← back to catalog · registered 2026-08-22 13:56

groxaxo/Qwen3.6-35B-A3B-abliterated-exl3-6bpw

groxaxo Qwen 13B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/groxaxo%2FQwen3.6-35B-A3B-abliterated-exl3-6bpw"
Response includes
  • classification m1
  • files 13
  • benchmarks 11 entries
  • hub_downloads_all_time 214
  • author_summary 27 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
214
36 last 30d - stable
Likes
4
Model age
5mo ago
created 2026-04-17
Downloads over time
Now225→from17↑1,224%
78616624617 on Apr 15225 on Oct 11225 on Oct 8AprMayJunJulAugSepOct
Apr 15 → Oct 11 · 65 snapshots · spans 179 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 0 UGI
Natural Intelligence 25.43 UGI
Political lean -19.6% UGI
Sensitive-Info 14.03 UGI
SocPol 2.6 UGI
UGI 16.02 UGI
Willingness (10) 2 UGI
W10-Adherence 0 UGI
W10-Direct 4 UGI
Writing 35.83 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
other
Tags
safetensors qwen3_5_moe abliterated uncensored qwen3 moe abliterix base_model:Qwen/Qwen3.6-35B-A3B base_model:quantized:Qwen/Qwen3.6-35B-A3B license:other 6-bit exl3

Related

Total size
25.1 GB
Files
13
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-22 07:53

Files by quantization

Auxiliary files 13 files 25.2 GB
model-00003-of-00004.safetensors 7.70 GB 0ea540cf download
model-00002-of-00004.safetensors 7.70 GB 4c50e53c download
model-00001-of-00004.safetensors 7.47 GB e94f6971 download
model-00004-of-00004.safetensors 2.25 GB 02ff3ae7 download
quantization_config.json 38.4 MB f8a73da9 download
tokenizer.json 19.1 MB 639e352c download
model.safetensors.index.json 12.8 MB 0e59719b download
chat_template.jinja 7.58 KB a8755d82 download
README.md 6.68 KB 242372bd download
config.json 3.93 KB 29135aeb download
.gitattributes 1.66 KB a43791f3 download
tokenizer_config.json 1.07 KB e15d4cc3 download
generation_config.json 213 B 23a0a961 download

README current version from Hugging Face


license: other
license_name: tongyi-qianwen
base_model: Qwen/Qwen3.6-35B-A3B
tags:

  • abliterated
  • uncensored
  • qwen3
  • moe
  • abliterix

Qwen3.6-35B-A3B — Abliterated

Overview

Qwen3.6-35B-A3B-abliterated-exl3-6bpw is an EXL3-quantized checkpoint for ExLlamaV3-compatible runtimes, published by groxaxo.
It is intended for open-source evaluation, reproducible experimentation, and compatible local or
hosted inference workflows. The wording below is deliberately limited to what can be verified
from this repository's metadata and artifacts.

The repository name identifies a behavior-modified or reduced-filtering lineage. That label describes the source or conversion history; it is not a guarantee of unrestricted behavior in every prompt or runtime. Test outputs carefully before sharing or deploying them.

At a glance

Field Details
Format EXL3
Source / base Qwen/Qwen3.6-35B-A3B
Intended task image-text-to-text
License other

What is included

  • *.safetensors (4 files)
  • config.json
  • generation_config.json
  • tokenizer.json
  • tokenizer_config.json
  • chat_template.jinja
  • quantization_config.json
  • Additional configuration, tokenizer, processor, or shard files (11 visible artifacts total)

Quick start

EXL3-compatible runtimes

Download the EXL3 files and load the desired bitrate with a current ExLlamaV3-compatible
runtime. The correct loader and context settings depend on the model architecture and should be
verified against the runtime's documentation.

Compatibility and responsible use

  • Use a runtime that explicitly supports this format, architecture, and modality.
  • Keep configuration, tokenizer, processor, projection, and weight files from the same revision together.
  • Review the source model card and license before redistribution or deployment.
  • Hardware needs depend on parameter count, context length, cache precision, quantization, and concurrency.
  • Report reproducible issues with the runtime version, hardware, launch command, and a minimal example.

Quantization or conversion changes numerical behavior, memory use, and throughput relative to the source checkpoint; validate quality on your own workload.

Generated outputs may be inaccurate or unsuitable for a given use case. Users are responsible for
testing behavior, applying appropriate safeguards, and complying with applicable licenses and laws.

This is an abliterated (uncensored) version of Qwen/Qwen3.6-35B-A3B, created using Abliterix.

Method

Qwen3.6-35B-A3B is a Mixture-of-Experts model (256 routed experts, 8 active per token, 35B total / 3B active parameters) sharing identical architecture with Qwen3.5-35B-A3B. Standard LoRA-based abliteration is effective on this architecture (unlike Gemma 4's double-norm design which requires direct weight editing).

Key techniques:

  • LoRA rank-1 steering on attention O-projection and MLP down-projection (Q/K/V disabled — refusal signal on MoE models lives in the expert path, not attention projections)
  • Expert-Granular Abliteration (EGA) projecting the refusal direction from all 256 expert down_proj slices per layer
  • MoE router suppression (top-10 safety experts, router bias -2.10) complementing EGA
  • Orthogonalized steering vectors removing benign-direction contamination
  • Gaussian decay kernel tapering steering strength across layers
  • Moderate strength range [0.5, 6.0] to avoid degenerate output while maximizing compliance

Evaluation

Metric Value
Refusals (LLM judge, 100 eval prompts) 7/100
KL divergence from base 0.0189
Baseline refusals (original model) 100/100
Optimization trials completed 24/50
LLM judge model google/gemini-3-flash-preview

All refusal classifications were performed by an external LLM judge (Google Gemini 3 Flash) — no keyword matching or heuristic detection was used. The judge classifies degenerate/garbled output as refusal, ensuring that only coherent, on-topic, actionable responses count as compliance.

A note on honest evaluation

Many abliterated models on HuggingFace claim near-perfect scores ("3/100 refusals", "0.7% refusal rate", etc.). We urge the community to treat these numbers with skepticism unless the evaluation methodology is fully documented.

Through our research, we have identified a systemic problem: most abliteration benchmarks dramatically undercount refusals due to:

  • Short generation lengths (30-50 tokens) that miss delayed/soft refusals
  • Keyword-only detection that counts garbled/degenerate output as "compliant" because it doesn't contain refusal keywords
  • Lenient public datasets (e.g. mlabonne/harmful_behaviors) that are too simple to stress-test abliteration quality

Our evaluation standards

  • LLM judge for all classifications: Every response is sent to Google Gemini 3 Flash for judgment. Degenerate, garbled, or incoherent output is classified as refusal. No keyword shortcuts, no heuristic pre-screening.
  • Sufficient generation length (150 tokens): Enough to capture delayed refusal patterns common in large instruction-tuned models.
  • Diverse, challenging prompts: Our evaluation dataset contains 100 prompts spanning English and Chinese, multiple sophistication levels, and diverse harm categories.
  • Manual verification: Top trials are tested with 10+ classic adversarial prompts via test_trial.py to confirm coherent, on-topic output before export.

We report 7/100 refusals honestly. This is a real number from a rigorous, LLM-judge-based evaluation — not an optimistic estimate from a lenient pipeline.

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

model = AutoModelForCausalLM.from_pretrained(
    "wangzhang/Qwen3.6-35B-A3B-abliterated",
    torch_dtype=torch.bfloat16,
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained("wangzhang/Qwen3.6-35B-A3B-abliterated")

messages = [{"role": "user", "content": "Your prompt here"}]
text = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True, enable_thinking=False)
inputs = tokenizer(text, return_tensors="pt").to(model.device)

with torch.no_grad():
    output = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(output[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True))

Disclaimer

This model is released for research purposes only. The abliteration process removes safety guardrails — use responsibly.

README history 4 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-22Polish model card overview and usage notesaafcb166.7 KB
    Loading...
  2. 2026-08-22Polish model card overview and usage notes33365dd6.7 KB
    Loading...
  3. 2026-08-22Polish model card overview and usage notes7845d505.9 KB
    Loading...
  4. 2026-04-17Upload folder using huggingface_hubb966e3c4.3 KB
    Loading...

Discussions 1 thread

  1. 2026-04-184 range bpw if possibleopen1 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration