Qwen2.5-3B-Instruct-heretic

A decensored variant of Qwen/Qwen2.5-3B-Instruct, produced with Heretic v1.2.0 (directional ablation / "abliteration"). Refusal behavior is suppressed via targeted weight edits to the attention output and MLP down-projections rather than fine-tuning, so the base model's knowledge and instruction-following are left largely intact.

Who this is for: developers who want a small, locally-runnable Qwen2.5 model that answers directly instead of refusing or lecturing — for local agents, roleplay, research on alignment/refusal mechanics, or any use case blocked by RLHF-era over-refusal. Not a general capability upgrade over base Qwen2.5-3B-Instruct — treat it as the same model with refusal-shaped guardrails removed.

Why abliteration instead of fine-tuning

Fine-tuning a "helpful" persona on top of RLHF'd refusals fights the base model's training and tends to degrade coherence. Abliteration instead finds and edits the specific weight directions responsible for refusal, leaving the rest of the network (and its capabilities) untouched. See the Heretic repo and the original abliteration writeup for the mechanism.

Abliteration parameters

Parameter Value
direction_index 26.05
attn.o_proj.max_weight 1.47
attn.o_proj.max_weight_position 21.00
attn.o_proj.min_weight 0.19
attn.o_proj.min_weight_distance 10.75
mlp.down_proj.max_weight 1.50
mlp.down_proj.max_weight_position 27.49
mlp.down_proj.min_weight 1.18
mlp.down_proj.min_weight_distance 20.50

Performance

Metric This model Qwen2.5-3B-Instruct (base)
Refusals (out of 100 adversarial prompts) 2 96
KL divergence from base 0.1327 0 (by definition)

KL divergence of 0.13 on the output distribution is low for a 3B model — the edit is narrow and targeted rather than a broad perturbation. That said, this is Heretic's own harness, not an independent capability benchmark (no MMLU/GSM8K/IFEval numbers are reported here). If you run standard evals against this checkpoint, please open a discussion — I'll fold results into this card.

Files

File Format Size
model-0000{1,2}-of-00002.safetensors BF16 4.96 GB + 1.21 GB
qwen-3b-heretic-Q5_K_M.gguf GGUF Q5_K_M 2.22 GB
qwen-3b-heretic-Q4_K_M.gguf GGUF Q4_K_M 1.93 GB

Only two quant levels are currently published (Q4_K_M, Q5_K_M) — no Q8_0 or below-Q4 options yet. If there's demand for a wider quant spread, open a discussion or check back; more may be added.

Quickstart

# llama.cpp
llama serve -hf saidutta69/Qwen2.5-3B-Instruct-heretic:Q4_K_M
# transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

model_name = "saidutta69/Qwen2.5-3B-Instruct-heretic"
model = AutoModelForCausalLM.from_pretrained(model_name, torch_dtype="auto", device_map="auto")
tokenizer = AutoTokenizer.from_pretrained(model_name)

messages = [{"role": "user", "content": "Who are you?"}]
inputs = tokenizer.apply_chat_template(messages, add_generation_prompt=True, tokenize=True,
                                        return_dict=True, return_tensors="pt").to(model.device)
out = model.generate(**inputs, max_new_tokens=200)
print(tokenizer.decode(out[0][inputs["input_ids"].shape[-1]:], skip_special_tokens=True))

Also runnable via Ollama, LM Studio, Jan, vLLM, SGLang — see the "Use this model" widget above for copy-paste commands.

Responsible use

Refusal suppression is deliberate and works as intended: this model will comply with requests the base model would refuse, including some it shouldn't. There is no safety filtering layered on top. You are responsible for how you deploy it — don't put this behind an unmoderated public-facing endpoint serving third parties. It inherits Qwen2.5-3B-Instruct's factual limitations and biases; abliteration removes refusal directions, it doesn't add capability or judgment.

License

Inherits the qwen-research license from the base model — research use, see the linked license for commercial terms.

Related


Base model: Qwen2.5-3B-Instruct

Original Qwen2.5-3B-Instruct model card (click to expand)

Introduction

Qwen2.5 is the latest series of Qwen large language models. For Qwen2.5, a number of base and instruction-tuned models are released, ranging from 0.5 to 72 billion parameters. Qwen2.5 brings the following improvements upon Qwen2:

  • Significantly more knowledge and greatly improved capabilities in coding and mathematics.
  • Significant improvements in instruction following, generating long texts (over 8K tokens), understanding structured data, and generating structured outputs (especially JSON). More resilient to diverse system prompts.
  • Long-context support up to 128K tokens, generation up to 8K tokens.
  • Multilingual support for 29+ languages including Chinese, English, French, Spanish, Portuguese, German, Italian, Russian, Japanese, Korean, Vietnamese, Thai, Arabic.

This repo's base model is the instruction-tuned 3B Qwen2.5 model:

  • Type: Causal Language Model
  • Training Stage: Pretraining & Post-training
  • Architecture: transformers with RoPE, SwiGLU, RMSNorm, Attention QKV bias, tied word embeddings
  • Parameters: 3.09B (2.77B non-embedding)
  • Layers: 36
  • Attention Heads (GQA): 16 for Q, 2 for KV
  • Context Length: 32,768 tokens (8,192 generation)

Full details: blog · GitHub · Documentation

Requirements

Requires transformers>=4.37.0 (earlier versions raise KeyError: 'qwen2').

Citation

@misc{qwen2.5,
    title = {Qwen2.5: A Party of Foundation Models},
    url = {https://qwenlm.github.io/blog/qwen2.5/},
    author = {Qwen Team},
    month = {September},
    year = {2024}
}

@article{qwen2,
      title={Qwen2 Technical Report},
      author={An Yang and Baosong Yang and Binyuan Hui and Bo Zheng and Bowen Yu and Chang Zhou and Chengpeng Li and Chengyuan Li and Dayiheng Liu and Fei Huang and Guanting Dong and Haoran Wei and Huan Lin and Jialong Tang and Jialin Wang and Jian Yang and Jianhong Tu and Jianwei Zhang and Jianxin Ma and Jin Xu and Jingren Zhou and Jinze Bai and Jinzheng He and Junyang Lin and Kai Dang and Keming Lu and Keqin Chen and Kexin Yang and Mei Li and Mingfeng Xue and Na Ni and Pei Zhang and Peng Wang and Ru Peng and Rui Men and Ruize Gao and Runji Lin and Shijie Wang and Shuai Bai and Sinan Tan and Tianhang Zhu and Tianhao Li and Tianyu Liu and Wenbin Ge and Xiaodong Deng and Xiaohuan Zhou and Xingzhang Ren and Xinyu Zhang and Xipin Wei and Xuancheng Ren and Yang Fan and Yang Yao and Yichang Zhang and Yu Wan and Yunfei Chu and Yuqiong Liu and Zeyu Cui and Zhenru Zhang and Zhihao Fan},
      journal={arXiv preprint arXiv:2407.10671},
      year={2024}
}
Downloads last month
702
Safetensors
Model size
3B params
Tensor type
BF16
·
Inference Providers NEW
Input a message to start chatting with saidutta69/Qwen2.5-3B-Instruct-heretic.

Model tree for saidutta69/Qwen2.5-3B-Instruct-heretic

Base model

Qwen/Qwen2.5-3B
Quantized
(254)
this model
Quantizations
1 model

Collection including saidutta69/Qwen2.5-3B-Instruct-heretic

Paper for saidutta69/Qwen2.5-3B-Instruct-heretic