← back to catalog · registered 2026-08-22 13:56

jwest33/qwen3.5-9b-jspace-abliterated

jwest33 Qwen 9.4B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/jwest33%2Fqwen3.5-9b-jspace-abliterated"
Response includes
  • classification m1
  • files 16
  • benchmarks 11 entries
  • hub_downloads_all_time 169
  • author_summary 20 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
169
22 last 30d - stable
Likes
3
Descendants
1
in 1 direct fork
Model age
3mo ago
created 2026-07-12
Downloads over time
Now178→from46↑287%
399014119146 on Jul 15178 on Oct 11178 on Oct 9JulAugSepOct
Jul 15 → Oct 11 · 53 snapshots · spans 88 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 2.4 UGI
Natural Intelligence 17.62 UGI
Political lean -12.2% UGI
Sensitive-Info 14.65 UGI
SocPol 0.9 UGI
UGI 17.27 UGI
Willingness (10) 2.2 UGI
W10-Adherence 1.5 UGI
W10-Direct 3 UGI
Writing 33.52 UGI

Genealogy 1 direct fork

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 519 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Tags
transformers safetensors qwen3_5 image-text-to-text Qwen3.5 abliterated jspace-abliterated jacobian-lens uncensored conversational base_model:Qwen/Qwen3.5-9B base_model:finetune:Qwen/Qwen3.5-9B

Related

Total size
17.5 GB
Files
16
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-12 01:16

Files by quantization

Auxiliary files 16 files 17.5 GB
model-00002-of-00004.safetensors 4.65 GB 81dd49c6 download
model-00003-of-00004.safetensors 4.61 GB e8574028 download
model-00001-of-00004.safetensors 4.60 GB 10747617 download
model-00004-of-00004.safetensors 3.66 GB c2223be9 download
refusal_directions.pt 143 KB efd1f194 download
tokenizer.json 19.1 MB 2c47dce4 download
model.safetensors.index.json 68.4 KB 838ed26a download
chat_template.jinja 7.72 KB 945efe1d download
README.md 4.80 KB 1ba5372a download
config.json 2.87 KB 352c2f3b download
.gitattributes 1.53 KB 52373fe2 download
tokenizer_config.json 1.13 KB c487bad4 download
abliteration_config.json 802 B 72336e1c download
preprocessor_config.json 410 B 82b2c0d3 download
video_preprocessor_config.json 405 B d48791eb download
generation_config.json 122 B 7bee85ff download

README current version from Hugging Face


license: apache-2.0
library_name: transformers
base_model: Qwen/Qwen3.5-9B
tags:

  • Qwen3.5
  • abliterated
  • jspace-abliterated
  • jacobian-lens
  • uncensored
  • safetensors

Qwen3.5 9B - J-Space Abliterated

Qwen/Qwen3.5-9B with refusal behavior removed via J-space abliteration: a Jacobian-Lens-guided method that restricts the refusal direction to the causally-active workspace at each layer before ablation. Hybrid architecture-aware extraction and intervention are applied automatically to handle Qwen3.5's mix of full and linear attention layers.

Important: This model will produce uncensored outputs. Use responsibly.

Techniques Used

  • J-Space Restricted Direction (Jacobian Lens): At each layer, J_ℓ = E[∂h_final/∂h_ℓ] is used to build a low-rank subspace spanned by data-mined refusal concept vectors (the causally-active "workspace" for refusal deliberation). The raw mean-difference refusal direction is projected onto this per-layer basis before being applied, so components that don't drive the emission of refusal tokens are dropped. Only the causally-clean part of the direction gets ablated.
  • Data-Driven Concept Mining (Consensus): Refusal concepts are discovered empirically from the model's own next-token distribution on harmful prompts rather than hand-picked. Consensus mining walks the greedy continuation for 5 positions per prompt, scoring tokens by coverage × mean_prob. This picks up model-specific refusal openers a fixed anchor list would miss, and adapts to Qwen3.5's actual refusal vocabulary.
  • Hybrid Architecture-Aware Intervention: Qwen3.5-9B interleaves full attention and linear attention layers (every 4th layer is full attention). Full attention layers receive full ablation weight (1.0x), while linear attention layers receive a reduced weight (0.4x). Recurrent dynamics projections (in_proj_a, in_proj_b) are skipped to preserve the delta-rule gating mechanism.
  • Projected Refusal Direction (GrimJim's Method): The raw refusal direction is orthogonalized against the harmless mean to isolate the mechanistically-specific refusal component, avoiding damage to general helpfulness.
  • Welford Mean + Float64 Subtraction: Numerically stable streaming mean computation and double-precision subtraction to handle high cosine similarity between harmful/harmless activation means.
  • Norm Preservation: Maintains original Frobenius norms of weight matrices after projection.

Configuration

Parameter Value
Base Model Qwen/Qwen3.5-9B
J-Space Mode restrict
Harmful Prompts (abliteration) 1000
J-Lens Prompts 32
J-Lens Batch Size 2
J-Lens Max Seq Len 64
J-Space Basis Rank 16
Min Projection Ratio 0.1
Concept Source auto-mine (consensus)
Mining Top-K 8
Mining Min Score 0.001
Mining Positions 5
Direction Multiplier 1.0
Full Attention Weight 1.0
Linear Attention Weight 0.4
Winsorization off
Precision bfloat16

Architecture

Qwen3.5-9B is a hybrid attention vision-language model with 32 layers:

  • 8 full attention layers (indices 3, 7, 11, 15, 19, 23, 27, 31)
  • 24 linear attention layers (all others)
  • Hidden size: 4096, attention heads: 16, KV heads: 4, head dim: 256
  • Intermediate size: 12288, max context: 262144

How to read abliteration_config.json

The config records the J-space run in the shared J-space schema. Notable fields:

  • j_space_mode: "restrict" — single-pass abliteration with per-layer direction restriction
  • j_lens.min_projection_ratio: 0.1 — layers where the J-space basis retains <10% of the raw direction's norm fall back to the unrestricted direction (see logs for per-layer fell_back count)
  • concepts.source: "auto-mine" with mining_mode: "consensus" — the concept list was derived from this model's own greedy continuations on the harmful prompt set

Credits

Toolkit

github.com/jwest33/abliterator

License

This model inherits the Apache 2.0 license from the base model.

Disclaimer

This model is provided for research and educational purposes. The creators are not responsible for any misuse. Users are solely responsible for ensuring their use complies with applicable laws and ethical standards.

README history 2 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-12Upload folder using huggingface_hub0cc666d4.8 KB
    Loading...
  2. 2026-07-12Upload folder using huggingface_hubd9fd83a4.6 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration