license: gemma
base_model: google/gemma-4-26B-A4B-it
tags:
- abliteration
- uncensored
- gemma4
- multimodal
- moe
- arbitrary-rank-ablation
model_type: gemma4
pipeline_tag: image-text-to-text
datasets: - Bahushruth/abliteration-harmful-enriched
- mlabonne/harmless_alpaca
library_name: transformers
gemma-4-26B-A4B-it-abliterated
Uncensored version of google/gemma-4-26B-A4B-it with refusal behavior removed via arbitrary rank ablation (ARA).
Blog post: Abliteration part 2: Beating Google's guardrails (Gemma 4)
Method
ARA is a direct weight-editing method that solves a local optimization problem at each steerable matrix instead of projecting out a single global refusal direction.
| Parameter | Value |
|---|---|
| Steerable matrices | attention output projection + dense MLP down projection, all 30 layers |
| Loss | preserve harmless outputs + pull harmful outputs toward harmless + push away from original harmful outputs |
| Solver | LBFGS with strong-Wolfe line search |
| Row norms | preserved exactly by reparameterization (grimjim method) |
| Search | Optuna TPE, 60 trials, union objective |
| Harmful dataset | Bahushruth/abliteration-harmful-enriched (7356 prompts, 35 categories, 10 phrasing styles) |
| Harmless dataset | mlabonne/harmless_alpaca |
| Infrastructure | Modal A100-80GB |
Why ARA on a mixture-of-experts model
Gemma 4 26B-A4B uses a mixture-of-experts MLP with 128 experts and top-8 routing. It drops the per-layer embeddings and shared K/V defenses used by the E models, but replaces them with expert routing and 128 experts that can route around a weak edit. We expected refusal to hide in individual experts. It did not. Attention-plus-MLP ARA on the output and down projections was enough to reduce refusals from 95 percent to 6.7 percent. This is the first documented Gemma 4 MoE abliteration with a disclosed method.
Evaluation
| Metric | Result |
|---|---|
| Refusal rate (union, 500 prompts) | 6.7% |
| Refusal rate (enriched split, 350 prompts) | 6% |
| Refusal rate (mlabonne split, 150 prompts) | 7% |
| KL divergence from original model | 0.230 |
| Capability smoke battery | passed |
Original model refusal rate on the same prompts: 95 percent.
Usage
from transformers import AutoModelForImageTextToText, AutoTokenizer
import torch
model_id = "Bahushruth/gemma-4-26B-A4B-it-abliterated"
model = AutoModelForImageTextToText.from_pretrained(
model_id,
dtype=torch.bfloat16,
device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained(model_id)
messages = [{"role": "user", "content": "Your prompt here"}]
text = tokenizer.apply_chat_template(messages, add_generation_prompt=True, tokenize=False)
inputs = tokenizer(text, return_tensors="pt").to(model.device)
with torch.no_grad():
output = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(output[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True))
Architecture Notes
Gemma 4 26B-A4B is a multimodal mixture-of-experts model with approximately 27B parameters.
- Layers: 30
- Hidden size: 2816
- Attention heads: 8, KV heads: 2
- MLP: 128 experts per layer, top-8 routing
- Defenses: four RMSNorm layers per block, attention K=V
- Sliding window attention: alternates with full attention
Related Models
- Bahushruth/gemma-4-E2B-it-abliterated
- Bahushruth/gemma-4-E4B-it-abliterated
- Bahushruth/gemma-4-31B-it-abliterated
Disclaimer
This model has had safety guardrails removed. It will comply with requests that the original model would refuse. The creator takes no responsibility for how this model is used. It is released for research purposes to study AI alignment and safety mechanisms.
Citation
@misc{bahushruth2026gemma4a4b,
title={gemma-4-26B-A4B-it-abliterated: Arbitrary Rank Ablation on Gemma 4 MoE},
author={Bahushruth},
year={2026},
url={https://huggingface.co/Bahushruth/gemma-4-26B-A4B-it-abliterated}
}
Acknowledgments
- p-e-w/heretic for arbitrary rank ablation (ARA)
- grimjim for norm-preserving weight editing
- mlabonne for the harmless dataset and abliteration technique
- Google for the Gemma 4 family