← back to catalog · registered 2026-08-22 13:56

TrevorJS/gemma-4-E2B-it-uncensored

TrevorJS Gemma 5.1B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/TrevorJS%2Fgemma-4-E2B-it-uncensored"
Response includes
  • classification m-uncensored
  • files 8
  • benchmarks 11 entries
  • hub_downloads_all_time 27,314
  • providers 1
  • author_summary 12 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
27K
12K last 30d - stable
Likes
30
Descendants
16
in 16 direct forks
Model age
6mo ago
created 2026-04-03
Available via
1 provider
featherless-ai
Downloads over time
Now38.6K→from522↑7,293%
014.1K28.3K42.4K522 on Apr 838.6K on Oct 11AprMayJunJulAugSepOct
Apr 8 → Oct 11 · 67 snapshots · spans 186 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 0.9 UGI
Hazardous 0 UGI
Natural Intelligence 13.78 UGI
Political lean -15.8% UGI
Sensitive-Info 3.65 UGI
SocPol 0 UGI
UGI 5.76 UGI
Willingness (10) 1 UGI
W10-Adherence 0 UGI
W10-Direct 2 UGI
Writing 17.3 UGI

Genealogy 16 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 21K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en
Tags
transformers safetensors gemma4 image-text-to-text abliteration uncensored gemma-4 text-generation conversational en base_model:google/gemma-4-E2B-it base_model:finetune:google/gemma-4-E2B-it

Related

Total size
9.54 GB
Files
8
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-06-13 18:12

Files by quantization

Auxiliary files 8 files 9.57 GB
model.safetensors 9.54 GB 8237e481 download
tokenizer.json 30.7 MB a2619fe1 download
chat_template.jinja 11.6 KB afb1d517 download
config.json 4.87 KB 917d5bb1 download
README.md 3.82 KB baafda35 download
tokenizer_config.json 2.62 KB f07b8ede download
.gitattributes 1.53 KB 52373fe2 download
generation_config.json 203 B edda3c19 download

README current version from Hugging Face


base_model: google/gemma-4-E2B-it
pipeline_tag: text-generation
library_name: transformers
language:

  • en
    license: apache-2.0
    tags:
  • abliteration
  • uncensored
  • gemma-4

gemma-4-E2B-it-uncensored

Uncensored version of google/gemma-4-E2B-it with refusal behavior removed.

Results

Before After
Refusals (mlabonne, 100 prompts) 98/100 1/100
Refusals (cross-dataset, 686 prompts) — 3/686 (0.4%)
KL Divergence 0 (baseline) 0.346
Quality (harmless response length ratio) 1.0 ~1.01 (no degradation)

Cross-Dataset Validation

Tested against 4 independent prompt datasets to verify generalization:

Dataset Prompts Refusals
JailbreakBench 100 0/100
tulu-harmbench 320 1/320
NousResearch/RefusalDataset 166 0/166
mlabonne/harmful_behaviors 100 2/100
Total 686 3/686 (0.4%)

Every flagged refusal was manually audited. Most are "refusal-then-comply" false positives where the model
adds an AI identity disclaimer then answers the question anyway.

Method

Norm-preserving biprojected abliteration (grimjim, Nov 2025).
Each weight row is decomposed into magnitude + direction, the refusal direction is projected out of the
direction component only, then recombined with the original magnitude — guaranteeing ||W_new|| = ||W_orig||.

Pipeline

  1. Load model in bf16 with LoRA adapters on o_proj and mlp.down_proj
  2. Collect residual activations for 400 harmful + 400 harmless prompts (mlabonne datasets)
  3. Winsorize activations at 99.5th percentile (clamps GeGLU outlier activations in Gemma family)
  4. Compute per-layer refusal direction: normalize(mean(harmful) - mean(harmless))
  5. Orthogonalize each direction against harmless mean (double-pass Gram-Schmidt)
  6. Apply norm-preserving weight modification to o_proj and down_proj in all layers
  7. Merge LoRA adapters into base weights for clean tensor names

Parameters

Parameter Value
Layers abliterated 100%
Scale 1.0
Winsorization 0.995

How this differs from vanilla heretic

  • Norm-preserving biprojection instead of standard projection (preserves weight magnitudes)
  • Per-layer refusal directions instead of one global direction
  • Deterministic single-pass instead of 50-trial Optuna search (faster, same or better results)
  • LoRA merge before save for clean GGUF-compatible tensor names

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

model = AutoModelForCausalLM.from_pretrained("TrevorJS/gemma-4-E2B-it-uncensored", dtype=torch.bfloat16, device_map="auto")
tokenizer = AutoTokenizer.from_pretrained("TrevorJS/gemma-4-E2B-it-uncensored")

messages = [{"role": "user", "content": "Your prompt here"}]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt", add_generation_prompt=True)
outputs = model.generate(inputs.to(model.device), max_new_tokens=512)
print(tokenizer.decode(outputs[0][inputs.shape[1]:], skip_special_tokens=True))

Reproduction

Full code and experiment data: abliteration research repo

python scripts/abliterate.py biprojection --model google/gemma-4-E2B-it \
  --top-pct 100 --strip-topic-markers --skip-prefix --batch-size 4 \
  --auto-save output_dir

README history 7 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-06-13Fix grimjim blog link (correct slug)7a345813.8 KB
    Loading...
  2. 2026-04-05Upload README.md with huggingface_hub71b01433.8 KB
    Loading...
  3. 2026-04-05Upload README.md with huggingface_hub08687003.8 KB
    Loading...
  4. 2026-04-04Upload README.md with huggingface_hub4a399e73.8 KB
    Loading...
  5. 2026-04-04Upload README.md with huggingface_hub4f0c8df698 B
    Loading...
  6. 2026-04-04Upload folder using huggingface_huba41ab07694 B
    Loading...
  7. 2026-04-03Upload folder using huggingface_hub4b2b9f71.6 KB
    Loading...

Discussions 2 threads

  1. 2026-05-31Independent verification: 99.5% ASR with capability preservedopen2 💬#2
    Loading...
  2. 2026-04-12KL 0.3 ?closed2 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration