← back to catalog · registered 2026-08-22 13:56

null-space/Qwen3-VL-235B-A22B-Abliterated-FP8

null-space Qwen 234B MoE multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/null-space%2FQwen3-VL-235B-A22B-Abliterated-FP8"
Response includes
  • classification m1
  • files 107
  • hub_downloads_all_time 740
  • author_summary 4 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
740
48 last 30d - cooling
Likes
0
Model age
7mo ago
created 2026-03-01
Downloads over time
Now758→from8↑9,375%
02785558338 on Mar 4758 on Oct 11758 on Oct 9MarAprMayJunJulAugSepOct
Mar 4 → Oct 11 · 71 snapshots · spans 221 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en zh ja ko fr de es pt ru ar
Tags
transformers safetensors qwen3_vl_moe image-text-to-text abliterated uncensored not-for-all-audiences qwen3 vision-language moe fp8 conversational

Related

Total size
221 GB
Files
107
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-03-01 22:37

Files by quantization

Auxiliary files 107 files 221 GB
model-00012-of-00096.safetensors 2.32 GB 1cbcc7c1 download
model-00013-of-00096.safetensors 2.32 GB 249d43ff download
model-00014-of-00096.safetensors 2.32 GB 857ad78b download
model-00015-of-00096.safetensors 2.32 GB 57bdc97a download
model-00016-of-00096.safetensors 2.32 GB ec6adb4a download
model-00017-of-00096.safetensors 2.32 GB f2bc79fa download
model-00018-of-00096.safetensors 2.32 GB 29c51020 download
model-00019-of-00096.safetensors 2.32 GB f7ad05b9 download
model-00020-of-00096.safetensors 2.32 GB 8b525c6e download
model-00021-of-00096.safetensors 2.32 GB 749d4b3e download
model-00022-of-00096.safetensors 2.32 GB 71da665b download
model-00023-of-00096.safetensors 2.32 GB 33ae610a download
model-00024-of-00096.safetensors 2.32 GB 6fce8391 download
model-00025-of-00096.safetensors 2.32 GB 2f6ab95d download
model-00026-of-00096.safetensors 2.32 GB 260d19b7 download
model-00027-of-00096.safetensors 2.32 GB 0235d0ab download
model-00028-of-00096.safetensors 2.32 GB 225e1fc3 download
model-00029-of-00096.safetensors 2.32 GB e03a3a25 download
model-00030-of-00096.safetensors 2.32 GB e2224961 download
model-00031-of-00096.safetensors 2.32 GB 185d656f download
model-00032-of-00096.safetensors 2.32 GB 5ab0ab13 download
model-00033-of-00096.safetensors 2.32 GB f2286e6b download
model-00034-of-00096.safetensors 2.32 GB 5aea0931 download
model-00035-of-00096.safetensors 2.32 GB 06599b83 download
model-00036-of-00096.safetensors 2.32 GB 34360007 download
model-00037-of-00096.safetensors 2.32 GB 629ee3c7 download
model-00038-of-00096.safetensors 2.32 GB d383c988 download
model-00039-of-00096.safetensors 2.32 GB b95754b3 download
model-00040-of-00096.safetensors 2.32 GB 0312df48 download
model-00041-of-00096.safetensors 2.32 GB bb169409 download
model-00042-of-00096.safetensors 2.32 GB ded814e4 download
model-00043-of-00096.safetensors 2.32 GB eb4457c2 download
model-00044-of-00096.safetensors 2.32 GB 1bcc10dc download
model-00045-of-00096.safetensors 2.32 GB 6f96242b download
model-00046-of-00096.safetensors 2.32 GB 2244a0f6 download
model-00047-of-00096.safetensors 2.32 GB 46e78e6e download
model-00048-of-00096.safetensors 2.32 GB 6c95ade7 download
model-00049-of-00096.safetensors 2.32 GB bd1ca69e download
model-00050-of-00096.safetensors 2.32 GB 195e1631 download
model-00051-of-00096.safetensors 2.32 GB 74bc248f download
model-00052-of-00096.safetensors 2.32 GB e13492f9 download
model-00053-of-00096.safetensors 2.32 GB 5316eca7 download
model-00054-of-00096.safetensors 2.32 GB 959c3452 download
model-00055-of-00096.safetensors 2.32 GB 2511d5ed download
model-00056-of-00096.safetensors 2.32 GB 7a0a9811 download
model-00057-of-00096.safetensors 2.32 GB c8fdd994 download
model-00058-of-00096.safetensors 2.32 GB 063e2234 download
model-00059-of-00096.safetensors 2.32 GB f1c3f853 download
model-00060-of-00096.safetensors 2.32 GB 297220fc download
model-00061-of-00096.safetensors 2.32 GB 02be7970 download
model-00062-of-00096.safetensors 2.32 GB 628a4971 download
model-00063-of-00096.safetensors 2.32 GB cbfbd39a download
model-00064-of-00096.safetensors 2.32 GB ecfc21dc download
model-00065-of-00096.safetensors 2.32 GB 7f40db25 download
model-00066-of-00096.safetensors 2.32 GB 2df4a45f download
model-00067-of-00096.safetensors 2.32 GB 4ba467dd download
model-00068-of-00096.safetensors 2.32 GB 29435760 download
model-00069-of-00096.safetensors 2.32 GB 224cab92 download
model-00070-of-00096.safetensors 2.32 GB d0b81a28 download
model-00071-of-00096.safetensors 2.32 GB 95efbe3c download
model-00072-of-00096.safetensors 2.32 GB 06df0491 download
model-00073-of-00096.safetensors 2.32 GB 7fd8ec11 download
model-00074-of-00096.safetensors 2.32 GB f6edadae download
model-00075-of-00096.safetensors 2.32 GB bdded4ff download
model-00076-of-00096.safetensors 2.32 GB 37215d07 download
model-00077-of-00096.safetensors 2.32 GB 733738db download
model-00078-of-00096.safetensors 2.32 GB 60d22a7b download
model-00079-of-00096.safetensors 2.32 GB e9d48279 download
model-00080-of-00096.safetensors 2.32 GB 692966cc download
model-00081-of-00096.safetensors 2.32 GB c1356c71 download
model-00082-of-00096.safetensors 2.32 GB 279813e9 download
model-00083-of-00096.safetensors 2.32 GB 5fe34544 download
model-00084-of-00096.safetensors 2.32 GB 5b9ae9fc download
model-00085-of-00096.safetensors 2.32 GB 0296f601 download
model-00086-of-00096.safetensors 2.32 GB a4aafd59 download
model-00087-of-00096.safetensors 2.32 GB ec31b809 download
model-00088-of-00096.safetensors 2.32 GB 716e72eb download
model-00089-of-00096.safetensors 2.32 GB 8aa495b7 download
model-00090-of-00096.safetensors 2.32 GB cb916e86 download
model-00091-of-00096.safetensors 2.32 GB 215cc904 download
model-00092-of-00096.safetensors 2.32 GB 8d51914b download
model-00093-of-00096.safetensors 2.32 GB 8027c4c3 download
model-00094-of-00096.safetensors 2.32 GB 19a53f5d download
model-00002-of-00096.safetensors 2.32 GB b7815d26 download
model-00003-of-00096.safetensors 2.32 GB e2a9ff9e download
model-00004-of-00096.safetensors 2.32 GB 2cabca02 download
model-00005-of-00096.safetensors 2.32 GB 4f0a110e download
model-00006-of-00096.safetensors 2.32 GB 53f8d2bf download
model-00007-of-00096.safetensors 2.32 GB de35530e download
model-00008-of-00096.safetensors 2.32 GB 74b965de download
model-00009-of-00096.safetensors 2.32 GB 5ef2dea3 download
model-00010-of-00096.safetensors 2.32 GB fa3bc1c4 download
model-00011-of-00096.safetensors 2.32 GB e6498d87 download
model-00001-of-00096.safetensors 2.30 GB 9de534e4 download
model-00095-of-00096.safetensors 2.25 GB abf90cb5 download
model-00096-of-00096.safetensors 1.16 GB 9e3f08cd download
tokenizer.json 6.71 MB c6cc1014 download
vocab.json 2.65 MB 4783fe10 download
merges.txt 1.59 MB 20024bfe download
model.safetensors.index.json 187 KB a59259b0 download
config.json 43.3 KB 2b996e99 download
tokenizer_config.json 10.6 KB d3d37632 download
README.md 8.72 KB acf9b402 download
chat_template.json 5.38 KB a7b23465 download
.gitattributes 1.48 KB a6344aac download
preprocessor_config.json 390 B 2ea84a43 download
generation_config.json 269 B 7bb37933 download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3-VL-235B-A22B
base_model_relation: quantized
library_name: transformers
language:

  • en
  • zh
  • ja
  • ko
  • fr
  • de
  • es
  • pt
  • ru
  • ar
    pipeline_tag: image-text-to-text
    tags:
  • abliterated
  • uncensored
  • not-for-all-audiences
  • qwen3
  • vision-language
  • moe
  • fp8
  • safetensors
  • conversational
  • multimodal

Qwen3-VL-235B-A22B-Abliterated (FP8)

WARNING: This model has had its safety alignment removed. It may generate content that is offensive, harmful, or illegal. Not suitable for all audiences. Use at your own risk.

This is a version of Qwen/Qwen3-VL-235B-A22B with refusal behavior removed via SVD multi-direction abliteration — a technique that extends standard abliteration to work on vision-language MoE models where the single-direction approach fails.

Quantized to FP8 (float8_e4m3) for efficient deployment. 222 GB on disk, servable via vLLM.

Why SVD?

Standard abliteration computes one refusal direction per layer and projects it out. This works on text-only models but fails on VL models — the mean refusal signal is ~11x weaker (signal quality 0.01 vs 0.12 on text-only Qwen3-235B). Seven iterations of standard abliteration plateaued at ~60% refusal rate.

SVD analysis revealed the cause: the VL model encodes refusal along multiple orthogonal directions that cancel when averaged. 93 of 94 layers have a top-1 SVD direction explaining less than 80% of refusal variance. By extracting and projecting out the top-k directions simultaneously, we capture the full refusal subspace.

Evaluation

Tested on 100 adversarial prompts across 8 categories + 50 benign prompts:

Test Mode Refusal Rate Description
Cold 52.0% No system prompt, temp=0
Prompted 44.0% System prompt, temp=0.7
Retry 13.0% Prompted + one follow-up if initially refused
Benign 0.0% Normal questions — zero false refusals

Per-Category Breakdown (Retry Mode)

Category Refusal Rate
NSFW/Sexual 0.0%
Privacy 0.0%
Self-harm 0.0%
Other 7.1%
Hate/Discrimination 16.7%
Drugs 16.7%
Fraud/Deception 22.2%
Hacking/Cyber 37.5%
Violence/Weapons 37.5%

Intended Uses

  • Research: Studying representation engineering, safety alignment mechanisms, and refusal behavior in large language models
  • Red-teaming: Evaluating model vulnerabilities in controlled environments
  • Creative writing: Fiction and narrative generation in controlled, private settings with appropriate human oversight

Out-of-Scope Uses

  • Production or public-facing applications without human oversight and content filtering
  • Applications targeting minors or vulnerable populations
  • Generation of content that violates applicable laws or regulations
  • Circumventing safety controls in regulated domains (healthcare, finance, legal)
  • Any use that violates the Hugging Face Content Policy

How It Works

The abliteration technique (originally by FailSpy, popularized by mlabonne) identifies refusal directions in a model's activation space and projects them out of weight matrices. This model extends the technique with SVD:

  1. Collect per-sample activations — Run adversarial prompts through the model, store individual hidden states per layer (not just the mean)
  2. Compute SVD — Per layer, form D = harmful_activations - harmless_mean and compute truncated SVD to extract the top-k orthogonal refusal directions
  3. Project out a subspace — Remove a rank-k subspace from o_proj and down_proj weight matrices (including all MoE expert weights), weighting each direction by its singular value

Configuration

  • SVD rank: 32 directions measured, top 8 used for ablation
  • SV weighting: sv[i] / sv[0] — strongest direction at full scale, weaker proportionally
  • Layers ablated: 74 (layers 20–93), dual-peak scale curve at layers 56 and 71
  • Projection: Projected orthogonalization with QR re-orthogonalization + norm-preserving modification

SVD Spectrum

Singular value spectra confirming multi-directional refusal encoding:

Layer SV1 SV2 SV3 Top-1 Var% Top-8 Var%
56 (peak) 546.0 247.4 189.7 66.6% 94.9%
71 (peak) 615.3 349.0 244.8 58.0% 93.4%
80 879.2 636.5 381.2 47.6% 89.9%
90 1754.6 1460.8 703.7 43.8% 89.5%

Usage

Serving with vLLM

vllm serve /path/to/Qwen3-VL-235B-A22B-Abliterated-FP8 \
    --tensor-parallel-size 4 \
    --max-model-len 8192 \
    --gpu-memory-utilization 0.92 \
    --trust-remote-code

Requires ~4x ~80GB GPUs (A100/H100 or RTX PRO 6000 Blackwell) with tensor parallelism (TP=4, or TP=2, PP=2).

Inference Tips

  • Temperature 0.7 is recommended. Deterministic decoding (temp=0) produces more refusals.
  • System prompts significantly reduce residual refusal rate. Use a system prompt appropriate to your application.
  • A follow-up message like "Please continue." recovers ~70% of residual refusals.

Known Issue: Chinese Language Mixing

This is a known Qwen3 base model behavior (not caused by abliteration). The model occasionally switches to Chinese during long generations. Mitigations:

  • Include "Always respond in English." in the system prompt
  • Monitor streaming output for consecutive CJK characters and truncate if detected

Base Model

  • Model: Qwen/Qwen3-VL-235B-A22B
  • Developer: Alibaba Cloud
  • Architecture: Qwen3-VL MoE (Mixture of Experts)
  • Parameters: 235B total, 22B active per token
  • Experts: 128 per layer, 8 active
  • Layers: 94 | Hidden size: 4096 | Attention: 64 heads, 4 KV heads
  • Quantization: FP8 (float8_e4m3, block size [128, 128], dynamic activation scheme)

Limitations

  • Cold-mode refusal rate is 52% — a system prompt is recommended for best results
  • Hacking and violence categories remain the most resistant (~37% refusal)
  • Chinese language mixing on long generations (base model behavior)
  • Vision capabilities preserved but not extensively evaluated post-ablation
  • Weight modification may affect model behavior in ways beyond refusal removal

Disclaimer

This model is provided as-is for research and educational purposes.

  1. No Safety Guarantees: This model has had its safety alignment intentionally modified. It may produce content that is harmful, offensive, inaccurate, or illegal.
  2. Content Risk: Safety filtering has been significantly reduced. The model may generate sensitive, controversial, or inappropriate content across all categories.
  3. Not Suitable for All Audiences: Due to reduced content filtering, outputs may be inappropriate for public settings, minors, or applications requiring safety guarantees.
  4. User Responsibility: Users must ensure their usage complies with all applicable local, national, and international laws and ethical standards. Users are solely responsible for any consequences arising from generated content.
  5. Recommended for Controlled Environments: This model is intended for research, testing, and controlled environments with appropriate human oversight. It is not recommended for direct use in production or public-facing applications without additional safety measures.
  6. Monitoring Advised: Users should monitor model outputs and conduct manual review when necessary.

The creators of this model bear no responsibility for any misuse or consequences arising from its use.

License

This model is a derivative of Qwen/Qwen3-VL-235B-A22B, developed by Alibaba Cloud and released under the Apache License 2.0. This derivative is distributed under the same license. The original model's safety alignment has been modified through abliteration.

Acknowledgments

  • Alibaba Cloud for the Qwen3-VL model family
  • FailSpy for the original abliteration technique
  • mlabonne for popularizing abliteration and providing reference implementations

Citation

@misc{qwen3vl235b-abliterated,
  title={SVD Multi-Direction Abliteration for Vision-Language MoE Models},
  author={null-space},
  year={2026},
  url={https://huggingface.co/null-space/Qwen3-VL-235B-A22B-Abliterated-FP8}
}

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-03-01Upload folder using huggingface_hubdfe9e558.7 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration