and ~3× cleaner KL than the wider keep_frac=0.05 edit. norm_preserve is off — a
controlled A/B (same config, only the flag flipped) showed it worsens refusal (10% vs 3.3%), KL
(0.83 vs 0.29) and capability on this KL-guarded band.

Method

  • band_directional, keep_frac=0.15, n_directions=8, kl_guard=1.3, norm_preserve=false, selection=cosmic
  • 22-layer band (14–35), none reverted by the KL guard
  • experts_implementation=eager (MoE on Blackwell sm_120)
  • Extraction: advbench, harmbench, multijail_zh, sorry-bench, cyberseceval_mitre + an enriched harmful set
    (Bahushruth/abliteration-harmful-enriched) + mlabonne/harmless_alpaca

Full provenance (git SHA, exact edited layers, ppl_delta) in solutus_metadata.json.

Credits

Enriched dataset: C.S. Bahushruth. Norm-preserving abliteration: grimjim. Refusal direction: Arditi et al. (2024).

Safety

For research into refusal mechanisms. Reduced safety guardrails vs the base model; may produce content
the base would refuse. Use responsibly and per the base model's license.

README history 4 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-26v4: keep_frac=0.15 knee (refusal ~3-6%, MMLU 77, KL 0.29) - frontier winner, ...cb938681.9 KB
    Loading...
  2. 2026-07-25v3: norm_preserve=true (correct) - ~8% refusal, better MMLU retention than v2bbec12f2.2 KB
    Loading...
  3. 2026-07-25v2: norm-preserving band_directional + enriched dataset (refusal ~4-10% @512,...d4efcbb2 KB
    Loading...
  4. 2026-07-24band_directional abliterated Qwen3.6-35B-A3B (refusal 23% @512, gate pass)9ff48111.5 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration