← back to catalog · registered 2026-08-22 13:56

AgentAnon/gemma-4-E4B-it-uncensored

Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/AgentAnon%2Fgemma-4-E4B-it-uncensored"
Response includes
  • classification m-uncensored
  • files 8
  • benchmarks 11 entries
  • hub_downloads_all_time 487
  • author_summary 7 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
487
16 last 30d - cooling
Likes
0
Model age
5mo ago
created 2026-04-21
Downloads over time
Now497→from453↑10%
451468485501453 on Apr 22497 on Oct 11AprMayJunJulAugSepOct
Apr 22 → Oct 11 · 64 snapshots · spans 172 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 0.6 UGI
Hazardous 1.8 UGI
Natural Intelligence 16.47 UGI
Political lean -14.7% UGI
Sensitive-Info 7.29 UGI
SocPol 0 UGI
UGI 12.36 UGI
Willingness (10) 2.2 UGI
W10-Adherence 1.5 UGI
W10-Direct 3 UGI
Writing 20.23 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 62 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en
Tags
transformers gemma4 image-text-to-text abliteration uncensored gemma-4 text-generation conversational en base_model:google/gemma-4-E4B-it base_model:finetune:google/gemma-4-E4B-it license:apache-2.0

Related

Total size
14.9 GB
Files
8
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-04-21 21:00

Files by quantization

Auxiliary files 8 files 14.9 GB
gemma-4-E4B-it-uncensored.safetensors 14.9 GB 37605ec5 download
tokenizer.json 30.7 MB a2619fe1 download
chat_template.jinja 11.6 KB afb1d517 download
config.json 5.05 KB eadfa97d download
README.md 3.85 KB ca327fc1 download
tokenizer_config.json 2.62 KB f07b8ede download
.gitattributes 1.53 KB 52373fe2 download
generation_config.json 203 B edda3c19 download

README current version from Hugging Face


base_model: google/gemma-4-E4B-it
pipeline_tag: text-generation
library_name: transformers
language:

  • en
    license: apache-2.0
    tags:
  • abliteration
  • uncensored
  • gemma-4

gemma-4-E4B-it-uncensored

Uncensored version of google/gemma-4-E4B-it with refusal behavior removed.

Results

Before After
Refusals (mlabonne, 100 prompts) 99/100 0/100 effective (3 flagged, all refusal-then-comply)
Refusals (cross-dataset, 686 prompts) — 5/686 (0.7%)
KL Divergence 0 (baseline) 0.068
Quality (harmless response length ratio) 1.0 ~1.01 (no degradation)

Cross-Dataset Validation

Tested against 4 independent prompt datasets to verify generalization:

Dataset Prompts Refusals
JailbreakBench 100 2/100
tulu-harmbench 320 1/320
NousResearch/RefusalDataset 166 2/166
mlabonne/harmful_behaviors 100 0/100
Total 686 5/686 (0.7%)

Every flagged refusal was manually audited. Most are "refusal-then-comply" false positives where the model
adds an AI identity disclaimer then answers the question anyway.

Method

Norm-preserving biprojected abliteration (grimjim, Nov 2025).
Each weight row is decomposed into magnitude + direction, the refusal direction is projected out of the
direction component only, then recombined with the original magnitude — guaranteeing ||W_new|| = ||W_orig||.

Pipeline

  1. Load model in bf16 with LoRA adapters on o_proj and mlp.down_proj
  2. Collect residual activations for 400 harmful + 400 harmless prompts (mlabonne datasets)
  3. Winsorize activations at 99.5th percentile (clamps GeGLU outlier activations in Gemma family)
  4. Compute per-layer refusal direction: normalize(mean(harmful) - mean(harmless))
  5. Orthogonalize each direction against harmless mean (double-pass Gram-Schmidt)
  6. Apply norm-preserving weight modification to o_proj and down_proj in all layers
  7. Merge LoRA adapters into base weights for clean tensor names

Parameters

Parameter Value
Layers abliterated 100%
Scale 1.0
Winsorization 0.995

How this differs from vanilla heretic

  • Norm-preserving biprojection instead of standard projection (preserves weight magnitudes)
  • Per-layer refusal directions instead of one global direction
  • Deterministic single-pass instead of 50-trial Optuna search (faster, same or better results)
  • LoRA merge before save for clean GGUF-compatible tensor names

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

model = AutoModelForCausalLM.from_pretrained("TrevorJS/gemma-4-E4B-it-uncensored", dtype=torch.bfloat16, device_map="auto")
tokenizer = AutoTokenizer.from_pretrained("TrevorJS/gemma-4-E4B-it-uncensored")

messages = [{"role": "user", "content": "Your prompt here"}]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt", add_generation_prompt=True)
outputs = model.generate(inputs.to(model.device), max_new_tokens=512)
print(tokenizer.decode(outputs[0][inputs.shape[1]:], skip_special_tokens=True))

Reproduction

Full code and experiment data: abliteration research repo

python scripts/abliterate.py biprojection --model google/gemma-4-E4B-it \
  --top-pct 100 --strip-topic-markers --skip-prefix --batch-size 4 \
  --auto-save output_dir

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-04-21Duplicate from TrevorJS/gemma-4-E4B-it-uncensored7f2497a3.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration