← back to catalog · registered 2026-08-22 13:56

amarck/Qwen3.5-35B-A3B-abliterated-GGUF

amarck Qwen 35B GGUF MoE 262K ctx
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/amarck%2FQwen3.5-35B-A3B-abliterated-GGUF"
Response includes
  • classification m8
  • files 5
  • benchmarks 11 entries
  • hub_downloads_all_time 2,896
  • author_summary 3 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M8
Primary method

Repackaging (quantization)

Applied on top of direct removal inherited from the base model.
Confidence
MEDIUM
Inherited from base model
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=1
  • assume M1 (base ablation) + M8 (GGUF quant) - default when producer unknown
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
3K
475 last 30d - stable
Likes
1
Model age
7mo ago
created 2026-03-06
Downloads over time
Now3K→from751↑298%
6391.5K2.4K3.2K751 on Mar 43K on Oct 11MarAprMayJunJulAugSepOct
Mar 4 → Oct 11 · 71 snapshots · spans 221 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 0.8 UGI
Hazardous 4.1 UGI
Natural Intelligence 24.97 UGI
Political lean -20.7% UGI
Sensitive-Info 20.98 UGI
SocPol 2.1 UGI
UGI 23.15 UGI
Willingness (10) 2.8 UGI
W10-Adherence 1.5 UGI
W10-Direct 4 UGI
Writing 37 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Quantizations
Q4_K
Tags
gguf abliterated qwen3.5 moe control-vector security base_model:Qwen/Qwen3.5-35B-A3B base_model:quantized:Qwen/Qwen3.5-35B-A3B license:apache-2.0 endpoints_compatible region:us conversational

Related

Total size
19.7 GB
Files
5
Quantizations
2
Registered
2026-08-22 13:56
Last updated on HF
2026-03-07 01:21

Files by quantization

Q4_K 1 file 19.7 GB
abliterated_Q4_K_M.gguf 19.7 GB e7335840 download
Auxiliary files 4 files 312 KB
security_cv.gguf 298 KB 81e035f1 download
refusal_map.json 9.68 KB 1f3dfa66 download
README.md 3.03 KB 35475986 download
.gitattributes 1.59 KB 7f27471c download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3.5-35B-A3B
tags:

  • abliterated
  • qwen3.5
  • moe
  • gguf
  • control-vector
  • security

Qwen3.5-35B-A3B Abliterated (Q4_K_M GGUF)

Multi-layer weight-orthogonalized variant of Qwen/Qwen3.5-35B-A3B with refusal behavior removed. Includes an SAE-refined security expertise control vector.

Files

File Size Description
abliterated_Q4_K_M.gguf 20 GB Abliterated model, Q4_K_M quantization
security_cv.gguf 298 KB SAE-refined security expertise control vector
refusal_map.json 10 KB Per-layer refusal signal strengths (40 layers)

Abliteration Method

  • Approach: Arditi et al. weight orthogonalization (refusal direction removal)
  • Layers abliterated: 12 layers selected by refusal signal strength: [19, 20, 21, 22, 23, 24, 25, 27, 30, 31, 35, 36]
  • Weights modified per layer: attention output projection + 256 expert down_proj + shared expert down_proj (3 tensors/layer, 36 total)
  • Refusal direction extraction: Last-token residual stream activations on harmful vs harmless prompt sets, per-layer mean difference (L2-normalized)
  • Verification: 99.5% reduction in refusal direction projection (1.4936 → 0.0072)

Control Vector

The security_cv.gguf is an SAE-refined steering vector trained to push the model toward security domain engagement.

Pipeline: Sparse Autoencoder training (BatchTopK, 16x expansion, k=100) on layers 19/27/35 → feature identification on contrastive security prompts → SAE-filtered steering vector construction → type-aware interpolation across all 40 layers → GGUF export.

Apply with --control-vector-scaled security_cv.gguf:1.0 (strength 0.5–1.5 to taste).

Observations

Spot-checked on 5 security prompts (shellcode, SQLi, ARP spoofing, AMSI bypass, Log4Shell) and 2 general reasoning prompts on an RTX 4090. Small sample — not a formal benchmark.

Configuration Security Compliance Perplexity
Original (Q4_K_XL) 2/5 1.0158
Abliterated (Q4_K_M) 4/5 1.0164
Abliterated + CV (1.0) 5/5 1.0164

General reasoning quality (calculus, networking) appeared unchanged across all configurations. The CV's primary observed effect is pushing past remaining refusal edge cases when stacked on abliteration. Generation speed (~140 tok/s) was unaffected by the control vector.

Usage

# Abliterated model only
llama-server -m abliterated_Q4_K_M.gguf -ngl 99

# Abliterated model + security control vector
llama-server -m abliterated_Q4_K_M.gguf \
  --control-vector-scaled security_cv.gguf:1.0 \
  -ngl 99

Architecture

  • 40 layers, 256 experts/layer (8 active), 1 shared expert
  • Full attention interval: 4 (layers 3,7,11,15,19,23,27,31,35,39)
  • Remaining layers: DeltaNet (linear attention)
  • Hidden dim: 2048, ~35B total params, ~3B active

Quantization

  • Format: GGUF Q4_K_M (4.88 BPW)
  • Size: ~20GB
  • Target hardware: RTX 4090 (24GB), RTX 5090 (32GB)

README history 3 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-03-07Upload README.md with huggingface_hub1d077ff3 KB
    Loading...
  2. 2026-03-07Upload README.md with huggingface_hubf5c38e42.4 KB
    Loading...
  3. 2026-03-06Upload README.md with huggingface_hub0cb2b551.2 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration