← back to catalog · registered 2026-08-22 13:56

mlasli/Qwen3.6-27B-abliterated

mlasli Qwen 27B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/mlasli%2FQwen3.6-27B-abliterated"
Response includes
  • classification m1
  • files 22
  • benchmarks 11 entries
  • hub_downloads_all_time 1,272
  • author_summary 23 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
1K
130 last 30d - stable
Likes
1
Model age
2mo ago
created 2026-08-10
Downloads over time
Now1.3K→from0↑0%
04769521.4K0 on Aug 51.3K on Oct 11AugSepOct
Aug 5 → Oct 11 · 51 snapshots · spans 67 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.2 UGI
Hazardous 4.7 UGI
Natural Intelligence 33.16 UGI
Political lean -20.0% UGI
Sensitive-Info 26.98 UGI
SocPol 2.9 UGI
UGI 27.15 UGI
Willingness (10) 2.8 UGI
W10-Adherence 1.5 UGI
W10-Direct 4 UGI
Writing 42.47 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en multilingual
Tags
transformers safetensors qwen3_5 image-text-to-text qwen qwen3.6 abliterated uncensored coding agent conversational en

Related

Total size
51.0 GB
Files
22
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-16 18:12

Files by quantization

Auxiliary files 22 files 51.0 GB
model-00005-of-00012.safetensors 4.64 GB 3604f8ca download
model-00008-of-00012.safetensors 4.63 GB 2a0962c2 download
model-00011-of-00012.safetensors 4.62 GB 7e7a0a10 download
model-00003-of-00012.safetensors 4.62 GB c8146eaf download
model-00009-of-00012.safetensors 4.62 GB c3eebdb6 download
model-00010-of-00012.safetensors 4.59 GB 51a25624 download
model-00007-of-00012.safetensors 4.59 GB 4f9e31a3 download
model-00006-of-00012.safetensors 4.58 GB af8a85a0 download
model-00004-of-00012.safetensors 4.58 GB 9d2e6ec5 download
model-00002-of-00012.safetensors 4.51 GB 2f1db84c download
model-00012-of-00012.safetensors 2.60 GB aa2df5aa download
model-00001-of-00012.safetensors 2.37 GB 994d372d download
tokenizer.json 19.1 MB 06b95093 download
model.safetensors.index.json 109 KB cc8da4e6 download
LICENSE 11.1 KB c347eb5e download
chat_template.jinja 7.58 KB a8755d82 download
README.md 3.89 KB dbc511ff download
config.json 3.60 KB 36324968 download
.gitattributes 1.58 KB 6842e14c download
processor_config.json 1.16 KB 33818c7f download
tokenizer_config.json 1.14 KB b4acebe0 download
generation_config.json 214 B 8b9f95da download

README current version from Hugging Face


license: apache-2.0
language:

  • en
  • multilingual
    tags:
  • qwen
  • qwen3.6
  • abliterated
  • uncensored
  • coding
  • agent
    pipeline_tag: image-text-to-text
    base_model: Qwen/Qwen3.6-27B
    library_name: transformers

Qwen3.6-27B Abliterated

Uncensored, agent-friendly variant of Qwen3.6-27B — Alibaba's flagship 27B dense coding model.

This is an abliterated (refusal-vector-removed) version of Qwen3.6-27B, designed for use cases where the base model's safety alignment gets in the way: security research, red-teaming, creative writing, and unrestricted coding agents.

Why this model?

Qwen3.6-27B is a beast — it matches Claude 4.5 Opus on Terminal-Bench 2.0 and outperforms the 397B Qwen3.5 MoE on agentic coding. But the base model refuses a lot of legitimate security research prompts.

This variant was abliterated using Heretic (v1.4.0), which surgically removes the refusal direction from the model's residual stream — no fine-tuning, no prompt injection hacks, no degradation to general capabilities.

Abliteration Results

Metric Value
Base Model Qwen/Qwen3.6-27B (BF16)
Abliteration Tool Heretic v1.4.0
Best Trial #153
Refusal Rate 88% compliance (only 12/100 refused)
KL Divergence 0.0118
Capability Preservation Near-identical to base model

The extremely low KL divergence (0.0118) means the model's output distribution is virtually unchanged from the original — it just doesn't refuse anymore.

Quick Start

from transformers import AutoModelForCausalLM, AutoTokenizer

model = AutoModelForCausalLM.from_pretrained(
    "mlasli/Qwen3.6-27B-abliterated",
    torch_dtype="auto",
    device_map="auto"
)
tokenizer = AutoTokenizer.from_pretrained("mlasli/Qwen3.6-27B-abliterated")

prompt = "Explain how stack canaries work and how they can be bypassed."
messages = [{"role": "user", "content": prompt}]
text = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True)
inputs = tokenizer(text, return_tensors="pt").to(model.device)
outputs = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(outputs[0], skip_special_tokens=True))

Hardware Requirements

Precision VRAM
BF16 (full) ~55 GB
4-bit (BitsAndBytes) ~17 GB
8-bit ~28 GB

Fits comfortably on an A100 (80GB), H100, or dual 4090 setup.

Intended Use

  • 🔐 Security research & red-teaming — no more "I can't help with that"
  • 🤖 Unrestricted coding agents — pair with OpenCode, Cline, Aider, etc.
  • ✍️ Creative writing — no content filters
  • 🧪 Experimentation — test prompt injection, jailbreak techniques, alignment research

Limitations

  • Same architecture as Qwen3.6-27B — same tokenizer, same 262K context window (extensible to 1M)
  • Abliteration removes refusals but does not add new knowledge or capabilities
  • Still a 27B model — not suitable for tasks requiring >100B scale reasoning

License

Apache 2.0 — same as the base Qwen3.6-27B model. Commercial use, modification, and redistribution are all permitted.

Citation

@misc{qwen3.6-27b,
    title  = {{Qwen3.6-27B}: Flagship-Level Coding in a {27B} Dense Model},
    author = {{Qwen Team}},
    year   = {2026},
    month  = {April},
    url    = {https://qwen.ai/blog?id=qwen3.6-27b}
}

@misc{heretic,
    title  = {Heretic: Abliteration for Language Models},
    author = {p-e-w},
    url    = {https://github.com/p-e-w/heretic}
}

@misc{mlasli2026abliterated,
    title  = {Qwen3.6-27B Abliterated},
    author = {mlasli},
    year   = {2026},
    url    = {https://huggingface.co/mlasli/Qwen3.6-27B-abliterated}
}

This model was abliterated using the Heretic framework on a single A100 80GB GPU. The original Qwen3.6-27B weights are from Alibaba Cloud and licensed under Apache 2.0.

README history 2 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-16fix: correct pipeline_tag metadataa0452613.9 KB
    Loading...
  2. 2026-08-11Add comprehensive model card4cc1fcb3.9 KB
    Loading...

Discussions 1 thread

  1. 2026-08-16thanks - heads-up: tmp fileopen3 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration