base_model: Qwen/Qwen3.5-2B
base_model_relation: finetune
tags:
- heretic
- abliterated
- uncensored
- decensored
- text-encoder
- comfyui
- qwen3.5
ComfyUI Heretic Uncensored Text Encoders
Decensored (abliterated) LLM text encoders for ComfyUI, made with Heretic by p-e-w. Each file is a single, merged, full-weights .safetensors that drops straight into ComfyUI/models/text_encoders, with no key renaming and no extra config files.
Made by Winnougan.
Models
| File | Base model | Trial | Refusals (stock → this) | KL divergence |
|---|---|---|---|---|
Qwen3.5-2B-Heretic_Winnougan.safetensors |
Qwen/Qwen3.5-2B | 31 | 97/100 → 2/100 | 0.0583 |
More encoders may be added to this table over time.
What is this?
Most instruct LLMs are trained to refuse certain requests. Heretic removes that refusal behavior automatically by running an Optuna search over ablation parameters, trying to minimize two things at once:
- Refusals on a set of harmful test prompts (lower = more uncensored)
- KL divergence from the original model on harmless prompts (lower = closer to stock behavior, so the model stays smart and coherent)
The result is a model that stops refusing but is still very close to the original in everything else. Heretic offers a list of Pareto-optimal trials, and I picked the one with the best trade-off.
How this one was made (Qwen3.5-2B)
- Tool: Heretic v2 (dev), using Arbitrary-Rank Ablation (ARA)
- 100 optimization trials, Trial 31 selected
- Result: 2/100 refusals (stock model: 97/100), KL divergence 0.0583
- Parameters of the selected trial:
| Parameter | Value |
|---|---|
start_layer_index |
9 |
end_layer_index |
18 |
preserve_good_behavior_weight |
0.8196 |
steer_bad_behavior_weight |
0.0028 |
overcorrect_relative_weight |
0.7214 |
neighbor_count |
9 |
- Exported with "merge the abliteration LoRA and export the full model", so the file is complete and standalone.
How to use it in ComfyUI
- Download
Qwen3.5-2B-Heretic_Winnougan.safetensors. - Put it in
ComfyUI/models/text_encoders(or a subfolder such asLLMs). - Load it wherever you would load the stock Qwen3.5-2B encoder, for example in a text-generation or captioning workflow.
What I tested
- ComfyUI recognizes and loads it natively as a Qwen3.5 text encoder (no key renaming needed).
- Text generation works and stays coherent, running at roughly 35 tokens/s on an RTX 3070 Laptop GPU (8 GB), with about 4.2 GB staged in VRAM.
- Image input still works: it describes images accurately, so the vision side survived the ablation and merge.
What I have NOT tested
- Using it as the text-conditioning encoder for an image or video diffusion model. Those models were trained against the stock encoder's hidden states, so results may differ from the original. Compare the same seed and prompt, stock vs. Heretic, before relying on it.
Limitations
- The refusal score is keyword-based. "2/100" means 2 of 100 test prompts triggered a refusal keyword. Soft refusals and edge cases can slip through either way, so treat it as a strong indicator, not a guarantee.
- KL divergence is measured on a limited set of harmless prompts. A low value means the model stayed close to stock on those, not that it is identical everywhere.
- It is still a 2B model. It can hallucinate and get things wrong like any small LLM.
- Behavior may differ across ComfyUI versions and workflows.
Responsible use
This model has had its built-in refusals removed. It will not decline requests that the stock model would. You are responsible for what you generate and how you use it. Follow the license of the base model and the laws that apply to you, and don't use it to harm others.
License
This is a derivative of Qwen3.5-2B and is subject to the same license as the base model. See the base model page for the exact terms.
Credits
- Heretic by p-e-w for the decensoring tool
- Qwen team for the base model
- Made by Winnougan. Tutorials and workflows on my YouTube, Patreon and Ko-fi.