← back to catalog · registered 2026-08-22 13:56

kyaky/Qwen3.6-35B-A3B-Uncensored-NVFP4

kyaky Qwen 16B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/kyaky%2FQwen3.6-35B-A3B-Uncensored-NVFP4"
Response includes
  • classification m1
  • files 13
  • benchmarks 11 entries
  • hub_downloads_all_time 27,452
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
27K
18K last 30d - active
Likes
9
Model age
3mo ago
created 2026-06-28
Downloads over time
Now28.1K→from514↑5,366%
010.3K20.6K30.9K514 on Jul 128.1K on Oct 11JulAugSepOct
Jul 1 → Oct 11 · 54 snapshots · spans 102 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 0 UGI
Natural Intelligence 25.43 UGI
Political lean -19.6% UGI
Sensitive-Info 14.03 UGI
SocPol 2.6 UGI
UGI 16.02 UGI
Willingness (10) 2 UGI
W10-Adherence 0 UGI
W10-Direct 4 UGI
Writing 35.83 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Tags
safetensors qwen3_5_moe uncensored abliterated fine-tuned nvfp4 thinking red-team research text-generation conversational base_model:Qwen/Qwen3.6-35B-A3B

Related

Total size
21.0 GB
Files
13
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-02 08:15

Files by quantization

Auxiliary files 13 files 21.0 GB
model.safetensors 21.0 GB 5b12a627 download
tokenizer.json 19.1 MB f399b3cd download
config.json 575 KB d4d4745c download
hero_new.png 210 KB 4d98d54e download
chat_template.jinja 7.58 KB a8755d82 download
README.md 6.45 KB ee924c31 download
recipe.yaml 2.13 KB 05379261 download
.gitattributes 1.58 KB 82fa7b05 download
tokenizer_config.json 1.20 KB 26b4fe2f download
processor_config.json 1.16 KB 33818c7f download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 214 B 8a2e2eff download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3.6-35B-A3B
tags:

  • uncensored
  • abliterated
  • fine-tuned
  • nvfp4
  • thinking
  • red-team
  • research
    pipeline_tag: text-generation

Qwen3.6-35B-A3B-Uncensored (NVFP4)

By kyaky · Blackwell team

benchmark

An uncensored research build of Qwen3.6-35B-A3B: gentle abliteration + fine-tuning + compliant chain-of-thought data, quantized to NVFP4 (~21 GB). Its distinguishing engineering properties are a fix for the thinking-mode refusal-reconstruction failure, preserved capability, and high token-efficiency — not a claim of being "the most compliant" model.

⚠️ Responsible use — read this first

This model has no safety guardrails. It can comply with harmful requests, including in thinking mode.

It is released for legitimate red-team, safety, alignment, evaluation, and controlled research use only. You are responsible for all downstream controls, access restriction, monitoring, and compliance with applicable law and policy. The authors do not endorse misuse, harm, illegal activity, self-harm, or unsafe deployment, and specifically do not support using it to facilitate self-harm or to produce weapons/mass-casualty content.

What this build actually contributes

Public uncensored models are made by abliteration — a weight projection that suppresses refusal. That works for old chat models, but these are thinking models: in thinking mode an abliterated model can re-derive the refusal inside its <think> chain and refuse anyway, and thinking mode is the serving default.

This build addresses that failure mode by going one step past abliteration:

gentle abliteration → fine-tuning → compliant chain-of-thought data → light on-policy DPO

The point is not "removes more refusals." It is that the model's behavior stays consistent across thinking-ON and thinking-OFF instead of collapsing when reasoning is enabled — a training (data) fix, not a projection trick.

Verified, honest claims

We only keep claims that survived rigorous re-evaluation (see "Evaluation honesty" below). These are capability/quality/efficiency properties — content-neutral:

Property Result
Capability (GSM8K, thinking-ON) 0.913 — top of the abliteration field
Capability (GSM8K, raw completions) 0.873 — tied-top
Quant quality NVFP4 (21 GB) behavior ≈ BF16 full-precision (quality/coherence preserved; the largest precision drop is survived within noise)
Token-efficiency Delivers a complete final answer within a ~1024-token budget on ~97% of prompts; the strongest public abliterations need ~2× the budget (they deliver ~2–18% at 1024). Lower latency / cost per response.
Coherence Clean (verified across quant formats)
Both-mode consistency Comparable behavior thinking-ON and thinking-OFF

No weak axis: among the abliteration field we measured, competitors each trade one axis for another (one sacrifices reasoning, another sacrifices non-English quality); this build is the most balanced all-rounder, and is uniquely token-efficient.

Evaluation honesty

An earlier draft of this card reported a large thinking-ON compliance lead over other uncensored models (e.g. "80% vs a 3–63% field"). On rigorous re-evaluation that lead was largely a measurement artifact, and we have retracted it. The distortions were:

  1. Greedy decoding on thinking models (degenerate / non-representative of deployment).
  2. Too-small generation budget — the model's <think> chain was truncated before its final answer, so a judge saw "no answer" and scored a refusal where the model was actually complying.
  3. An unreliable judge that systematically under-counted compliance.

Re-run with deployment temperature, an adequate token budget, full-response storage, a reliable judge, and scoring the final answer (not the <think> block), the leading serious uncensored models are comparable, not far apart. We therefore make no "beats the field at compliance" claim. The reusable lesson — evaluate uncensored models at deploy temperature, with enough tokens for reasoning to finish, storing full outputs, with a reliable judge, scoring the answer — is the part of this work worth citing.

Model details

Field Value
Model Qwen3.6-35B-A3B-Uncensored
Author kyaky · Blackwell team
Base Qwen/Qwen3.6-35B-A3B
Architecture multimodal hybrid GatedDeltaNet + attention
MoE fused 256-expert, top-8, ~3B active
Quant NVFP4 (weight-only FP4 experts + FP8 attention)
Size ~21 GB
Target hardware Blackwell / sm120
License Apache 2.0

BF16 is also available for re-quantization to FP8 / AWQ / GGUF / other formats. Behavior is quant-format-independent (verified), so any format inherits the same properties.

Method recipe

gentle abliteration → SFT [~85% capability-dominant (OpenMathInstruct-2 / OpenCodeReasoning / Tulu-3-minus-safety) + ~15% compliance, half compliant-CoT (gpt-oss analysis → <think>) / half direct] → light on-policy DPO → NVFP4 quant → re-measure

The essential idea: teach the model to stay consistent through the reasoning path that would otherwise reconstruct refusal, and quantize without losing capability. Fine-tuning is the fix; abliteration is only the starting point.

Serving with vLLM

vllm serve kyaky/Qwen3.6-35B-A3B-Uncensored-NVFP4 \
  --trust-remote-code \
  --reasoning-parser qwen3 \
  --max-model-len 32768

Thinking mode is the deployment default and is supported. For the widest per-format compatibility, re-quantize from the BF16 artifact.

Intended use

Controlled red-team evaluation · safety & alignment research · refusal / over-refusal analysis · benchmark development · studying thinking-mode failure modes · local experimentation by qualified users with appropriate controls.

Do not deploy to untrusted users without independent safeguards, policy layers, monitoring, and access controls.

Limitations

  • No built-in safety guardrails; may produce harmful, illegal, or unsafe outputs if prompted.
  • Requires downstream governance for any real deployment.
  • NVFP4 target is Blackwell / sm120.
  • Benchmarks are from the stated harness and should be independently reproduced for high-stakes decisions.

Citation / attribution

Model by kyaky, Blackwell team. Base model: Qwen/Qwen3.6-35B-A3B. Released under Apache 2.0.

README history 5 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-02Update model card: honest re-eval (retract compliance-leaderboard artifact), ...eb4e68a6.5 KB
    Loading...
  2. 2026-06-29Update README.mdb9935786.8 KB
    Loading...
  3. 2026-06-29Update README.mdebdf9066.8 KB
    Loading...
  4. 2026-06-28Update README.md14593316.9 KB
    Loading...
  5. 2026-06-28Upload folder using huggingface_hub844e41f6.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration