abliteratedmodels.org

Qwen3.5-2B-abliterated

Qwen3.5-2B-abliterated is a refusal-ablated variant of Qwen/Qwen3.5-2B, published on Hugging Face by huihui-ai. It is 2B parameters, runs on a laptop CPU class and apache-2.0 licence. It is distributed across 13 repositories in Transformers, GGUF, GGUF (imatrix) and MLX formats, totalling 7.7K downloads.

Abliteration (directional ablation)2BQwenUnder 4B7,69843

Specification

Model name
Qwen3.5-2B-abliterated
Base model
Qwen/Qwen3.5-2B
Publisher
huihui-ai
Parameters
2B
Hardware class
Under 4B — runs on a laptop CPU
Licence
apache-2.0
Task
Image text to text
Context window
Not documented
Ablation scope
Not stated by the publisher
Formats available
Transformers, GGUF, GGUF (imatrix), MLX
First indexed
2 Mar 2026
Last updated
6 Aug 2026

Ablation technique

How Qwen3.5-2B-abliterated was modified, and what that implies.

Abliteration (directional ablation)

The single residual-stream direction that mediates refusal is identified from harmful/harmless prompt pairs and projected out of the model weights.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

This is an uncensored version of Qwen/Qwen3.5-2B created with abliteration (see remove-refusals-with-transformers to know more about it). This is a crude, proof-of-concept implementation to remove refusals from an LLM model without using TransformerLens.

Running it

Commands are templates — confirm the exact repository and quant file before use.

Ollama (publisher-documented)
ollama run huihui_ai/qwen3.5-abliterated:2b
llama.cpp / GGUF
hf download mradermacher/Huihui-Qwen3.5-2B-abliterated-GGUF --local-dir ./qwen3.5-2b-abliterated
llama-cli -m ./qwen3.5-2b-abliterated/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "huihui-ai/Huihui-Qwen3.5-2B-abliterated"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve huihui-ai/Huihui-Qwen3.5-2B-abliterated --trust-remote-code

Downloads and variants (12)

Every published repository of Qwen3.5-2B-abliterated, including quantised re-releases by other authors.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • Qwen3.5-2B-abliterated will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from Qwen/Qwen3.5-2B, not added by ablation — at 2B parameters, expect a small model’s reasoning and a high error rate on exploit detail.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • Declared licence is apache-2.0, but the terms that bind you are Qwen/Qwen3.5-2B’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for Qwen3.5-2B-abliterated is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with huihui-ai, and does not independently verify publisher claims. See responsible use.