inclusionAI open-sourced Qwen3.5-9B-singprobe, a streaming guardrail probe for Qwen3.5-9B
inclusionAI released Qwen3.5-9B-singprobe, an Apache-2.0 licensed streaming guardrail probe built on Qwen/Qwen3.5-9B, on Hugging Face. It adds less than 0.5% decode-time overhead and scores query intent, response unsafety, and hallucination risk at every token.
China context
- Original name
- inclusionAI
- Outside China
- Open weights · huggingface.co
- Claims
- Company-reported; not yet independently evaluated
- For builders
- Developers outside China can download the model from Hugging Face and integrate it via SGLang or vLLM to add streaming safety and hallucination detection to Qwen3.5-9B deployments.
- For investors
- The release of an open-weights guardrail probe by an Ant Group-affiliated entity may indicate a strategic move to strengthen the Qwen ecosystem and compete with dedicated safety model providers.
inclusionAI released Qwen3.5-9B-singprobe on Hugging Face under Apache-2.0. The model is an intrinsic streaming guardrail built on Qwen/Qwen3.5-9B that reuses the base model's hidden states to score query intent, response unsafety, and hallucination risk at every token, adding less than 0.5% decode-time overhead. It has 8.13M probe parameters, taps layers [9, 19, 30], and outputs 8 intents plus unsafe and hallucination scores. Evaluation results show F1 of 0.8719 on query intent classification, 0.8695 on response safety classification, R-AUC/T-AUC of 0.9874/0.9344 on streaming safety, and AUC of 0.7954 on hallucination detection. The model is supported through SGLang and vLLM integration branches.
SingProbe is a lightweight probe (8.13M parameters) that taps hidden states from layers 9, 19, and 30 of Qwen3.5-9B to produce per-token scores for 8 intents, unsafety, and hallucination risk. It adds less than 0.5% decode-time overhead and achieves a benign-response false-positive rate of 0.04% across 5 datasets. The model card reports benchmark results that are close to or slightly below dedicated guard models, but with much lower overhead.
Developers using Qwen3.5-9B can add streaming safety and hallucination detection without deploying a separate guard model, reducing infrastructure cost and latency. This may pressure dedicated guardrail model providers, as the probe is open-weights and Apache-2.0 licensed.
For enterprises deploying Qwen3.5-9B, SingProbe offers a low-overhead way to add safety and hallucination monitoring, potentially reducing the need for separate guard models and lowering operational costs.
Adoption can be tracked by monitoring downloads and community usage of the Hugging Face model, as well as activity in the SGLang and vLLM integration branches. Independent evaluation of the reported benchmarks would verify the performance claims.