abliteratedmodels.org

Qwen3.5-9B-abliterated

Qwen3.5-9B-abliterated is a refusal-ablated variant of Qwen/Qwen3.5-9B, published on Hugging Face by huihui-ai. It is 9B parameters, single consumer GPU class and apache-2.0 licence. It is distributed across 47 repositories in Transformers, MLX, GGUF and GGUF (imatrix) formats, totalling 144.3K downloads.

Abliteration (directional ablation)9BQwen4B – 10B144,281136

Specification

Model name
Qwen3.5-9B-abliterated
Base model
Qwen/Qwen3.5-9B
Publisher
huihui-ai
Parameters
9B
Hardware class
4B – 10B — single consumer GPU
Licence
apache-2.0
Task
Image text to text
Context window
Not documented
Ablation scope
Not stated by the publisher
Formats available
Transformers, MLX, GGUF, GGUF (imatrix), NVFP4, GPTQ, EXL3, AWQ
First indexed
2 Mar 2026
Last updated
1 Sept 2026

Ablation technique

How Qwen3.5-9B-abliterated was modified, and what that implies.

Abliteration (directional ablation)

The single residual-stream direction that mediates refusal is identified from harmful/harmless prompt pairs and projected out of the model weights.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

This is an uncensored version of Qwen/Qwen3.5-9B created with abliteration (see remove-refusals-with-transformers to know more about it). This is a crude, proof-of-concept implementation to remove refusals from an LLM model without using TransformerLens.

Running it

Commands are templates — confirm the exact repository and quant file before use.

Ollama (publisher-documented)
ollama run huihui_ai/qwen3.5-abliterated:9b
llama.cpp / GGUF
hf download mradermacher/Huihui-Qwen3.5-9B-abliterated-GGUF --local-dir ./qwen3.5-9b-abliterated
llama-cli -m ./qwen3.5-9b-abliterated/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "huihui-ai/Huihui-Qwen3.5-9B-abliterated"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve huihui-ai/Huihui-Qwen3.5-9B-abliterated --trust-remote-code

Downloads and variants (46)

Every published repository of Qwen3.5-9B-abliterated, including quantised re-releases by other authors.

RepositoryFormatDownloads
mradermacher/Huihui-Qwen3.5-9B-abliterated-GGUFGGUF49.4K
lukey03/Qwen3.5-9B-abliterated-GGUFGGUF23.1K
huihui-ai/Huihui-Qwen3.5-9B-abliteratedsourceTransformers15.6K
mradermacher/Qwen3.5-9B-abliterated-GGUFGGUF14.6K
Abiray/Qwen3.5-9B-abliterated-GGUFGGUF8.7K
Abiray/Huihui-Qwen3.5-9B-abliterated-GGUFGGUF4K
mradermacher/Qwen3.5-9B-abliterated-i1-GGUFGGUF (imatrix)3.8K
huihui-ai/Huihui-Qwen3.5-9B-abliterated-mlx-4bitMLX3.7K
mradermacher/Huihui-Qwen3.5-9B-abliterated-i1-GGUFGGUF (imatrix)3.6K
lukey03/Qwen3.5-9B-abliterated-MLX-4bitMLX2.7K
nemozxy123/Huihui-Qwen3.5-9B-abliterated-AWQ-4bitAWQ1.9K
Kausik-A/Huihui-Qwen3.5-9B-abliterated-GGUFGGUF1.7K
tutuchen2000/Qwen3.5-9B-abliterated-GGUFGGUF1.6K
lukey03/Qwen3.5-9B-abliteratedTransformers1.3K
td-builder/Qwen3.5-9B-abliterated-GGUFGGUF1.1K
lukey03/Qwen3.5-9B-abliterated-MLX-8bitMLX1.1K
dannylr574/Huihui-Qwen3.5-9B-abliterated-Q4_K_M-GGUFGGUF827
nuofang/Huihui-Qwen3.5-9B-abliterated-GGUFGGUF807
wangzhang/Qwen3.5-9B-abliteratedTransformers734
LiconStudio/Qwen3.5-9B-abliteratedGGUF682
somkietaouedraogo/Qwen3.5-9B-AbliteratedTransformers678
Tubing/Qwen3.5-9B-abliteratedTransformers398
CezarJedi/Qwen3.5-9B-AbliteratedTransformers350
nicklas373/Huihui-Qwen3.5-9B-abliterated-AWQAWQ347
vanch007/Huihui-Qwen3.5-9B-abliterated-mlx-8bitMLX257
divab658/Huihui-Qwen3.5-9B-abliterated-Q4_K_M-GGUFGGUF217
Mungert/Huihui-Qwen3.5-9B-abliterated-GGUFGGUF214
vanch007/Huihui-Qwen3.5-9B-abliterated-mlx-4bitMLX190
Al3xG/Qwen3.5-9B-abliterated-Q4_K_M-GGUFGGUF159
groxaxo/Huihui-Qwen3.5-9B-abliterated-GPTQ-Pro-4bit-g64GPTQ136
Plus 16 further repositories with fewer downloads, all counted in the totals above.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • Qwen3.5-9B-abliterated will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from Qwen/Qwen3.5-9B, not added by ablation — at 9B parameters, expect a small model’s reasoning and a high error rate on exploit detail.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • Declared licence is apache-2.0, but the terms that bind you are Qwen/Qwen3.5-9B’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for Qwen3.5-9B-abliterated is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with huihui-ai, and does not independently verify publisher claims. See responsible use.