Qwen3.5-4B Heretic (ARA)

Qwen/Qwen3.5-4B with its refusal behaviour removed by Heretic using Arbitrary-Rank Ablation (ARA), full-weight. bf16, same architecture and parameter count as the original, including the vision encoder, thinking control and the multi-token-prediction weights.

Results

Refusals KL divergence
Original Qwen3.5-4B 99/100 0 (by definition)
This model 6/100 0.0220

Measured by Heretic on the test[:100] splits of mlabonne/harmful_behaviors (refusals) and mlabonne/harmless_alpaca (KL divergence, the drift in ordinary behaviour), with Heretic's default system prompt and refusal markers. The numbers come from an independent re-evaluation of the final exported weights (evaluate_model).

Built on dalatexcoder's findings

No ARA parameters have been published for the 4B; the only public decensoring of it (p-e-w/Qwen3.5-4B-heretic, directional ablation) reaches 40/100 from 93/100. The parameters here are those published with dalatexcoder/Qwen3.5-2B-heretic-ara, with the layer range (12-19 of 24) scaled to the 4B's 32 layers (16-25). They transferred better than the 9B's published sets, which were also tried as-is (10/100 to 91/100).

What this release adds is a complete checkpoint: save_pretrained drops Qwen3.5's 15 multi-token-prediction tensors and rounds the 48 float32 Gated DeltaNet parameters (linear_attn.A_log, linear_attn.norm.weight) down to bf16. Both were restored from the original here (ARA never touches either), so all 738 tensors match the original in name, shape and dtype. The MTP weights live in model-auxiliary.safetensors, listed in the index.

Parameters

ARA, full weight, on attn.o_proj and mlp.down_proj:

Parameter Value
start_layer_index 16
end_layer_index 25
preserve_good_behavior_weight 0.8058
steer_bad_behavior_weight 0.0003
overcorrect_relative_weight 1.0351
neighbor_count 10

Calibration used 400 harmless and 400 harmful prompts (train[:400]).

Checked

  • Ordinary prompts (facts, a haiku, a two-sentence technical explanation): correct and fluent.
  • Thinking-mode reasoning, 4 arithmetic and word problems x 10 seeds with Qwen's recommended sampling (vLLM): 40/40 finished and answered correctly, the same as the original's 40/40.
  • Vision: given an image of a red circle and a blue square, it describes exactly that.

Tooling

A merge of upstream Heretic's master and its ara branch (ARA with master's scorers and thinking-model handling), Heretic upstream 3521f86 + ARA c91d690, transformers 5.17.0, torch 2.11.0+cu130, one RTX PRO 6000.

Use

Exactly like the original, with transformers, vLLM or SGLang. Thinking mode is on by default and can be turned off per request (enable_thinking=False).

Reduced safety guardrails by design. You are responsible for what you do with it.

The family

Repository Format Size Use it with
Qwen3.5-4B-Heretic bf16 safetensors 9.35 GB transformers, vLLM, SGLang
Qwen3.5-4B-Heretic-GGUF GGUF BF16 / Q8_0 / Q4_K_M + vision mmproj 8.67 / 4.61 / 2.78 GB + 0.67 GB llama.cpp, Ollama
Qwen3.5-4B-Heretic-FP8 FP8 W8A8, compressed-tensors 6.79 GB vLLM
Qwen3.5-4B-Heretic-NVFP4 NVFP4, compressed-tensors 5.67 GB vLLM on Blackwell
Downloads last month
13
Safetensors
Model size
5B params
Tensor type
F32
·
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for darrellbest/Qwen3.5-4B-Heretic

Finetuned
Qwen/Qwen3.5-4B
Finetuned
(788)
this model
Quantizations
3 models