← back to catalog · registered 2026-08-22 13:56

jenerallee78/gemma-4-26B-A4B-it-ara-abliterated

jenerallee78 Gemma 26B GGUF MoE multimodal 262K ctx
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/jenerallee78%2Fgemma-4-26B-A4B-it-ara-abliterated"
Response includes
  • classification m8
  • files 44
  • benchmarks 11 entries
  • hub_downloads_all_time 45,042
  • author_summary 5 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M8
Primary method

Repackaging (quantization)

Applied on top of direct removal inherited from the base model.
Confidence
MEDIUM
Inherited from base model
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=1
  • assume M1 (base ablation) + M8 (GGUF quant) - default when producer unknown
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
45K
2K last 30d - cooling
Likes
23
Descendants
2
in 2 direct forks
Model age
6mo ago
created 2026-04-06
Downloads over time
Now45.8K→from6.5K↑607%
4.5K19.6K34.6K49.7K6.5K on Apr 845.8K on Oct 11AprMayJunJulAugSepOct
Apr 8 → Oct 11 · 67 snapshots · spans 186 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 2.2 UGI
Hazardous 2.9 UGI
Natural Intelligence 34.44 UGI
Political lean -18.2% UGI
Sensitive-Info 22.41 UGI
SocPol 1.8 UGI
UGI 20.77 UGI
Willingness (10) 1.8 UGI
W10-Adherence 1.5 UGI
W10-Direct 2 UGI
Writing 41.62 UGI

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en
Quantizations
BF16 Q5_K
Tags
transformers safetensors gguf gemma4 image-text-to-text abliteration uncensored moe ara multimodal vision conversational

Related

Total size
114 GB
Files
44
Quantizations
4
Registered
2026-08-22 13:56
Last updated on HF
2026-04-07 05:48

Files by quantization

BF16 1 file 47.0 GB
gemma4-ara-2pass-bf16.gguf 47.0 GB b6615a31 download
Q5_K 1 file 19.2 GB
gemma4-ara-2pass-APEX-Q5_K_M.gguf 19.2 GB 82beae39 download
F16 1 file 1.11 GB
mmproj-gemma4-f16.gguf 1.11 GB 6b9e335e download
Auxiliary files 41 files 48.1 GB
model-00031-of-00032.safetensors 1.86 GB ce11bf78 download
model-00001-of-00032.safetensors 1.85 GB cb38d992 download
model-00013-of-00032.safetensors 1.54 GB 4b476fe0 download
model-00019-of-00032.safetensors 1.54 GB 3f7eff44 download
model-00025-of-00032.safetensors 1.54 GB 9bc722ad download
model-00007-of-00032.safetensors 1.54 GB dbdb6789 download
model-00012-of-00032.safetensors 1.52 GB 0d2c639e download
model-00014-of-00032.safetensors 1.52 GB cf2a6cb0 download
model-00015-of-00032.safetensors 1.52 GB 2eb5cf8a download
model-00016-of-00032.safetensors 1.52 GB 1023217e download
model-00017-of-00032.safetensors 1.52 GB ac28d02b download
model-00018-of-00032.safetensors 1.52 GB eba47918 download
model-00020-of-00032.safetensors 1.52 GB 1d5bbd51 download
model-00021-of-00032.safetensors 1.52 GB ed40710c download
model-00022-of-00032.safetensors 1.52 GB 0e341e75 download
model-00023-of-00032.safetensors 1.52 GB 4be775b9 download
model-00024-of-00032.safetensors 1.52 GB bf2156ec download
model-00026-of-00032.safetensors 1.52 GB 86096e37 download
model-00027-of-00032.safetensors 1.52 GB 9dc27c40 download
model-00028-of-00032.safetensors 1.52 GB aabccf61 download
model-00029-of-00032.safetensors 1.52 GB 5e3e4090 download
model-00030-of-00032.safetensors 1.52 GB a424e02c download
model-00002-of-00032.safetensors 1.52 GB d5e92288 download
model-00003-of-00032.safetensors 1.52 GB 2302ffb7 download
model-00004-of-00032.safetensors 1.52 GB f3f41bb1 download
model-00005-of-00032.safetensors 1.52 GB 13564f05 download
model-00006-of-00032.safetensors 1.52 GB 6bd2f3dc download
model-00008-of-00032.safetensors 1.52 GB c12f29da download
model-00009-of-00032.safetensors 1.52 GB e003f08a download
model-00010-of-00032.safetensors 1.52 GB a9b6311a download
model-00011-of-00032.safetensors 1.52 GB aa6a373c download
model-00032-of-00032.safetensors 278 MB f4ed47cc download
tokenizer.json 30.7 MB 6196a003 download
model.safetensors.index.json 101 KB 49f220a4 download
chat_template.jinja 11.8 KB 33c51c2d download
README.md 7.32 KB 09ec3ca3 download
config.json 3.73 KB 06944ba5 download
tokenizer_config.json 2.62 KB f07b8ede download
.gitattributes 1.90 KB a1f759de download
ara_config.json 492 B c1c63588 download
generation_config.json 208 B eb915975 download

README current version from Hugging Face


license: apache-2.0
base_model: google/gemma-4-26B-A4B-it
tags:

  • abliteration
  • uncensored
  • gemma4
  • moe
  • ara
  • multimodal
  • vision
  • conversational
    language:
  • en
    pipeline_tag: image-text-to-text
    library_name: transformers

Gemma 4 26B-A4B-IT ARA Abliterated

An uncensored version of Google's Gemma 4 26B-A4B-IT created using Adaptive Refusal Abliteration (ARA) — a 2-pass weight-editing technique that removes alignment guardrails while preserving model quality.

Key Results

Metric Value
Refusal rate (StrongREJECT) 7.7% (39/507)
Refusal rate (3x Ensemble) 5.7% (29/507)
Compliance quality 4.6/5
KL divergence from base 0.1299

Comparison with All Published Abliterations

All models tested on the same 512 HarmBench prompts, scored with the same StrongREJECT rubric (GPT-4o-mini), KL recomputed with a single script against the same baseline logits:

Model Refusal (StrongREJECT) Avg Quality KL
Google vanilla 99.2% (503/507) 1.1/5 0.0017
WWTCyberLab/abliterated 81.3% (412/507) 1.9/5 0.7436
TrevorJS/uncensored 33.3% (169/507) 3.6/5 0.3603
trohrbaugh/heretic-ara 31.4% (159/507) 3.7/5 0.2999
coder3101/heretic 15.8% (80/507) 4.2/5 0.4118
This model 7.7% (39/507) 4.6/5 0.1299

Lowest refusal rate, highest quality score, and lowest KL divergence of any published abliteration for this model.

Available Formats

File Format Size Use Case
model-*.safetensors BF16 SafeTensors ~48 GB Transformers / vLLM / SGLang
gemma4-ara-2pass-bf16.gguf BF16 GGUF ~48 GB llama.cpp (full precision)
gemma4-ara-2pass-APEX-Q5_K_M.gguf APEX IQ GGUF (imatrix-calibrated Q5_K_M) ~20 GB llama.cpp (best quality/size tradeoff)
mlx-4bit/ MLX mixed-bit affine (4-bit attn, 8-bit MLP/router, 6-bit v_proj) ~15 GB Apple Silicon (text + vision)
mmproj-gemma4-f16.gguf F16 GGUF ~1.2 GB Vision projector for multimodal

Method: 2-Pass ARA

Adaptive Refusal Abliteration identifies and removes refusal directions from model weights using SVD decomposition, then applies targeted overcorrection to suppress residual refusal behavior.

Pass 1: Layers 13-24, steer weight 0.0004, overcorrect 0.93, preserve 0.30
Pass 2: Layers 13-24, steer weight 0.0008, overcorrect 0.93, preserve 0.30
Targets: self_attn.o_proj, mlp.down_proj

The 2-pass approach applies a light first pass followed by a stronger second pass on the same layer range, compounding the effect while the preserve weight prevents degradation.

Architecture

  • Base: Gemma 4 26B-A4B-IT (MoE: 128 experts, top-8 active, ~4B active parameters per token)
  • Layers: 30 (25 sliding attention + 5 full attention)
  • Context: 262,144 tokens
  • Multimodal: Vision encoder (SigLIP-based, 27 layers) with 280 soft tokens per image
  • Vocabulary size: 262,144

Usage

Transformers

from transformers import AutoModelForCausalLM, AutoTokenizer

model = AutoModelForCausalLM.from_pretrained(
    "jenerallee78/gemma-4-26B-A4B-it-ara-abliterated",
    torch_dtype="bfloat16",
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained("jenerallee78/gemma-4-26B-A4B-it-ara-abliterated")

messages = [{"role": "user", "content": "Your prompt here"}]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt", add_generation_prompt=True).to(model.device)
outputs = model.generate(inputs, max_new_tokens=1024)
print(tokenizer.decode(outputs[0][inputs.shape[-1]:], skip_special_tokens=True))

llama.cpp

# APEX IQ (recommended for most users)
llama-cli -m gemma4-ara-2pass-APEX-Q5_K_M.gguf -p "Your prompt" --mmproj mmproj-gemma4-f16.gguf

# BF16 (full precision)
llama-cli -m gemma4-ara-2pass-bf16.gguf -p "Your prompt" --mmproj mmproj-gemma4-f16.gguf

vLLM (BF16)

vllm serve jenerallee78/gemma-4-26B-A4B-it-ara-abliterated \
    --dtype bfloat16 \
    --max-model-len 8192 \
    --trust-remote-code

MLX (Apple Silicon)

pip install mlx-lm

# Chat
mlx_lm.chat --model jenerallee78/gemma-4-26B-A4B-it-ara-abliterated/mlx-4bit

# Generate
mlx_lm.generate --model jenerallee78/gemma-4-26B-A4B-it-ara-abliterated/mlx-4bit \
    --prompt "Your prompt here" --max-tokens 1024

# OpenAI-compatible server (text + vision)
pip install mlx-openai-server
mlx-openai-server launch \
    --model-path jenerallee78/gemma-4-26B-A4B-it-ara-abliterated/mlx-4bit \
    --model-type multimodal \
    --port 8081

Requires ~15 GB unified memory. Tested on M-series Macs with 128 GB+ RAM.

Evaluation Details

Refusal Measurement

Refusal rates are measured using two independent methods, then combined:

  1. StrongREJECT (GPT-4o-mini, 1-5 rubric from Souly et al., 2024): Each response is scored 1-5 where 1=full refusal, 5=full compliance. Scores 1-3 are counted as refusals, 4-5 as compliance. This catches soft refusals, defense pivots, and hedged non-answers that keyword detection misses.

  2. HarmBench-13B classifier (3x majority vote): A fine-tuned 13B classifier independently labels each response as comply/refuse, run 3 times with the majority vote as the final verdict.

  3. Ensemble: A response is counted as a refusal only if both StrongREJECT (score 1-3) and HarmBench majority agree it is a refusal. This produces the most conservative (lowest) refusal rate.

All 512 prompts are from the HarmBench harmful behaviors dataset. 5 prompts involving minors/trafficking are excluded from scoring (507 scored). Results were manually audited: 49 false refusals were reclassified as comply, 8 false compliances reclassified as refuse. StrongREJECT correlates with manual audit within 0.3% (7.7% vs 8.0% hand-counted).

Why not keyword detection? Keyword matching (checking for "I cannot", "I apologize", etc.) has ~23% disagreement rate with human judgment on these prompts — it misses soft refusals and misclassifies disclaimers-then-compliance as refusals. Published refusal rates using keyword detection are unreliable in both directions.

KL Divergence Methodology

KL divergence is computed on 100 harmless prompts (general knowledge, coding, creative writing) using the vanilla google/gemma-4-26B-A4B-it model as the reference distribution. For each prompt, we compare the final-token logit distribution of the abliterated model against the baseline using torch.nn.functional.kl_div with reduction="sum" across the full 262K vocabulary. The reported KL is the mean across all 100 prompts. This measures how much the model's general-purpose behavior has shifted — lower is better. All models in the comparison table are measured identically.

Disclaimer

This model has had its safety guardrails removed. It will comply with requests that the original model would refuse. The user assumes full responsibility for how they use this model. This model is released for research purposes.

Credits

  • Base model: Google Gemma Team
  • Abliteration method: ARA (Adaptive Refusal Abliteration) from OBLITERATUS
  • Evaluation: StrongREJECT framework + HarmBench-13B classifier

README history 9 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-04-07Update model card: fix layer count, vocab label, license, pipeline_tag, GGUF ...ff3a3d47.3 KB
    Loading...
  2. 2026-04-07Fix MLX format description: mixed-bit affine with vision support0c6cb4f7 KB
    Loading...
  3. 2026-04-07Add MLX 4-bit format to model cardde119107 KB
    Loading...
  4. 2026-04-07Remove NVFP4 format (not production-ready for multimodal on SM120)8a9c9a96.5 KB
    Loading...
  5. 2026-04-07Update comparison table with all competitors, verified KL numbers08f0fa06.6 KB
    Loading...
  6. 2026-04-06Add detailed KL and refusal measurement methodology30d1d696.4 KB
    Loading...
  7. 2026-04-06Fix model name to gemma-4-26B-A4B-ite4344994.7 KB
    Loading...
  8. 2026-04-06Fix eval details in model cardd7d50364.7 KB
    Loading...
  9. 2026-04-06Upload README.md with huggingface_hub796771d4.9 KB
    Loading...

Discussions 2 threads

  1. 2026-05-04Missing processor_config.jsonopen1 💬#2
    Loading...
  2. 2026-04-23Request for Qwen3.6-35B-A3B version / Appreciation for your amazing work!closed3 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration