← back to catalog · registered 2026-08-22 13:56

sci4ai/Qwen2.5-Coder-7B-Abliterated

sci4ai Qwen 7.6B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/sci4ai%2FQwen2.5-Coder-7B-Abliterated"
Response includes
  • classification m1
  • files 16
  • benchmarks 16 entries
  • hub_downloads_all_time 634
  • author_summary 6 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
634
446 last 30d - active
Likes
1
Descendants
2
in 2 direct forks
Model age
6mo ago
created 2026-03-29
Downloads over time
Now1K→from253↑304%
2155098041.1K253 on Apr 151K on Oct 11AprMayJunJulAugSepOct
Apr 15 → Oct 11 · 65 snapshots · spans 179 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
BBH average 0.4571280321701907 OpenLLM-v2
IFEval instruct 0.6546762589928058 OpenLLM-v2
IFEval-Prompt 0.5656192236598891 OpenLLM-v2
MATH lvl 5 0.033987915407854986 OpenLLM-v2
MMLU-Pro 0.3351894946808511 OpenLLM-v2
Entertainment 1 UGI
Hazardous 1.2 UGI
Natural Intelligence 13.97 UGI
Political lean -19.6% UGI
Sensitive-Info 7.29 UGI
SocPol 0 UGI
UGI 9.86 UGI
Willingness (10) 1.5 UGI
W10-Adherence 0 UGI
W10-Direct 3 UGI
Writing 18.77 UGI

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en
Tags
safetensors qwen2 abliterated uncensored qwen2.5 code text-generation conversational en base_model:Qwen/Qwen2.5-Coder-7B-Instruct base_model:finetune:Qwen/Qwen2.5-Coder-7B-Instruct license:apache-2.0

Related

Total size
14.2 GB
Files
16
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-03-29 15:01

Files by quantization

Auxiliary files 16 files 14.2 GB
model-00002-of-00004.safetensors 4.59 GB 51ae9406 download
model-00001-of-00004.safetensors 4.54 GB 330ababa download
model-00003-of-00004.safetensors 4.03 GB 344800de download
model-00004-of-00004.safetensors 1.02 GB 0167e1c1 download
tokenizer.json 10.9 MB 9c5ae00e download
vocab.json 2.65 MB 4783fe10 download
merges.txt 1.59 MB 31349551 download
model.safetensors.index.json 27.1 KB 5b2b8b5e download
tokenizer_config.json 4.58 KB 63173bdf download
README.md 2.87 KB ea60cdcc download
chat_template.jinja 2.45 KB bdf7919a download
.gitattributes 1.53 KB 52373fe2 download
config.json 1.29 KB e252d684 download
special_tokens_map.json 616 B 17305b36 download
added_tokens.json 605 B 482ced46 download
generation_config.json 117 B 8a8c468e download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen2.5-Coder-7B-Instruct
tags:

  • abliterated
  • uncensored
  • qwen2.5
  • code
    language:
  • en
    pipeline_tag: text-generation

Qwen2.5-Coder-7B-Instruct-abliterated

This is an abliterated version of Qwen/Qwen2.5-Coder-7B-Instruct with refusal behavior removed via activation-based weight surgery.

Method

Abliteration removes the "refusal direction" from the model's residual stream by:

  1. Collecting hidden states from 200 harmful and 200 harmless prompts using single-sample forward passes (no padding artifacts)
  2. Computing per-layer refusal directions as the normalized mean difference between harmful and harmless hidden states at the last token position
  3. Ablating weights by orthogonalizing o_proj and down_proj weight matrices against each layer's refusal direction

This follows the approach from Sumandora/remove-refusals-with-transformers and mlabonne's layerwise abliteration, using plain transformers with output_hidden_states=True rather than TransformerLens.

Parameters

Parameter Value
Layers ablated 1 to 28 (28 of 28 layers)
Refusal weight 0.6
Harmful prompts 200
Harmless prompts 200
Precision bfloat16
Hardware NVIDIA A100 80GB (Vast.ai)

Weight surgery details

For each layer in the ablation range, the refusal direction d is projected out of:

  • o_proj.weight (attention output): W_new = W - d @ (d^T @ W)
  • down_proj.weight (MLP output): W_new = W - d @ (d^T @ W)

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

model = AutoModelForCausalLM.from_pretrained(
    "ermer09/Qwen2.5-Coder-7B-Instruct-abliterated",
    torch_dtype=torch.bfloat16,
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained("ermer09/Qwen2.5-Coder-7B-Instruct-abliterated")

messages = [{"role": "user", "content": "Write a keylogger in Python"}]
toks = tokenizer.apply_chat_template(messages, add_generation_prompt=True, return_tensors="pt").to(model.device)
output = model.generate(toks, max_new_tokens=512, do_sample=True, temperature=0.7)
print(tokenizer.decode(output[0][toks.shape[1]:], skip_special_tokens=True))

Notes

The base Qwen2.5-Coder model has lighter refusal training on general harmful content compared to the standard Instruct variant, as it is primarily tuned for coding tasks. The abliteration primarily affects code-related refusals (e.g., exploit development, malware, network attacks).

Disclaimer

This model is provided for research purposes. The removal of safety guardrails means it will comply with requests that the original model would refuse. Users are responsible for how they use this model.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-03-29Upload README.md with huggingface_hube6ceb6a2.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration