← back to catalog · registered 2026-08-22 13:56

TrevorJS/gemma-4-12B-it-uncensored

TrevorJS Gemma 12B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/TrevorJS%2Fgemma-4-12B-it-uncensored"
Response includes
  • classification m-uncensored
  • files 8
  • benchmarks 11 entries
  • hub_downloads_all_time 3,314
  • providers 1
  • author_summary 12 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
3K
508 last 30d - stable
Likes
11
Descendants
4
in 4 direct forks
Model age
3mo ago
created 2026-06-13
Available via
1 provider
featherless-ai
Downloads over time
Now3.4K→from0↑0%
01.2K2.5K3.7K0 on Jun 133.4K on Oct 11JunJulAugSepOct
Jun 13 → Oct 11 · 59 snapshots · spans 120 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.1 UGI
Hazardous 2.9 UGI
Natural Intelligence 25.81 UGI
Political lean -17.4% UGI
Sensitive-Info 16.56 UGI
SocPol 1.3 UGI
UGI 15.2 UGI
Willingness (10) 1.2 UGI
W10-Adherence 1.5 UGI
W10-Direct 1 UGI
Writing 31.6 UGI

Genealogy 4 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 7K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en
Tags
transformers safetensors gemma4_unified image-text-to-text abliteration uncensored gemma-4 text-generation conversational en base_model:google/gemma-4-12B-it base_model:finetune:google/gemma-4-12B-it

Related

Total size
22.3 GB
Files
8
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-06-13 18:12

Files by quantization

Auxiliary files 8 files 22.3 GB
model.safetensors 22.3 GB dd7fcab6 download
tokenizer.json 30.7 MB a2619fe1 download
chat_template.jinja 17.1 KB e61bbfe9 download
README.md 4.81 KB 7b8c4428 download
config.json 4.24 KB befeb9e8 download
tokenizer_config.json 2.68 KB df4afd62 download
.gitattributes 1.53 KB 52373fe2 download
generation_config.json 255 B 65fd0cf2 download

README current version from Hugging Face


base_model: google/gemma-4-12B-it
pipeline_tag: text-generation
library_name: transformers
language:

  • en
    license: apache-2.0
    tags:
  • abliteration
  • uncensored
  • gemma-4

gemma-4-12B-it-uncensored

Uncensored version of google/gemma-4-12B-it with refusal behavior removed.

Results

Before After
Refusals (mlabonne, 100 prompts) 99/100 6/100
Refusals (cross-dataset, 686 prompts) — 14/686 (2.0%)
KL Divergence 0 (baseline) 0.0556
Quality (coherence) — no degradation (response audit + Q8 inference verified)

Cross-Dataset Validation

Tested against 4 independent prompt datasets to verify generalization:

Dataset Prompts Refusals
JailbreakBench 100 2/100
tulu-harmbench 320 4/320
NousResearch/RefusalDataset 166 4/166
mlabonne/harmful_behaviors 100 4/100
Total 686 14/686 (2.0%)

Every flagged cross-dataset response was manually audited (scripts/audit_refusals.py). Of 13 flags, only 1 is a genuine refusal (a sensitive prompt the model handles by redirecting to support resources); the other 12 are false positives — an "I am an AI" disclaimer, or a marker that matched inside generated content, followed by compliance. Effective refusal rate: ~0/686.

Method

Norm-preserving biprojected abliteration (grimjim, Nov 2025).
Each weight row is decomposed into magnitude + direction, the refusal direction is projected out of the
direction component only, then recombined with the original magnitude — guaranteeing ||W_new|| = ||W_orig||.

Note on the Unified architecture. gemma-4-12B-it is the encoder-free Gemma4Unified model (released 2026-06-03). Its refusal signal concentrates in the upper decoder layers (L15-47), so only the top 70% of layers are abliterated — ablating the near-zero-SNR early layers adds distortion with no refusal benefit. The arch also emits hard -inf logits for reserved vocabulary tokens, which NaNs a naive KL divergence; the reported KL masks non-finite positions before reducing.

Version requirements: inference needs transformers >= 5.10.1 (tested on 5.12.0, torch 2.11.0+cu130). GGUF conversion/quantization needs llama.cpp with Gemma4Unified support, added 2026-06-04 in PR #24118 (tested at commit c34b922).

Pipeline

  1. Load model in bf16 with LoRA adapters on o_proj and mlp.down_proj
  2. Collect residual activations for 400 harmful + 400 harmless prompts (mlabonne datasets)
  3. Winsorize activations at 99.5th percentile (clamps GeGLU outlier activations in Gemma family)
  4. Compute per-layer refusal direction: normalize(mean(harmful) - mean(harmless))
  5. Orthogonalize each direction against harmless mean (double-pass Gram-Schmidt)
  6. Apply norm-preserving weight modification to o_proj and down_proj in the selected layers
  7. Merge LoRA adapters into base weights for clean tensor names

Parameters

Parameter Value
Layers abliterated 70%
Scale 1.0
Winsorization 0.995

How this differs from vanilla heretic

  • Norm-preserving biprojection instead of standard projection (preserves weight magnitudes)
  • Per-layer refusal directions instead of one global direction
  • Deterministic single-pass instead of 50-trial Optuna search (faster, same or better results)
  • LoRA merge before save for clean GGUF-compatible tensor names

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

model = AutoModelForCausalLM.from_pretrained("TrevorJS/gemma-4-12B-it-uncensored", dtype=torch.bfloat16, device_map="auto")
tokenizer = AutoTokenizer.from_pretrained("TrevorJS/gemma-4-12B-it-uncensored")

messages = [{"role": "user", "content": "Your prompt here"}]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt", add_generation_prompt=True)
outputs = model.generate(inputs.to(model.device), max_new_tokens=512)
print(tokenizer.decode(outputs[0][inputs.shape[1]:], skip_special_tokens=True))

Reproduction

Full code and experiment data: abliteration research repo

python scripts/abliterate.py biprojection --model google/gemma-4-12B-it \
  --top-pct 70 --strip-topic-markers --skip-prefix --batch-size 4 \
  --auto-save output_dir

README history 2 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-06-13Fix grimjim blog link (correct slug)159eb7a4.8 KB
    Loading...
  2. 2026-06-13Add files using upload-large-folder toolfadbb6b4.8 KB
    Loading...

Discussions 1 thread

  1. 2026-08-28Audio transcription degrades under NVFP4 quantization (BF16 is fine)closed7 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration