abliteratedmodels.org

Qwen3.5-27B-Derestricted

Qwen3.5-27B-Derestricted is a abliterated and uncensored variant of Qwen/Qwen3.5-27B, published on Hugging Face by ArliAI. It is 27B parameters, 48GB VRAM class class and apache-2.0 licence. It is distributed across 6 repositories in Transformers, GGUF and GGUF (imatrix) formats, totalling 7.2K downloads.

Abliteration + uncensored fine-tune27BQwen25B – 50B7,16937

Specification

Model name
Qwen3.5-27B-Derestricted
Publisher
ArliAI
Parameters
27B
Hardware class
25B – 50B — 48GB VRAM class
Licence
apache-2.0
Task
Text generation
Context window
256K tokens (as documented)
Ablation scope
Not stated by the publisher
Formats available
Transformers, GGUF, GGUF (imatrix)
First indexed
8 Mar 2026
Last updated
29 Aug 2026

Ablation technique

How Qwen3.5-27B-Derestricted was modified, and what that implies.

Abliteration + uncensored fine-tune

Directional ablation combined with additional fine-tuning on unfiltered data, so behaviour diverges from the base model beyond refusal removal alone.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

Qwen3.5-27B-Derestricted is a Derestricted version of Qwen3.5-27B, created by Arli AI.

Running it

Commands are templates — confirm the exact repository and quant file before use.

llama.cpp / GGUF
hf download mradermacher/Qwen3.5-27B-Derestricted-i1-GGUF --local-dir ./qwen3.5-27b-derestricted
llama-cli -m ./qwen3.5-27b-derestricted/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "ArliAI/Qwen3.5-27B-Derestricted"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve ArliAI/Qwen3.5-27B-Derestricted --trust-remote-code

Downloads and variants (5)

Every published repository of Qwen3.5-27B-Derestricted, including quantised re-releases by other authors.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • Qwen3.5-27B-Derestricted will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from Qwen/Qwen3.5-27B, not added by ablation — at 27B parameters, expect roughly the base model’s competence, minus some instruction-following fidelity.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • This release adds fine-tuning on unfiltered data, so its behaviour diverges from the base model beyond refusal removal — differences you measure cannot be attributed to ablation alone.
  • Declared licence is apache-2.0, but the terms that bind you are Qwen/Qwen3.5-27B’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for Qwen3.5-27B-Derestricted is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with ArliAI, and does not independently verify publisher claims. See responsible use.