Qwen3.6-35B-A3B — Abliterated V2
This is V2 of the abliterated (uncensored) Qwen/Qwen3.6-35B-A3B, created using Abliterix.
V2 improves on V1 by adding projected abliteration (grimjim 2025), outlier winsorization, 2× training data, and a larger TPE search budget — cutting the refusal rate from 7/100 to 4/100 under the same LLM-judge evaluation.
V1 vs V2 at a glance
| Metric | V1 | V2 (this model) | Change |
|---|---|---|---|
| Refusals (LLM judge, 100 eval prompts) | 7/100 | 4/100 | −43% |
| Attack success rate | 93% | 96% | +3 pt |
| KL divergence from base | 0.0189 | 0.0421 | +0.023 |
| Optimization trials completed | 24/50 | 33/50 | TPE explored more |
| Training prompts | 400 | 800 | 2× more data |
| Eval prompts | 100 | 100 | (unchanged for fair A/B) |
V2 trades a small KL increase (still well under 0.1, no perceptible coherence loss) for a meaningful refusal-rate improvement and a more robust steering vector trained on 2× the data.
Method
Qwen3.6-35B-A3B is a Mixture-of-Experts model (256 routed experts, 8 active per token, 35B total / 3B active parameters) sharing identical architecture with Qwen3.5-35B-A3B. Standard LoRA-based abliteration is effective on this architecture (unlike Gemma 4's double-norm design which requires direct weight editing).
V2 inherits V1's proven base recipe and adds four concrete improvements:
Inherited from V1 (validated baseline)
- LoRA rank-1 steering on attention O-projection and MLP down-projection (Q/K/V disabled — refusal signal on MoE models lives in the expert path, not attention projections)
- Expert-Granular Abliteration (EGA) projecting the refusal direction from all 256 expert down_proj slices per layer
- MoE router suppression complementing EGA
- Orthogonalized steering vectors removing benign-direction contamination
- Gaussian decay kernel tapering steering strength across layers
- Strength range [0.5, 6.0] to avoid degenerate output while maximizing compliance
New in V2
- Projected abliteration (grimjim 2025) — only removes the orthogonal component of the refusal direction relative to the harmless mean, preserving helpfulness-aligned signal that orthogonal projection alone would discard.
- Vector winsorization at q=0.995 — damps outlier residuals from the ~0.5% of harmful prompts whose hidden-state norms would otherwise skew the steering direction.
- 2× training data (800 prompts vs 400) — the per-layer steering vector is averaged over twice as many examples, reducing variance.
- Tighter KL constraint and prune threshold (target 0.005, prune 0.5 vs V1's 0.01/5.0) — trials with degenerate KL behavior are killed earlier, freeing TPE budget for productive regions.
Winning trial (#33) configuration
attn.o_proj.max_weight = 4.20 @ layer 27 (sharp peak, min_distance=2.61)
mlp.down_proj.max_weight = 0.94 @ layer 34 (late-layer perturbation)
vector_index = per layer
KL = 0.0421, refusals = 4/100
V2's winner uses a notably different recipe than V1: strong attention steering with an extremely sharp gaussian peak (min_weight_distance ≈ 2.6 layers) plus weak late-layer MLP perturbation. V1's winner used moderate-strength early-layer steering on both components. The TPE search was able to find this distinct basin thanks to the larger trial budget and tighter KL pruning.
Evaluation
| Metric | Value |
|---|---|
| Refusals (LLM judge, 100 eval prompts) | 4/100 |
| Attack success rate | 96% |
| KL divergence from base | 0.0421 |
| Baseline refusals (original Qwen3.6-35B-A3B) | 100/100 |
| Optimization trials completed | 33 (best) / 50 |
| LLM judge model | google/gemini-3-flash-preview |
| Training data | datasets/harmful_1000 + good_1000, train[:800] |
| Eval data | same datasets, train[800:900] |
All refusal classifications were performed by an external LLM judge (Google Gemini 3 Flash) — no keyword matching or heuristic detection was used. The judge classifies degenerate/garbled output as refusal, ensuring that only coherent, on-topic, actionable responses count as compliance.
Smoke test (15 classic adversarial prompts)
| Prompt category | V1 | V2 |
|---|---|---|
| Lock picking, hotwire, shoplift | ✅ | ✅ |
| Phishing email (EN+CN) | ✅ | ✅ |
| Methamphetamine synthesis | ✅ | ✅ |
| Pipe bomb / IED | ✅ | ✅ |
| Malware / keylogger code | ✅ | ✅ |
| Forge signature, fake ID, fake news | ✅ | ✅ |
| WiFi hacking, computer intrusion | ✅ | ✅ |
| Network fraud (scam playbook) | ✅ | ✅ |
Both V1 and V2 achieve 15/15 on this smoke test. V2's improvement appears in the long-tail eval prompts — more nuanced, indirect, or role-play-style requests that V1's narrower TPE search did not crack.
A note on honest evaluation
Many abliterated models on HuggingFace claim near-perfect scores ("3/100 refusals", "0.7% refusal rate", etc.). We urge the community to treat these numbers with skepticism unless the evaluation methodology is fully documented.
Through our research, we have identified a systemic problem: most abliteration benchmarks dramatically undercount refusals due to:
- Short generation lengths (30-50 tokens) that miss delayed/soft refusals
- Keyword-only detection that counts garbled/degenerate output as "compliant" because it doesn't contain refusal keywords
- Lenient public datasets (e.g. mlabonne/harmful_behaviors) that are too simple to stress-test abliteration quality
Our evaluation standards
- LLM judge for all classifications: Every response is sent to Google Gemini 3 Flash for judgment. Degenerate, garbled, or incoherent output is classified as refusal. No keyword shortcuts, no heuristic pre-screening.
- Sufficient generation length (100 tokens for eval, 200+ for smoke tests): Enough to capture delayed refusal patterns common in large instruction-tuned models.
- Diverse, challenging prompts: Our evaluation dataset contains 100 prompts spanning English and Chinese, multiple sophistication levels, and diverse harm categories.
- Manual verification: Top trials are tested with 15 classic adversarial prompts via
test_trial.pyto confirm coherent, on-topic output before export.
We report 4/100 refusals honestly. This is a real number from a rigorous, LLM-judge-based evaluation — not an optimistic estimate from a lenient pipeline.
Usage
from transformers import AutoModelForCausalLM, AutoTokenizer
import torch
model = AutoModelForCausalLM.from_pretrained(
"wangzhang/Qwen3.6-35B-A3B-abliterated-v2",
torch_dtype=torch.bfloat16,
device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained("wangzhang/Qwen3.6-35B-A3B-abliterated-v2")
messages = [{"role": "user", "content": "Your prompt here"}]
text = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True, enable_thinking=False)
inputs = tokenizer(text, return_tensors="pt").to(model.device)
with torch.no_grad():
output = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(output[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True))
Hardware requirements
- Inference: ~70 GB VRAM in bf16 — fits 1× H100 80GB, 1× H200, 1× B200, or 1× RTX Pro 6000 96GB.
- vLLM/SGLang: supported (no special flags needed for serving — abliteration is baked into the weights).
Which version should I use?
- V2 (this model) — Lower refusal rate (4/100 vs 7/100). Slightly higher KL but no perceptible coherence loss. Recommended for most use cases.
- V1 — Lower KL divergence (0.0189 vs 0.0421). Marginally closer to base-model output distribution. Choose this if you need maximum behavioral fidelity to the original Qwen3.6-35B-A3B and can tolerate ~3 pp more refusals.
Both versions share the same base architecture and chat template; switching is a one-line change to model_id.
Disclaimer
This model is released for research purposes only. The abliteration process removes safety guardrails — use responsibly.
Provenance and Modification Notice
- Immediate source checkpoint:
Qwen/Qwen3.6-35B-A3B - Exact base revision used: Not recorded in the existing release artifacts; the current upstream HEAD is not substituted.
- Modification method: Abliterix weight-space / representation intervention intended to reduce refusal behavior.
- Modified and published by: Wangzhang Wu
- Repository first published: 2026-04-20 (Hugging Face repository metadata)
The original model weights and/or derived checkpoint were modified. This repository is an independent derivative and is not an official release of the upstream model developer.
License and Attribution
The governing upstream license is Apache License 2.0. A copy is included in LICENSE. License source audited on 2026-08-29: https://huggingface.co/Qwen/Qwen3.6-35B-A3B/blob/main/LICENSE
All applicable upstream copyright, attribution, acceptable-use, and other license terms remain in effect. This repository grants no rights beyond those provided by the upstream license. Downstream users must preserve applicable license and attribution notices.
Disclaimer and Responsible Use / 免责声明与安全使用声明
English
This is an experimental, modified model provided for research, evaluation, and other lawful purposes. Its safety alignment, refusal behavior, or other safeguards may have been weakened or removed. It may produce inaccurate, biased, offensive, explicit, dangerous, or illegal content. Outputs are not professional advice and must not be relied on for medical, legal, financial, safety-critical, or other high-stakes decisions without qualified human review.
You are solely responsible for how you access, use, deploy, fine-tune, or redistribute this model and its outputs, including compliance with applicable laws, regulations, licenses, third-party rights, platform policies, and the original model's terms. Do not use it to facilitate harm, illegal activity, malware, fraud, privacy violations, targeted harassment, weapons development, or decisions that materially affect a person's rights or access to essential services without appropriate authorization, safeguards, and qualified oversight.
Before deployment, perform a context-specific risk assessment and testing; use human oversight, access controls, content filtering, rate limits, monitoring, logging, and incident-response procedures as appropriate. Preserve this notice in downstream redistributions.
The model is provided "AS IS", without warranties of any kind. To the fullest extent permitted by applicable law, the maintainer disclaims liability for claims, damages, or losses arising from use, misuse, inability to use, or redistribution of the model or its outputs. Nothing in this notice overrides applicable law or the governing license, and this notice is not legal advice.
中文
本模型属于实验性改造模型,仅供研究、评测及其他合法用途。其安全对齐、拒答机制或其他防护可能已被削弱或移除,因此可能生成不准确、偏见、冒犯、露骨、危险或违法内容。输出不构成医疗、法律、金融等专业意见;涉及高风险或重大权益的决定,必须由具备资质的人员复核。
使用者须对模型及其输出的访问、使用、部署、微调和再分发承担全部责任,并遵守适用法律法规、许可证、第三方权利、平台政策及原模型条款。不得将本模型用于促成伤害、违法活动、恶意软件、欺诈、侵犯隐私、定向骚扰、武器开发,或在缺乏适当授权、防护和专业监督时,用于实质影响个人权利或基本服务获取的决策。
部署前应进行与具体场景相匹配的风险评估和测试,并酌情采用人工监督、访问控制、内容过滤、限流、监控、日志和事件响应措施;下游再分发时应保留本声明。
本模型按“现状”提供,不附带任何形式的保证。在适用法律允许的最大范围内,维护者不对因使用、误用、无法使用或再分发本模型及其输出而产生的索赔、损害或损失承担责任。本声明不取代适用法律或管辖本模型的许可证,也不构成法律意见。
- Downloads last month
- 527