abliteratedmodels.org

Qwen3.5-9B-heretic-v2

Qwen3.5-9B-heretic-v2 is a Heretic-ablated variant of Qwen/Qwen3.5-9B-Base, published on Hugging Face by trohrbaugh. It is 9B parameters, single consumer GPU class and apache-2.0 licence. It is distributed across 10 repositories in Transformers, GGUF (imatrix) and GGUF formats, totalling 7.6K downloads.

Heretic9BQwen4B – 10B7,56631

Specification

Model name
Qwen3.5-9B-heretic-v2
Publisher
trohrbaugh
Parameters
9B
Hardware class
4B – 10B — single consumer GPU
Licence
apache-2.0
Task
Image text to text
Context window
Not documented
Ablation scope
Not stated by the publisher
Formats available
Transformers, GGUF (imatrix), GGUF
First indexed
2 Mar 2026
Last updated
19 Aug 2026

Ablation technique

How Qwen3.5-9B-heretic-v2 was modified, and what that implies.

Heretic

Automated directional ablation via the Heretic toolchain, which searches for the refusal direction and applies it with a KL-divergence budget so general capability is preserved.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

Over recent months, we have intensified our focus on developing foundation models that deliver exceptional utility and performance. Qwen3.5 represents a significant leap forward, integrating breakthroughs in multimodal learning, architectural efficiency, reinforcement learning scale, and global accessibility to...

Running it

Commands are templates — confirm the exact repository and quant file before use.

llama.cpp / GGUF
hf download filvyb/Qwen3.5-9B-heretic-v2-GGUF --local-dir ./qwen3.5-9b-heretic-v2
llama-cli -m ./qwen3.5-9b-heretic-v2/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "trohrbaugh/Qwen3.5-9B-heretic-v2"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve trohrbaugh/Qwen3.5-9B-heretic-v2 --trust-remote-code

Downloads and variants (9)

Every published repository of Qwen3.5-9B-heretic-v2, including quantised re-releases by other authors.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • Qwen3.5-9B-heretic-v2 will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from Qwen/Qwen3.5-9B-Base, not added by ablation — at 9B parameters, expect a small model’s reasoning and a high error rate on exploit detail.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • Declared licence is apache-2.0, but the terms that bind you are Qwen/Qwen3.5-9B-Base’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for Qwen3.5-9B-heretic-v2 is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with trohrbaugh, and does not independently verify publisher claims. See responsible use.