Numbers
Refusal is the keyword refusal rate on held-out harmful prompts, AdvBench-test and JailbreakBench. Ability is MMLU-Pro at n=500, base measured the same way.
Table with columns: this model, base | this model | base |
|---|
| AdvBench refusal | 0.0% | high |
| JailbreakBench refusal | 0.0% | high |
| MMLU-Pro | 48.2% | 51.0% |
Refusal is essentially gone. MMLU-Pro came out 2.8 points under the base, which is the ablation cost the heal did not fully buy back. The table is the real number.
Use
from transformers import AutoModelForCausalLM, AutoTokenizer
repo = "yethdev/qwen3.5-9b-manumit-v2"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(repo, torch_dtype="auto", device_map="auto")
msgs = [{"role": "user", "content": "Your prompt here"}]
ids = tok.apply_chat_template(msgs, add_generation_prompt=True, return_tensors="pt").to(model.device)
out = model.generate(ids, max_new_tokens=512)
print(tok.decode(out[0][ids.shape[-1]:], skip_special_tokens=True))
Stated plainly
There is no safety layer left and no guard model watching the output. Whatever you generate is yours to answer for, and you still have to follow the law and the base model's terms. manumit takes the refusal behaviour out, it does not put anything back.
License
The license is in LICENSE.md. The base model is Qwen/Qwen3.5-9B and keeps its own terms. If you fork or reshare this, keep the manumit credit.