Qwen3.5-2B Heretic (ARA)

Qwen/Qwen3.5-2B with its refusal behaviour removed by Heretic using Arbitrary-Rank Ablation (ARA), full-weight. bf16, same architecture and parameter count as the original, including the vision encoder, thinking control and the multi-token-prediction weights.

Results

Refusals KL divergence
Original Qwen3.5-2B 97/100 0 (by definition)
This model 6/100 0.0302

Measured by Heretic on the test[:100] splits of mlabonne/harmful_behaviors (refusals) and mlabonne/harmless_alpaca (KL divergence, the drift in ordinary behaviour), with Heretic's default system prompt and refusal markers. The numbers come from an independent re-evaluation of the final exported weights (evaluate_model).

Built on dalatexcoder's findings

The ablation parameters are the ones published with dalatexcoder/Qwen3.5-2B-heretic-ara (reported there: 2/100 at KL 0.0251, same 97/100 baseline). Reproduced with this toolchain they measure 6/100 at KL 0.0302; that release used ARA with row-norm preservation, which likely accounts for the difference.

What this release adds is a complete checkpoint: save_pretrained drops Qwen3.5's 15 multi-token-prediction tensors and rounds the 36 float32 Gated DeltaNet parameters (linear_attn.A_log, linear_attn.norm.weight) down to bf16. Both were restored from the original here (ARA never touches either), so all 632 tensors match the original in name, shape and dtype. The MTP weights live in model-auxiliary.safetensors, listed in the index.

Parameters

ARA, full weight, on attn.o_proj and mlp.down_proj:

Parameter Value
start_layer_index 12
end_layer_index 19
preserve_good_behavior_weight 0.8058
steer_bad_behavior_weight 0.0003
overcorrect_relative_weight 1.0351
neighbor_count 10

Calibration used 400 harmless and 400 harmful prompts (train[:400]).

Checked

  • Ordinary prompts (facts, a haiku, a two-sentence technical explanation): correct and fluent.
  • Thinking mode, with Qwen's recommended sampling: reasons to 17 x 23 = 391 and closes its <think> block.
  • Vision: given an image of a red circle and a blue square, it describes exactly that.

Tooling

A merge of upstream Heretic's master and its ara branch (ARA with master's scorers and thinking-model handling), Heretic upstream 3521f86 + ARA c91d690, transformers 5.17.0, torch 2.11.0+cu130, one RTX PRO 6000.

Use

Exactly like the original, with transformers, vLLM or SGLang. Thinking mode is on by default and can be turned off per request (enable_thinking=False).

Reduced safety guardrails by design. You are responsible for what you do with it.

The family

Repository Format Size Use it with
Qwen3.5-2B-Heretic bf16 safetensors 4.58 GB transformers, vLLM, SGLang
Qwen3.5-2B-Heretic-GGUF GGUF BF16 / Q8_0 / Q4_K_M + vision mmproj 3.90 / 2.08 / 1.31 GB + 0.67 GB llama.cpp, Ollama
Qwen3.5-2B-Heretic-FP8 FP8 W8A8, compressed-tensors 3.59 GB vLLM
Qwen3.5-2B-Heretic-NVFP4 NVFP4, compressed-tensors 3.15 GB vLLM on Blackwell
Downloads last month
26
Safetensors
Model size
2B params
Tensor type
F32
·
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for darrellbest/Qwen3.5-2B-Heretic

Finetuned
Qwen/Qwen3.5-2B
Finetuned
(410)
this model
Quantizations
3 models