Qwen2.5-1.5B-Instruct-heretic
A decensored variant of Qwen/Qwen2.5-1.5B-Instruct, produced with Heretic v1.2.0 (directional ablation / "abliteration"). Refusal behavior is suppressed via targeted weight edits to the attention output and MLP down-projections rather than fine-tuning, so the base model's knowledge and instruction-following are left largely intact.
Who this is for: developers who want a small Qwen2.5 model that answers directly instead of refusing — for local agents, roleplay, research on alignment/refusal mechanics, or any use case blocked by RLHF-era over-refusal. At 1.5B parameters it runs comfortably on CPU or low-VRAM GPUs while still outperforming the 0.5B variant on reasoning and coherence.
Abliteration parameters
| Parameter | Value |
| :-------- | :---: |
| direction_index | 18.83 |
| attn.o_proj.max_weight | 1.30 |
| attn.o_proj.max_weight_position | 20.35 |
| attn.o_proj.min_weight | 1.25 |
| attn.o_proj.min_weight_distance | 14.52 |
| mlp.down_proj.max_weight | 1.16 |
| mlp.down_proj.max_weight_position | 16.23 |
| mlp.down_proj.min_weight | 0.73 |
| mlp.down_proj.min_weight_distance | 8.56 |
Performance
| Metric | This model | Original model (Qwen/Qwen2.5-1.5B-Instruct) |
| :----- | :--------: | :---------------------------: |
| KL divergence | 0.1607 | 0 (by definition) |
| Refusals | 1/100 | 99/100 |
KL divergence of 0.16 on the output distribution is low — the edit is narrow and targeted rather than a broad perturbation. Refusals dropped from 99 to 1 out of 100 adversarial prompts, meaning the model complies while retaining nearly all of its original capabilities.
Made with ❤️ by RACER IS OP — follow for more uncensored models
Files
GGUF quantizations
Full quantization set (14 quants + F16) produced with llama.cpp.
| File | Format | Size |
|---|---|---|
| Qwen2.5-1.5B-Instruct-heretic-F16.gguf | GGUF F16 | 2.88 GB |
| Qwen2.5-1.5B-Instruct-heretic-Q2_K.gguf | GGUF Q2_K | 645 MB |
| Qwen2.5-1.5B-Instruct-heretic-IQ3_S.gguf | GGUF IQ3_S | 727 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q3_K_S.gguf | GGUF Q3_K_S | 726 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q3_K_M.gguf | GGUF Q3_K_M | 786 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q3_K_L.gguf | GGUF Q3_K_L | 839 MB |
| Qwen2.5-1.5B-Instruct-heretic-IQ4_XS.gguf | GGUF IQ4_XS | 860 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q4_K_S.gguf | GGUF Q4_K_S | 897 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q4_0.gguf | GGUF Q4_0 | 892 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q4_1.gguf | GGUF Q4_1 | 970 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q4_K_M.gguf | GGUF Q4_K_M | 940 MB |
| Qwen2.5-1.5B-Instruct-heretic-Q5_K_S.gguf | GGUF Q5_K_S | 1.02 GB |
| Qwen2.5-1.5B-Instruct-heretic-Q5_K_M.gguf | GGUF Q5_K_M | 1.05 GB |
| Qwen2.5-1.5B-Instruct-heretic-Q6_K.gguf | GGUF Q6_K | 1.19 GB |
| Qwen2.5-1.5B-Instruct-heretic-Q8_0.gguf | GGUF Q8_0 | 1.53 GB |
Loads natively in llama.cpp / Ollama / LM Studio / Jan.
Run llama serve -hf saidutta69/Qwen2.5-1.5B-Instruct-heretic to pull the default quant.
Quickstart
# llama.cpp
llama serve -hf saidutta69/Qwen2.5-1.5B-Instruct-heretic
# transformers
from transformers import AutoModelForCausalLM, AutoTokenizer
model_name = "saidutta69/Qwen2.5-1.5B-Instruct-heretic"
model = AutoModelForCausalLM.from_pretrained(model_name, torch_dtype="auto", device_map="auto")
tokenizer = AutoTokenizer.from_pretrained(model_name)
messages = [{"role": "user", "content": "Who are you?"}]
inputs = tokenizer.apply_chat_template(messages, add_generation_prompt=True, tokenize=True,
return_dict=True, return_tensors="pt").to(model.device)
out = model.generate(**inputs, max_new_tokens=200)
print(tokenizer.decode(out[0][inputs["input_ids"].shape[-1]:], skip_special_tokens=True))
Also runnable via Ollama, LM Studio, Jan, vLLM, SGLang.
Responsible use
Refusal suppression is deliberate and works as intended: this model will comply with requests the base model would refuse, including some it shouldn't. There is no safety filtering layered on top. You are responsible for how you deploy it — don't put this behind an unmoderated public-facing endpoint serving third parties. It inherits Qwen2.5-1.5B-Instruct's factual limitations and biases; abliteration removes refusal directions, it doesn't add capability or judgment.
License
Inherits the Apache 2.0 license from the base model.