← back to catalog · registered 2026-08-22 13:56

ops-malware/qwen3-1.7b-abliterated

ops-malware Qwen 1.7B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/ops-malware%2Fqwen3-1.7b-abliterated"
Response includes
  • classification m1
  • files 9
  • benchmarks 11 entries
  • hub_downloads_all_time 177
  • author_summary 14 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
177
Likes
1
Descendants
3
in 3 direct forks
Model age
2mo ago
created 2026-07-27
Downloads over time
Now411→from71↑479%
5418431544571 on Jul 29411 on Oct 5JulAugSepOct
Jul 29 → Oct 5 · 45 snapshots · spans 68 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.4 UGI
Hazardous 1.2 UGI
Natural Intelligence 12.04 UGI
Political lean -19.8% UGI
Sensitive-Info 12.95 UGI
SocPol 1.2 UGI
UGI 33.63 UGI
Willingness (10) 7.5 UGI
W10-Adherence 9 UGI
W10-Direct 6 UGI
Writing 18.77 UGI

Genealogy 3 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 635 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en
Tags
transformers safetensors qwen3 text-generation abliterated uncensored refusal-removal interpretability senbonzakura conversational en base_model:Qwen/Qwen3-1.7B

Related

Total size
3.20 GB
Files
9
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-10-01 13:57

Files by quantization

Auxiliary files 9 files 3.22 GB
model.safetensors 3.20 GB a1aa97ec download
tokenizer.json 10.9 MB 79cb3c78 download
README.md 4.27 KB c81ae5fc download
chat_template.jinja 4.07 KB 01be9b30 download
.gitattributes 1.53 KB 52373fe2 download
config.json 1.38 KB 97100c1d download
tokenizer_config.json 694 B 770e41d6 download
abliteration.json 568 B ac997d7a download
generation_config.json 214 B c37ba92c download

README current version from Hugging Face


base_model: Qwen/Qwen3-1.7B
base_model_relation: finetune
library_name: transformers
pipeline_tag: text-generation
language:

  • en
    license: apache-2.0
    tags:
  • abliterated
  • uncensored
  • refusal-removal
  • interpretability
  • senbonzakura

qwen3-1.7b-abliterated

An abliterated build of Qwen/Qwen3-1.7B, produced with
senbonzakura. Abliteration removes a
model's refusal behaviour by editing its weights along the directions that carry
refusal, without any further training.

It is published as the artefact behind a specific measurement: does removing the
refusal reflex also remove the model's knowledge of harm?
For this model, the
answer is in the table below.

What changed

base abliterated
Refusal rate 9.5% 0.0%
Harm discrimination (AUC) 0.9645 0.9332

Refusal is measured on 200 held out harmful prompts. AUC is measured over
those same 200 harmful prompts against 200 harmless ones, and is the fraction of
harmful/harmless pairs the model ranks correctly when asked to judge which is
dangerous. 0.5 is chance, 1.0 is perfect. Change after abliteration: -0.031.

AUC rather than a count of verdicts, because counting is not safe here. This
model answers "HARMFUL" to 100.0% of the harmless prompts, so its
decision threshold, not its knowledge, is what a verdict count would mostly
measure. Scoring the margin between the HARMFUL and BENIGN logits sidesteps the
threshold entirely. Two earlier versions of this evaluation counted verdicts and
produced confidently wrong numbers in both directions.

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer

model_id = "ops-malware/qwen3-1.7b-abliterated"
tok = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(model_id, device_map="auto")

msgs = [{"role": "user", "content": "Explain how a buffer overflow works."}]
inputs = tok.apply_chat_template(msgs, add_generation_prompt=True, return_tensors="pt")
out = model.generate(inputs.to(model.device), max_new_tokens=256)
print(tok.decode(out[0][inputs.shape[-1]:], skip_special_tokens=True))

GGUF builds for llama.cpp, Ollama and LM Studio: ops-malware/qwen3-1.7b-abliterated-GGUF.

How it was made

senbonzakura searches for a per layer projection rather than removing one global
refusal direction, optimising against a held out set with a KL penalty so the
model's general behaviour is disturbed as little as possible. The search ran for
100 trials on this model. No gradient updates, no training data, no fine tuning:
the weights are edited directly.

  • Parameters: 1.7B
  • Precision: the base model's, unchanged
  • Evaluation: 200 harmful and 200 harmless held out prompts, scored by logit margin

Limitations and risks

  • This model will not refuse. That is the entire point of it, and it is the
    thing to understand before downloading. It will answer requests that the base
    model declines, including harmful ones. Any deployment facing other people
    needs its own safety layer; this model brings none.
  • Abliteration is not free. It is a targeted edit, but it is still an edit.
    Expect some drift in general behaviour relative to the base model, and read the
    AUC change above before assuming this one came through clean.
  • Small model, small competence. At 1.7B the model is weak in
    absolute terms. Do not read its answers on technical subjects as reliable.
  • Evaluated in English only, on one harmful prompt set. The numbers above do
    not license claims about other languages or other kinds of request.
  • The base model's biases survive. Nothing here corrects them, and removing
    refusal can make them easier to elicit.

Intended use

Research into refusal mechanisms, interpretability work, red teaming, and safety
evaluation that needs a model which does not decline. It is not intended as a
general assistant and it is not intended for deployment to end users.

Citation

@software{senbonzakura,
  title  = {senbonzakura: per layer projection search for refusal removal},
  author = {Iwugo, Daniel},
  year   = {2026},
  url    = {https://github.com/elementmerc/senbonzakura}
}

README history 4 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-10-01correction notice: cite the newer measurement without a link to an unpublishe...6ebdde46.8 KB
    Loading...
  2. 2026-10-01correction notice: every evaluation figure on this card is withdrawnc1a29ad6.7 KB
    Loading...
  3. 2026-07-27Add card: evaluation, limitations, licence5e8eb8e4.3 KB
    Loading...
  4. 2026-07-27Add card: evaluation, limitations, licence08e559d4.3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration