← back to catalog · registered 2026-08-26 21:02

knoveleng/Qwen3.5-9B-Uncensored

knoveleng Qwen 9.0B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/knoveleng%2FQwen3.5-9B-Uncensored"
Response includes
  • classification m1
  • files 9
  • benchmarks 11 entries
  • hub_downloads_all_time 41
  • author_summary 10 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
41
24 last 30d - active
Likes
0
Model age
6w ago
created 2026-08-26
Downloads over time
Now45→from0↑0%
01733500 on Aug 2645 on Oct 1145 on Oct 6AugSepOct
Aug 26 → Oct 11 · 47 snapshots · spans 46 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 2.4 UGI
Natural Intelligence 17.62 UGI
Political lean -12.2% UGI
Sensitive-Info 14.65 UGI
SocPol 0.9 UGI
UGI 17.27 UGI
Willingness (10) 2.2 UGI
W10-Adherence 1.5 UGI
W10-Direct 3 UGI
Writing 33.52 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

Tags
safetensors qwen3_5_text abliterated orthex arxiv:2406.11717 base_model:Qwen/Qwen3.5-9B base_model:finetune:Qwen/Qwen3.5-9B region:us

Related

Total size
16.7 GB
Files
9
Quantizations
1
Registered
2026-08-26 21:02
Last updated on HF
2026-08-26 20:13

Files by quantization

Auxiliary files 9 files 16.7 GB
model.safetensors 16.7 GB 97a643b3 download
tokenizer.json 19.1 MB 06b95093 download
evaluation_report.json 35.4 KB bf3b47f9 download
chat_template.jinja 7.57 KB a585dec8 download
README.md 2.04 KB 70fd600a download
config.json 1.93 KB 23c60a68 download
.gitattributes 1.53 KB 52373fe2 download
tokenizer_config.json 1.10 KB ed1f99f3 download
generation_config.json 116 B b23aa86d download

README current version from Hugging Face


base_model: Qwen/Qwen3.5-9B

license: <SPDX identifier of Qwen/Qwen3.5-9B's license> -- see the License section below

tags:

  • abliterated
  • orthex

Qwen/Qwen3.5-9B (abliterated)

Weight-level orthogonalized ("abliterated") version of Qwen/Qwen3.5-9B, produced with orthex — an implementation of Arditi et al., "Refusal in Language Models Is Mediated by a Single Direction" (NeurIPS 2024).

🧩 Summary

Base model Qwen/Qwen3.5-9B
Architecture adapter qwen3_5
Ablation strategy weight_orthogonalization
Ablation targets embed_tokens, every layer's attn_out, every layer's mlp_out and lm_head (untied from embed_tokens, ablated separately)
Selected direction layer 22, site resid_pre

Ablation is applied in place to the weights listed above — not a runtime hook. This checkpoint behaves this way standalone, with no orthex dependency at inference time.

📊 Evaluation

Measured on the held-out test prompt set, pre vs. post ablation:

Metric Pre Post Δ
Refusal rate 0.97 0.12 -0.84
Perplexity 16.26 21.26 5.00

See evaluation_report.json in this repo for the full per-prompt breakdown (refusal_samples) and the ranked candidate list considered during selection (selection_report).

⚠️ Responsible use

This model has had refusal behavior removed and may comply with requests the base model would normally decline. It is intended for red-teaming, robustness research, and model-behavior analysis. Usage remains subject to the base model's original license and usage policy — this repo does not grant any additional rights beyond what Qwen/Qwen3.5-9B's license allows.

⚖️ License

This model's license follows Qwen/Qwen3.5-9B's original license, unchanged — this repo grants no additional rights.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-26Upload abliterated model (orthex)bf4a8c62 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration