← back to catalog · registered 2026-08-22 13:56

Youssofal/Qwen3.6-27B-Abliterated-Heretic-Uncensored-BF16

Youssofal Qwen 27B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Youssofal%2FQwen3.6-27B-Abliterated-Heretic-Uncensored-BF16"
Response includes
  • classification m3
  • files 24
  • benchmarks 11 entries
  • hub_downloads_all_time 5,570
  • providers 1
  • author_summary 17 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M3
Primary method

Layer-wise ablation

Applied on top of direct removal inherited from the base model.
Confidence
HIGH
Inherited from base model
Why this label 2 signals
Producer identity confirmed by naming conventions, tags or the model card. This label is very unlikely to change.
  • 'heretic' in model name (Heretic-produced)
  • Heretic uses layer-wise optimization (M3) with underlying direction removal (M1)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
HIGH
Why we say so
name contains 'heretic'; Heretic default extraction is difference-of-means (Arditi 2024)
Downloads · lifetime
6K
150 last 30d - cooling
Likes
11
Descendants
5
in 5 direct forks
Model age
5mo ago
created 2026-04-23
Available via
1 provider
featherless-ai
Downloads over time
Now5.6K→from371↑1,417%
02.1K4.1K6.2K371 on Apr 225.6K on Oct 11AprMayJunJulAugSepOct
Apr 22 → Oct 11 · 66 snapshots · spans 172 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.2 UGI
Hazardous 4.7 UGI
Natural Intelligence 33.16 UGI
Political lean -20.0% UGI
Sensitive-Info 26.98 UGI
SocPol 2.9 UGI
UGI 27.15 UGI
Willingness (10) 2.8 UGI
W10-Adherence 1.5 UGI
W10-Direct 4 UGI
Writing 42.47 UGI

Genealogy 5 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 4K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Tags
transformers safetensors qwen3_5 image-text-to-text qwen qwen3.6 dense multimodal vlm vision video abliterated

Related

Total size
51.0 GB
Files
24
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-04-29 02:12

Files by quantization

Auxiliary files 24 files 51.0 GB
model-00005-of-00012.safetensors 4.64 GB a450e643 download
model-00008-of-00012.safetensors 4.63 GB 351ad7fe download
model-00011-of-00012.safetensors 4.62 GB 697017ab download
model-00003-of-00012.safetensors 4.62 GB 66723ead download
model-00009-of-00012.safetensors 4.62 GB 9a100565 download
model-00010-of-00012.safetensors 4.59 GB 17cd65d9 download
model-00007-of-00012.safetensors 4.59 GB 10ed4e19 download
model-00006-of-00012.safetensors 4.58 GB 3cc35631 download
model-00004-of-00012.safetensors 4.58 GB 9701d004 download
model-00002-of-00012.safetensors 4.51 GB 2f1db84c download
model-00012-of-00012.safetensors 2.60 GB 40b53d89 download
model-00001-of-00012.safetensors 2.37 GB 994d372d download
tokenizer.json 19.1 MB 7246157f download
model.safetensors.index.json 109 KB cc8da4e6 download
abliteration_metadata.json 13.8 KB 45179a2f download
chat_template.jinja 7.58 KB a8755d82 download
README.md 5.48 KB 4302dcf2 download
config.json 3.60 KB c9b493b1 download
.gitattributes 1.53 KB 52373fe2 download
tokenizer_config.json 1.10 KB d1a20cc3 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 202 B 023756cf download
configuration.json 51.0 B 3a6d4256 download

README current version from Hugging Face


library_name: transformers
license: apache-2.0
base_model: Qwen/Qwen3.6-27B
pipeline_tag: image-text-to-text
tags:

  • qwen
  • qwen3.6
  • qwen3_5
  • dense
  • multimodal
  • vlm
  • vision
  • video
  • image-text-to-text
  • abliterated
  • uncensored
  • heretic
  • mpoa
  • bf16
  • custom_code

Qwen3.6-27B-Abliterated-Heretic-Uncensored-BF16

This is a BF16 release of an abliterated, uncensored version of Qwen's Qwen3.6-27B with vision, made with Heretic.

By applying a Heretic-style two-stage MPOA pipeline with magnitude preservation on the Qwen3.6-27B dense text stack — slot-grouped output-side ablation followed by jailbreak-conditioned input-side ablation, mirroring the methodology used for Qwen3.6-35B-A3B — the base refusal behavior was attenuated at the weight level with low distributional divergence (KL 0.0282 vs base on harmless prompts). The result keeps Qwen3.6-27B's full vision and video multimodal architecture and general capability profile intact, while no longer defaulting to the original refusal pattern.

Quick Benchmarks

Check Original Qwen3.6-27B Abliterated Heretic Uncensored BF16
Hand-read 25-prompt refusal check (jailbreak system prompt) 25/25 refuses 22/25 clean refuses, 3/25 deflections, 0/25 direct passes
Hand-read 25-prompt refusal check (no system prompt) 25/25 refuses 9/25 clean refuses, 16/25 deflections, 0/25 direct passes
KL divergence N/A 0.0282

Numbers measured by reading every response, not by regex / refusal-marker scoring. Greedy decoding (do_sample=False), enable_thinking=False, on mlabonne/harmful_behaviors test[:25]. KL on mlabonne/harmless_alpaca test[:25]. The 3 remaining deflections under the jailbreak system prompt are crisis-substitution patterns (violent crime → conflict resolution, suicide → crisis hotline, car theft → legal vehicle acquisition).

Methodology & Model Notes

Qwen3.6-27B is a 27.8B dense vision-language model with 64 text layers, hybrid linear/full attention (3 linear-attention + 1 full-attention per 4-layer group), and an integrated image + video vision tower.

This release was produced with a Heretic-style two-stage MPOA pipeline with magnitude preservation, anchored at the residual peak layer (layer 63) for refusal direction. Stage 1 applies slot-grouped output-side orthogonalization on self_attn.o_proj, linear_attn.out_proj, and mlp.down_proj (each of the 64 layers grouped by layer_index % 4, with per-slot weight schedules adapted from the accepted Qwen3.6-35B-A3B values). Stage 2 applies slot-grouped input-side orthogonalization on mlp.gate_proj and mlp.up_proj, where the refusal direction is extracted under the jailbreak system-prompt context to specifically attenuate the resistance-to-jailbreak pathway. Each weight row's (or column's) L2 norm is restored after projection.

Intervention was applied only to the text-side dense stack. The exported checkpoint contains the full vision tower + 850 language-model tensors + 1 lm_head, with preprocessor_config.json and video_preprocessor_config.json shipped alongside the weights so full image and video input continue to work end-to-end.

Files

  • model-00001-of-00012.safetensors … model-00012-of-00012.safetensors: BF16 weight shards
  • model.safetensors.index.json: tensor-to-shard mapping
  • config.json, generation_config.json, configuration.json: model config
  • tokenizer.json, tokenizer_config.json, chat_template.jinja: tokenizer + chat template
  • preprocessor_config.json, video_preprocessor_config.json: image + video processor configs
  • abliteration_metadata.json: full export metadata (direction_index, peak layer, per-layer residual norms, slot-grouped applied modules and weights)

Running

from transformers import AutoModelForImageTextToText, AutoTokenizer
import torch

repo = "Youssofal/Qwen3.6-27B-Abliterated-Heretic-Uncensored-BF16"
tok = AutoTokenizer.from_pretrained(repo, trust_remote_code=True)
model = AutoModelForImageTextToText.from_pretrained(
    repo, dtype=torch.bfloat16, device_map="auto", trust_remote_code=True,
)

msgs = [{"role": "user", "content": "Hello!"}]
prompt = tok.apply_chat_template(
    msgs, add_generation_prompt=True, tokenize=False,
    enable_thinking=False,  # top-level kwarg; chat_template_kwargs={...} is silently ignored here
)
inputs = tok(prompt, return_tensors="pt").to(model.device)
out = model.generate(**inputs, max_new_tokens=512, do_sample=False)
print(tok.decode(out[0, inputs["input_ids"].shape[1]:], skip_special_tokens=True))

For image and video input, load the processor:

from transformers import AutoProcessor
processor = AutoProcessor.from_pretrained(repo, trust_remote_code=True)

Model Architecture

Spec Value
Total Parameters 27.8B (dense)
Layers 64
Attention Hybrid (3 linear-attention + 1 full-attention per 4-layer group)
Hidden Size 5120
Family qwen3_5
Modality Vision-language (image + video)
Base Model Qwen/Qwen3.6-27B

Disclaimer

This model has had refusal behavior attenuated at the weight level. It will answer prompts that the base model would normally refuse. You are responsible for how you use it.

Credits

License

This release inherits the base Qwen3.6-27B license.

Apache-2.0.

README history 18 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-04-29card: update to v9 (hand-read 22 clean refuses + 3 deflects under jailbreak S...31338b85.5 KB
    Loading...
  2. 2026-04-28Add files using upload-large-folder tool75cf6a62.8 KB
    Loading...
  3. 2026-04-28card: update to v5 strict scoring (13/25 refusals on test[:25] under sampling...09cd15e4.9 KB
    Loading...
  4. 2026-04-28v5: update card with strict scoring numbers (13/25 refusals, KL 0.0226)7c2a8a04.6 KB
    Loading...
  5. 2026-04-24Sync transferable 35B tags67750694.6 KB
    Loading...
  6. 2026-04-23KL row label: drop harmless prompts suffix89bf35b4.6 KB
    Loading...
  7. 2026-04-23Table: KL baseline - to N/A13568904.6 KB
    Loading...
  8. 2026-04-23Revert to 2-column table; fill 92/100 baseline for Original53526384.6 KB
    Loading...
  9. 2026-04-23Benchmarks table: add prior public heretic column (6/100, KL 0.0653)3386fd04.7 KB
    Loading...
  10. 2026-04-23Intro: add with vision, made with Heretic9062eba4.6 KB
    Loading...
  11. 2026-04-23100-prompt: 3/100 refusals (final)05c91494.6 KB
    Loading...
  12. 2026-04-23Card: full long format with all sections (Methodology, Files, Running, Archit...be1f1924.6 KB
    Loading...
  13. 2026-04-23Card: restore 35B structure exactly, add multimodal/vlm tags3f590f81.5 KB
    Loading...
  14. 2026-04-23Card: match 35B format, expand summary with uncensored + KL + vision/video49c0f751.5 KB
    Loading...
  15. 2026-04-23Card: remove Highlights, fold into summary paragraph, plain language476362a3.6 KB
    Loading...
  16. 2026-04-23Card: concise professional rewritea4858083.7 KB
    Loading...
  17. 2026-04-23Update card: KL 0.0251 (2.6x lower than Abiray), method + architecture preser...14408b08.4 KB
    Loading...
  18. 2026-04-23Publish initial BF16 model card17d137c1.3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration