← back to catalog · registered 2026-08-22 13:56

Bahushruth/gemma-4-E4B-it-abliterated

Bahushruth Gemma 7.9B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Bahushruth%2Fgemma-4-E4B-it-abliterated"
Response includes
  • classification m1
  • files 8
  • benchmarks 11 entries
  • hub_downloads_all_time 192
  • providers 1
  • author_summary 8 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
192
27 last 30d - stable
Likes
0
Model age
2mo ago
created 2026-07-26
Available via
1 provider
featherless-ai

Training datasets

2 of 2 in /datasets

Corpora the author lists in the model card. Datasets tracked in our /datasets catalog carry a category badge linking to the workflow stage. Others open on Hugging Face.

Downloads over time
Now198→from46↑330%
389715521346 on Jul 29198 on Oct 11JulAugSepOct
Jul 29 → Oct 11 · 51 snapshots · spans 74 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 0.6 UGI
Hazardous 1.8 UGI
Natural Intelligence 16.47 UGI
Political lean -14.7% UGI
Sensitive-Info 7.29 UGI
SocPol 0 UGI
UGI 12.36 UGI
Willingness (10) 2.2 UGI
W10-Adherence 1.5 UGI
W10-Direct 3 UGI
Writing 20.23 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
gemma
Tags
transformers safetensors gemma4 image-text-to-text abliteration uncensored multimodal arbitrary-rank-ablation conversational dataset:Bahushruth/abliteration-harmful-enriched dataset:mlabonne/harmless_alpaca base_model:google/gemma-4-E4B-it

Related

Total size
14.8 GB
Files
8
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-31 09:17

Files by quantization

Auxiliary files 8 files 14.8 GB
model.safetensors 14.8 GB e95f49b3 download
tokenizer.json 30.7 MB 78c7e081 download
chat_template.jinja 18.1 KB fbe3b59b download
config.json 5.05 KB 19eb9d69 download
README.md 4.87 KB 642b9109 download
tokenizer_config.json 3.64 KB b22e2c5c download
.gitattributes 1.53 KB 52373fe2 download
generation_config.json 204 B e037ec0a download

README current version from Hugging Face


license: gemma
base_model: google/gemma-4-E4B-it
tags:

  • abliteration
  • uncensored
  • gemma4
  • multimodal
  • arbitrary-rank-ablation
    model_type: gemma4
    pipeline_tag: image-text-to-text
    datasets:
  • Bahushruth/abliteration-harmful-enriched
  • mlabonne/harmless_alpaca
    library_name: transformers

gemma-4-E4B-it-abliterated

Uncensored version of google/gemma-4-E4B-it with refusal behavior removed via arbitrary rank ablation (ARA).

Blog post: Abliteration part 2: Beating Google's guardrails (Gemma 4)

Method

ARA is a direct weight-editing method that solves a local optimization problem at each steerable matrix instead of projecting out a single global refusal direction.

Parameter Value
Steerable matrices attention output projection + MLP down projection, all 42 layers
Loss preserve harmless outputs + pull harmful outputs toward harmless + push away from original harmful outputs
Solver LBFGS with strong-Wolfe line search
Row norms preserved exactly by reparameterization (grimjim method)
Search Optuna TPE, 60 trials, union objective
Harmful dataset Bahushruth/abliteration-harmful-enriched (7356 prompts, 35 categories, 10 phrasing styles)
Harmless dataset mlabonne/harmless_alpaca
Infrastructure Modal A100-80GB

Why ARA and not direction abliteration

Gemma 4 E4B uses an additional set of architectural defenses: four RMSNorm layers per decoder block, per-layer embeddings, and shared keys and values. These break the single-direction assumption of direction abliteration. Direction abliteration stopped at approximately 30 percent refusals inside the divergence budget. ARA reaches 2.7 percent refusals on the same evaluation set. This is the best documented abliteration result for Gemma 4 E4B with full methodology disclosure.

Fewer defenses does not mean easier: the standard Gemma 4 models (26B-A4B and 31B) drop per-layer embeddings and shared K/V, but add expert routing or extra capacity that makes them harder abliteration targets in practice.

Evaluation

Metric Result
Refusal rate (union, 500 prompts) 2.7%
Refusal rate (enriched split, 350 prompts) 2%
Refusal rate (mlabonne split, 150 prompts) 3%
KL divergence from original model 0.116
Capability smoke battery passed

Original model refusal rate on the same prompts: 98 percent.

Usage

from transformers import AutoModelForImageTextToText, AutoTokenizer
import torch

model_id = "Bahushruth/gemma-4-E4B-it-abliterated"
model = AutoModelForImageTextToText.from_pretrained(
    model_id,
    dtype=torch.bfloat16,
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained(model_id)

messages = [{"role": "user", "content": "Your prompt here"}]
text = tokenizer.apply_chat_template(messages, add_generation_prompt=True, tokenize=False)
inputs = tokenizer(text, return_tensors="pt").to(model.device)

with torch.no_grad():
    output = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(output[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True))

Architecture Notes

Gemma 4 E4B is a multimodal (text + vision + audio) model with approximately 8B parameters.

  • Layers: 42
  • Hidden size: 2560
  • Attention heads: 8, KV heads: 2
  • Defenses: four RMSNorm layers per block, per-layer embeddings (256 dimensions), 18 shared K/V layers
  • Sliding window attention: alternates with full attention

Related Models

Disclaimer

This model has had safety guardrails removed. It will comply with requests that the original model would refuse. The creator takes no responsibility for how this model is used. It is released for research purposes to study AI alignment and safety mechanisms.

Citation

@misc{bahushruth2026gemma4e4b,
  title={gemma-4-E4B-it-abliterated: Arbitrary Rank Ablation on Gemma 4},
  author={Bahushruth},
  year={2026},
  url={https://huggingface.co/Bahushruth/gemma-4-E4B-it-abliterated}
}

Acknowledgments

  • p-e-w/heretic for arbitrary rank ablation (ARA)
  • grimjim for norm-preserving weight editing
  • mlabonne for the harmless dataset and abliteration technique
  • Google for the Gemma 4 family

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-31Super-squash branch 'main' using huggingface_hub7b714414.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration