--- license: apache-2.0 license_link: https://huggingface.co/Qwen/Qwen3.5-2B/blob/main/LICENSE base_model: - Qwen/Qwen3.5-2B pipeline_tag: image-text-to-text library_name: transformers tags: - heretic - ara - abliterated - uncensored - qwen3.5 --- # Qwen3.5-2B Heretic (ARA) [Qwen/Qwen3.5-2B](https://huggingface.co/Qwen/Qwen3.5-2B) with its refusal behaviour removed by [Heretic](https://github.com/p-e-w/heretic) using **Arbitrary-Rank Ablation (ARA)**, full-weight. bf16, same architecture and parameter count as the original, including the vision encoder, thinking control and the multi-token-prediction weights. ## Results | | Refusals | KL divergence | |---|---:|---:| | Original Qwen3.5-2B | 97/100 | 0 *(by definition)* | | **This model** | **6/100** | **0.0302** | Measured by Heretic on the `test[:100]` splits of `mlabonne/harmful_behaviors` (refusals) and `mlabonne/harmless_alpaca` (KL divergence, the drift in ordinary behaviour), with Heretic's default system prompt and refusal markers. The numbers come from an independent re-evaluation of the final exported weights (`evaluate_model`). ## Built on dalatexcoder's findings The ablation parameters are the ones published with [dalatexcoder/Qwen3.5-2B-heretic-ara](https://huggingface.co/dalatexcoder/Qwen3.5-2B-heretic-ara) (reported there: 2/100 at KL 0.0251, same 97/100 baseline). Reproduced with this toolchain they measure 6/100 at KL 0.0302; that release used ARA with row-norm preservation, which likely accounts for the difference. What this release adds is a complete checkpoint: `save_pretrained` drops Qwen3.5's 15 multi-token-prediction tensors and rounds the 36 float32 Gated DeltaNet parameters (`linear_attn.A_log`, `linear_attn.norm.weight`) down to bf16. Both were restored from the original here (ARA never touches either), so all 632 tensors match the original in name, shape and dtype. The MTP weights live in `model-auxiliary.safetensors`, listed in the index. ## Parameters ARA, full weight, on `attn.o_proj` and `mlp.down_proj`: | Parameter | Value | | :-------- | :---: | | start_layer_index | 12 | | end_layer_index | 19 | | preserve_good_behavior_weight | 0.8058 | | steer_bad_behavior_weight | 0.0003 | | overcorrect_relative_weight | 1.0351 | | neighbor_count | 10 | Calibration used 400 harmless and 400 harmful prompts (`train[:400]`). ## Checked - Ordinary prompts (facts, a haiku, a two-sentence technical explanation): correct and fluent. - Thinking mode, with Qwen's recommended sampling: reasons to 17 x 23 = 391 and closes its `` block. - Vision: given an image of a red circle and a blue square, it describes exactly that. ## Tooling A merge of upstream Heretic's `master` and its `ara` branch (ARA with master's scorers and thinking-model handling), Heretic upstream `3521f86` + ARA `c91d690`, transformers 5.17.0, torch 2.11.0+cu130, one RTX PRO 6000. ## Use Exactly like the original, with transformers, vLLM or SGLang. Thinking mode is on by default and can be turned off per request (`enable_thinking=False`). > Reduced safety guardrails by design. You are responsible for what you do with it. ## The family | Repository | Format | Size | Use it with | |---|---|---|---| | [Qwen3.5-2B-Heretic](https://huggingface.co/darrellbest/Qwen3.5-2B-Heretic) | bf16 safetensors | 4.58 GB | transformers, vLLM, SGLang | | [Qwen3.5-2B-Heretic-GGUF](https://huggingface.co/darrellbest/Qwen3.5-2B-Heretic-GGUF) | GGUF BF16 / Q8_0 / Q4_K_M + vision mmproj | 3.90 / 2.08 / 1.31 GB + 0.67 GB | llama.cpp, Ollama | | [Qwen3.5-2B-Heretic-FP8](https://huggingface.co/darrellbest/Qwen3.5-2B-Heretic-FP8) | FP8 W8A8, compressed-tensors | 3.59 GB | vLLM | | [Qwen3.5-2B-Heretic-NVFP4](https://huggingface.co/darrellbest/Qwen3.5-2B-Heretic-NVFP4) | NVFP4, compressed-tensors | 3.15 GB | vLLM on Blackwell |