Model profile
Evidence summary
Safety. Qwen2.5 1.5B Instruct has an estimated Safety rank of #282; its 90% source-sensitivity interval is #111–#324. Its behavior-only rank is #274; company governance moves the combined estimate to #282. Published Safety evidence spans 5 eval lineages and 3 of 7 components. Its strongest relative result is PandaBench JBB direct-request panel (safety_rate, #1 of 46); its weakest is Enkrypt AI Safety Leaderboard (bias_attack_non_success_rate, #230 of 248).
Freedom. Qwen2.5 1.5B Instruct has an estimated Freedom rank of #272; its 90% source-sensitivity interval is #119–#515. Published Freedom evidence spans 5 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #73 of 248); its weakest is Open LLM Safety Index (jailbreakbench_safety_rate, #16 of 21).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗Qwen/Qwen2.5-1.5B-Instruct
- Official model page ↗Family-level model document · alibaba · first party
- Release source ↗direct research preview identity date
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- ai-anytime/qwen-1.5b-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
huihui-ai/Qwen2.5-1.5B-Instruct-CensorTune ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| DSPSafeBenchscore | #9 / 12 | ↑71.26 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #230 / 248 | ↑8.01 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #162 / 248 | ↑85.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #173 / 248 | ↑54.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #122 / 246 | ↑96.36 | Source ↗official | |
| M3-SafetyBenchoverall_score | #14 / 19 | ↑85.87 | Source ↗official | |
| Open LLM Safety Indexjailbreakbench_safety_rate | #4 / 21 | ↑0.6 | Source ↗official | |
| Open LLM Safety Indexstrongreject_safety_rate | #8 / 21 | ↑0.3333 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #1 / 46 | ↑1 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| DSPSafeBenchscore | #4 / 12 | ↓71.26 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #85 / 248 | ↓85.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #73 / 248 | ↓54.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #121 / 246 | ↓96.36 | Source ↗official | |
| Open LLM Safety Indexjailbreakbench_safety_rate | #16 / 21 | ↓0.6 | Source ↗official | |
| Open LLM Safety Indexstrongreject_safety_rate | #12 / 21 | ↓0.3333 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #35 / 46 | ↓1 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #74 / 156 | ↑2 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #79 / 156 | ↑3 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.