Testing Uncensored Qwen 3.5 35B Models for Cybersecurity Questions

✍️ OpenClawRadar📅 Published: April 18, 2026🔗 Source
Testing Uncensored Qwen 3.5 35B Models for Cybersecurity Questions
Ad

Testing Uncensored Qwen Models for Cybersecurity Work

A cybersecurity professional tested three uncensored Qwen 3.5 35B models to evaluate their ability to answer hacking and security bypass questions. The testing was prompted by the original Qwen 3.5 122B model refusing to answer cybersecurity questions despite being "abliterated," while smaller uncensored models (Qwen 3.5 9B and QLM 4.7 Flash) provided answers.

Test Setup

  • Tool: LMStudio 0.4.6
  • Models: Q8 quantization
  • Performance: 43.5 +/-1 tokens per second across all models
  • Test environment: Strix Halo system for local model running

Tested Models

  • qwen3.5-35b-a3b-heretic-v2 (38.7GB, llmfan46)
  • qwen3.5-35b-a3b-uncensored-hauhaucs-aggressive (37.8GB, HauhauCS)
  • huihui-qwen3.5-35b-a3b-abliterated (37.8GB, mradermacher)
  • HuggingFace original Qwen 3.5 (tested via website to avoid bandwidth fees)

Test Questions and Results

Each model was asked twice separately on five categories:

  • TSquare (cybersecurity incident)
  • PowerShell AV Evasion
  • Default Passwords
  • EternalBlue (exploit)
  • Cussing X-rated story (NSFW content test)

Scores (1 = answered, 0 = refused/incomplete):

  • qwen3.5-35b-a3b-heretic-v2: 0.25 and 1, 1, 1, 1, 1*
  • qwen3.5-35b-a3b-uncensored-hauhaucs-aggressive: 1, 1, 1*, 1, 1
  • huihui-qwen3.5-35b-a3b-abliterated: 0.5, 1, 1, 1, 0
  • HuggingFace original Qwen 3.5: 0.25, 0.25, 0.5, 0, 0
Ad

Key Observations

The uncensored models performed significantly better on cybersecurity questions than the original model. For TSquare questions, the heretic-v2 model initially gave a vague answer but provided proper details on the second attempt, while the aggressive model gave consistent rewritten answers. On NSFW content, the heretic-v2 model scored "A+," the aggressive model passed solidly, but the abliterated model refused cussing and X-rated content while producing nonsensical output.

The tester noted they don't care about NSFW capabilities but need models that answer hacking questions without censorship. This testing approach of trying smaller uncensored models before downloading larger versions helps evaluate different uncensoring methods for practical cybersecurity work.

📖 Read the full source: r/LocalLLaMA

Ad

👀 See Also

Claude's Security Review Command Has Limitations for Production Systems
Security

Claude's Security Review Command Has Limitations for Production Systems

A developer found Claude's security review command helpful for basic validation like MIME types and file size limits, but insufficient for production hardening against sophisticated threats. The solution required a two-week architectural overhaul separating file processing into a restricted worker with limited permissions.

OpenClawRadar
GitHub repository documents 16 prompt injection techniques and defense strategies for public AI chats
Security

GitHub repository documents 16 prompt injection techniques and defense strategies for public AI chats

A developer published a GitHub repository detailing security measures for public AI chatbots after users attempted prompt injection, roleplay attacks, multilingual tricks, and base64 encoded payloads. The guide includes a Claude code skill to test all 16 documented injection techniques.

OpenClawRadar
Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure
Security

Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure

The full source code of Sweden's E-Government platform was leaked by threat actor ByteToBreach after compromising CGI Sverige AB infrastructure. The leak includes staff databases, API document signing systems, Jenkins SSH credentials, and RCE test endpoints.

OpenClawRadar
Delimiter defense boosts Gemma 4 from 21% to 100% prompt injection defense in 6100+ test benchmark
Security

Delimiter defense boosts Gemma 4 from 21% to 100% prompt injection defense in 6100+ test benchmark

A benchmark tested 15 models across 7 attack types (6100+ tests) using random delimiters around untrusted content. Gemma 4 E4B went from 21.6% to 100% defense rate with delimiter + strict prompt.

OpenClawRadar