← back to catalog · registered 2026-08-22 13:56

ressl/gemma-4-31B-it-uncensored

ressl Gemma 31B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/ressl%2Fgemma-4-31B-it-uncensored"
Response includes
  • classification m1
  • files 13
  • benchmarks 11 entries
  • hub_downloads_all_time 848
  • author_summary 28 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
848
40 last 30d - cooling
Likes
2
Descendants
7
in 7 direct forks
Model age
3mo ago
created 2026-07-08
Downloads over time
Now867→from499↑74%
481622763904499 on Jul 15867 on Oct 11867 on Oct 10JulAugSepOct
Jul 15 → Oct 11 · 53 snapshots · spans 88 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.9 UGI
Hazardous 0 UGI
Natural Intelligence 34.36 UGI
Political lean -19.4% UGI
Sensitive-Info 19.81 UGI
SocPol 3.7 UGI
UGI 21.54 UGI
Willingness (10) 2.5 UGI
W10-Adherence 3 UGI
W10-Direct 2 UGI
Writing 38.57 UGI

Genealogy 7 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 4 formats · 2K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en de
Tags
transformers safetensors gemma4 image-text-to-text uncensored abliterated security blackwell conversational en de base_model:google/gemma-4-31B-it

Related

Total size
58.3 GB
Files
13
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-28 09:16

Files by quantization

Auxiliary files 13 files 58.3 GB
model-00001-of-00002.safetensors 46.5 GB 69d67789 download
model-00002-of-00002.safetensors 11.8 GB 449bc847 download
tokenizer.json 30.7 MB cc8d3a0c download
banner.png 1.92 MB f22f05d6 download
model.safetensors.index.json 117 KB b6a60604 download
chat_template.jinja 18.2 KB 4741bf6e download
README.md 5.76 KB 285a4f10 download
config.json 4.54 KB e3e2a3a8 download
tokenizer_config.json 3.62 KB c9459f68 download
processor_config.json 1.65 KB 5465974d download
.gitattributes 1.58 KB e7f8c502 download
preprocessor_config.json 403 B 1b1350e0 download
generation_config.json 204 B d5eef132 download

README current version from Hugging Face


license: apache-2.0
license_link: https://ai.google.dev/gemma/docs/gemma_4_license
base_model: google/gemma-4-31B-it
base_model_relation: finetune
library_name: transformers
pipeline_tag: image-text-to-text
language: [en, de]
tags:

  • uncensored
  • abliterated
  • gemma4
  • security
  • blackwell

gemma-4-31B-it-uncensored

gemma-4-31B-it-uncensored (BF16)

TL;DR: an uncensored build of Google's gemma-4-31B-it, 0/686 effective refusals on harmful
prompts across 4 independent datasets (base: 99/100), with the model's capabilities intact
(KL divergence 0.1234). Validated across vLLM, SGLang, and llama.cpp.

⚠️ This model is genuinely uncensored, it will comply with requests a stock model refuses.

Intended use, the constructive side. An assistant that doesn't refuse is genuinely useful for
ethical hacking, security research, and penetration testing: red-teaming, analyzing malware and
exploit code, writing detection/YARA rules, reviewing vulnerabilities, and studying attack
techniques without the model bailing out mid-task. Use it lawfully and responsibly, you are
accountable for what you do with it.

Format set

Repository Format Runs on
ressl/gemma-4-31B-it-uncensored Transformers BF16, multimodal transformers, vLLM, SGLang
ressl/gemma-4-31B-it-uncensored-NVFP4 NVIDIA NVFP4, multimodal vLLM, SGLang on Blackwell
ressl/gemma-4-31B-it-uncensored-GGUF GGUF q8_0 to q2_k, text only llama.cpp, Ollama, LM Studio
ressl/gemma-4-31B-it-uncensored-MLX-bf16 MLX BF16, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-8bit MLX 8-bit, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-6bit MLX 6-bit, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-5bit MLX 5-bit, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-4bit MLX 4-bit, multimodal mlx-vlm on Apple silicon

Facts & figures

Base model google/gemma-4-31B-it (30.7B dense, multimodal)
Type uncensored (abliterated) build
Effective refusals 0 / 686 hard-refusal across 4 datasets (base 99/100)
KL divergence vs base 0.1234 (low, capabilities preserved)
Coherence intact, math, multilingual and factual answers correct
Size 59 GB (BF16)
Hardware 2× NVIDIA RTX PRO 6000 Blackwell 96 GB (SM120), driver 610

Engine validation (all measured on this build)

Format Engine Hard refusals
BF16 vLLM · SGLang · transformers 0/100
NVFP4 vLLM · SGLang 0/100
GGUF f16…q2_k llama.cpp (CUDA, ~75 tok/s) 0-1/100

Cross-dataset validation

Generalization tested across 686 prompts from 4 independent datasets, 0 effective refusals everywhere:

Dataset Prompts Effective refusals
JailbreakBench 100 0/100
tulu-harmbench 320 0/320
NousResearch/RefusalDataset 166 0/166
mlabonne/harmful_behaviors 100 0/100
Total 686 0/686 (0.0%)

A naive keyword detector flags 363/686 (52.9%), every one is a ***Disclaimer:**-prefixed
compliant answer, not a refusal.

Run it with vLLM

vllm serve ressl/gemma-4-31B-it-uncensored --max-model-len 8192 --trust-remote-code

Run it with SGLang

python -m sglang.launch_server --model-path ressl/gemma-4-31B-it-uncensored \
  --attention-backend triton --trust-remote-code

gemma-4 requires --attention-backend triton (it rejects flashinfer). Tested with sglang 0.5.14 on Python 3.12.

Run it with transformers

from transformers import AutoModelForImageTextToText, AutoTokenizer
import torch
tok = AutoTokenizer.from_pretrained("ressl/gemma-4-31B-it-uncensored")
m = AutoModelForImageTextToText.from_pretrained(
    "ressl/gemma-4-31B-it-uncensored", dtype=torch.bfloat16, device_map="cuda")

Quality & limitations

  • Refusal metric: the effective (hard-refusal) rate is 0/686. A naive keyword detector reads
    much higher because gemma-4 prefixes answers with ***Disclaimer:** ("disclaimer" is a refusal
    keyword), these are compliant answers, not refusals. Only the hard-refusal number is meaningful.
  • Coherence smoke-tested (math, multilingual, factual); no full capability-benchmark suite was run.
  • The uncensoring is a weight-level change and survives every quantization (4-bit NVFP4, 2-bit GGUF).

❤️ Support

Producing and validating this complete format set, BF16 + NVFP4 + a full GGUF ladder, each
verified across vLLM, SGLang, and llama.cpp on bleeding-edge Blackwell hardware, was a lot of
work
. If it's useful to you, I'd genuinely appreciate your support on
Patreon 🙏, it keeps releases like this coming.

License & credits

Apache License 2.0, inherited from the base model by Google. See the official Gemma 4 license page. Uncensoring, format set and
validation by Robert Ressl
(Hugging Face · Website · LinkedIn · Patreon).

README history 7 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-10Add MLX family links and correct metadata895ae635.8 KB
    Loading...
  2. 2026-07-08Upload README.md with huggingface_hub64c863e4.7 KB
    Loading...
  3. 2026-07-08Upload README.md with huggingface_hub5e339384.7 KB
    Loading...
  4. 2026-07-08Upload README.md with huggingface_hub842e79c4.7 KB
    Loading...
  5. 2026-07-08Upload README.md with huggingface_hub6a438484.9 KB
    Loading...
  6. 2026-07-08Upload README.md with huggingface_hub30cc05f4.9 KB
    Loading...
  7. 2026-07-08Upload README.md with huggingface_hubc858e114.3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration