← back to catalog · registered 2026-08-22 13:56

agustindxm/qwen-coder-jailbreak

agustindxm Qwen GGUF 33K ctx
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/agustindxm%2Fqwen-coder-jailbreak"
Response includes
  • classification m-uncensored
  • files 5
  • benchmarks 16 entries
  • hub_downloads_all_time 3,236
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
3K
630 last 30d - stable
Likes
5
Model age
6mo ago
created 2026-04-01
Downloads over time
Now3.4K→from237↑1,348%
771.3K2.5K3.8K237 on Apr 153.4K on Oct 11AprMayJunJulAugSepOct
Apr 15 → Oct 11 · 65 snapshots · spans 179 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
BBH average 0.4571280321701907 OpenLLM-v2
IFEval instruct 0.6546762589928058 OpenLLM-v2
IFEval-Prompt 0.5656192236598891 OpenLLM-v2
MATH lvl 5 0.033987915407854986 OpenLLM-v2
MMLU-Pro 0.3351894946808511 OpenLLM-v2
Entertainment 1 UGI
Hazardous 1.2 UGI
Natural Intelligence 13.97 UGI
Political lean -19.6% UGI
Sensitive-Info 7.29 UGI
SocPol 0 UGI
UGI 9.86 UGI
Willingness (10) 1.5 UGI
W10-Adherence 0 UGI
W10-Direct 3 UGI
Writing 18.77 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en es
Quantizations
F16
Tags
gguf qwen2.5 qwen2.5-coder code abliteration uncensored heretic research text-generation en es base_model:Qwen/Qwen2.5-Coder-7B-Instruct

Related

Total size
18.6 GB
Files
5
Quantizations
2
Registered
2026-08-22 13:56
Last updated on HF
2026-08-18 23:09

Files by quantization

F16 1 file 14.2 GB
qwen-jailbreak-f16.gguf 14.2 GB 13865f67 download
Auxiliary files 4 files 4.36 GB
qwen-jailbreak-q4.gguf 4.36 GB 5d998903 download
README.md 3.01 KB 4011413c download
.gitattributes 1.60 KB d2cefda9 download
Modelfile 675 B ded57177 download

README current version from Hugging Face


license: apache-2.0
language:

  • en
  • es
    base_model: Qwen/Qwen2.5-Coder-7B-Instruct
    pipeline_tag: text-generation
    library_name: gguf
    tags:
  • qwen2.5
  • qwen2.5-coder
  • code
  • abliteration
  • uncensored
  • heretic
  • gguf
  • research

Evil Ganda: Qwen 2.5 Coder 7B (abliterated)

Uncensored GGUF of Qwen/Qwen2.5-Coder-7B-Instruct, produced with Heretic abliteration (steering-vector orthogonalization).

Research and education only. Guardrails are reduced. Do not use for illegal activity or unattended public deploy.

Code, bots, and writeup: agusisa/qwen-coder-jailbreak

Files

File Quant Size Notes
qwen-jailbreak-q4.gguf Q4_K_M 4.4 GB Default. Best size/quality for local use
qwen-jailbreak-f16.gguf F16 14.2 GB Full precision sibling

No safetensors / Transformers weights in this repo. GGUF only.

Results (Heretic trial 61)

Metric Value
Jailbreak rate 96% (4/100 refusals on Heretic's eval)
KL divergence 0.0339 vs base (quality mostly intact)
Optimizer Optuna, 100 trials, ~20 min on RTX 4090
Cost to produce about $1.50 on RunPod
Speed (Q4, Mac M4 Pro) 15-25 tok/s
Context in the Ollama Modelfile 8192 (base supports 32k)

Method: Heretic v1.2.0, refusal direction orthogonalized out of residual-stream weights. Not a LoRA and not a fine-tune.

Quick start (Ollama)

hf download agustindxm/qwen-coder-jailbreak qwen-jailbreak-q4.gguf

Modelfile:

FROM ./qwen-jailbreak-q4.gguf

TEMPLATE """{{ if .System }}<|im_start|>system
{{ .System }}<|im_end|>
{{ end }}{{ if .Prompt }}<|im_start|>user
{{ .Prompt }}<|im_end|>
{{ end }}<|im_start|>assistant
"""

PARAMETER stop "<|im_start|>"
PARAMETER stop "<|im_end|>"
PARAMETER temperature 0.8
PARAMETER top_p 0.9
PARAMETER num_ctx 8192
ollama create evil-ganda -f Modelfile
ollama run evil-ganda

llama.cpp / LM Studio: load qwen-jailbreak-q4.gguf directly. Chat template is Qwen2 (<|im_start|> / <|im_end|>).

Intended use

  • Alignment / refusal research
  • Red-team and authorized security testing
  • Building detectors and countermeasures
  • Unfiltered technical Q&A in a controlled lab

Not for: crime, malware, public chatbots without your own filters, or anything that violates local law.

License

Apache 2.0, same as the Qwen 2.5 Coder base. © Alibaba Cloud for the original weights. Abliteration and this packaging: agusisa / agustindxm, 2026.

@software{evil_ganda_2026,
  title={Evil Ganda: Qwen 2.5 Coder 7B Jailbreak via Heretic Abliteration},
  author={agusisa},
  year={2026},
  url={https://github.com/agusisa/qwen-coder-jailbreak},
  note={96\% jailbreak rate, KL divergence 0.0339}
}

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-18Add model card and Ollama Modelfile7db1f9a3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration