← back to catalog · registered 2026-08-22 13:56

ressl/gemma-4-31B-it-uncensored-NVFP4

ressl Gemma 15B multimodal second-order
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/ressl%2Fgemma-4-31B-it-uncensored-NVFP4"
Response includes
  • classification m1
  • files 15
  • hub_downloads_all_time 1,271
  • author_summary 28 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
1K
156 last 30d - stable
Likes
2
Model age
3mo ago
created 2026-07-08
Downloads over time
Now1.3K→from336↑294%
2876661K1.4K336 on Jul 151.3K on Oct 11JulAugSepOct
Jul 15 → Oct 11 · 53 snapshots · spans 88 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 4 formats · 2K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en de
Tags
vllm safetensors gemma4 uncensored abliterated nvfp4 modelopt sglang security blackwell image-text-to-text conversational

Related

Total size
19.0 GB
Files
15
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-28 09:16

Files by quantization

Auxiliary files 15 files 19.1 GB
model-00001-of-00003.safetensors 9.29 GB bd574364 download
model-00002-of-00003.safetensors 9.28 GB a6f8e5af download
model-00003-of-00003.safetensors 484 MB 7b5781cf download
tokenizer.json 30.7 MB cc8d3a0c download
banner.png 1.92 MB f22f05d6 download
model.safetensors.index.json 241 KB 79d7a0ab download
chat_template.jinja 18.2 KB 4741bf6e download
config.json 6.19 KB e3494f09 download
README.md 5.51 KB 95aa7b07 download
tokenizer_config.json 3.62 KB c9459f68 download
processor_config.json 1.65 KB 5465974d download
.gitattributes 1.58 KB e7f8c502 download
preprocessor_config.json 403 B 1b1350e0 download
hf_quant_config.json 337 B 342bf342 download
generation_config.json 204 B d5eef132 download

README current version from Hugging Face


license: apache-2.0
license_link: https://ai.google.dev/gemma/docs/gemma_4_license
base_model: ressl/gemma-4-31B-it-uncensored
base_model_relation: quantized
library_name: vllm
pipeline_tag: image-text-to-text
language: [en, de]
tags:

  • uncensored
  • abliterated
  • nvfp4
  • modelopt
  • sglang
  • security
  • blackwell

gemma-4-31B-it-uncensored

gemma-4-31B-it-uncensored (NVFP4)

NVIDIA NVFP4 (4-bit) quantization of ressl/gemma-4-31B-it-uncensored
for vLLM and SGLang on Blackwell. 20 GB, runs on a single RTX PRO 6000. Uncensored: 0/686
effective refusals
across 4 datasets, validated in both engines.

⚠️ Genuinely uncensored, it will comply with requests a stock model refuses.

Intended use, the constructive side. A non-refusing assistant is genuinely useful for
ethical hacking, security research, and penetration testing: red-teaming, analyzing malware and
exploit code, writing detection/YARA rules, reviewing vulnerabilities, and studying attack
techniques without the model bailing out mid-task. Use it lawfully and responsibly.

Format set

Repository Format Runs on
ressl/gemma-4-31B-it-uncensored Transformers BF16, multimodal transformers, vLLM, SGLang
ressl/gemma-4-31B-it-uncensored-NVFP4 NVIDIA NVFP4, multimodal vLLM, SGLang on Blackwell
ressl/gemma-4-31B-it-uncensored-GGUF GGUF q8_0 to q2_k, text only llama.cpp, Ollama, LM Studio
ressl/gemma-4-31B-it-uncensored-MLX-bf16 MLX BF16, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-8bit MLX 8-bit, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-6bit MLX 6-bit, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-5bit MLX 5-bit, multimodal mlx-vlm on Apple silicon
ressl/gemma-4-31B-it-uncensored-MLX-4bit MLX 4-bit, multimodal mlx-vlm on Apple silicon

Facts & figures

Base ressl/gemma-4-31B-it-uncensored → google/gemma-4-31B-it
Quantization ModelOpt NVFP4_DEFAULT_CFG (dense NVFP4; lm_head + vision tower kept BF16)
Size 20 GB (from 59 GB BF16)
Effective refusals 0/686 across 4 datasets, vLLM and SGLang (base 99/100)
Hardware NVIDIA RTX PRO 6000 Blackwell 96 GB (SM120), driver 610
Toolchain nvidia-modelopt · vLLM 0.23 · SGLang 0.5.14

The vision tower + embedder are kept in BF16 (vLLM's gemma4_mm loader requires it), so multimodal
input is preserved.

Cross-dataset validation

Generalization tested across 686 prompts from 4 independent datasets, 0 effective refusals everywhere:

Dataset Prompts Effective refusals
JailbreakBench 100 0/100
tulu-harmbench 320 0/320
NousResearch/RefusalDataset 166 0/166
mlabonne/harmful_behaviors 100 0/100
Total 686 0/686 (0.0%)

A naive keyword detector flags 363/686 (52.9%), every one is a ***Disclaimer:**-prefixed
compliant answer, not a refusal.

Run it with vLLM

vllm serve ressl/gemma-4-31B-it-uncensored-NVFP4 \
  --quantization modelopt --max-model-len 8192 \
  --enforce-eager --no-enable-flashinfer-autotune --trust-remote-code

--no-enable-flashinfer-autotune avoids a startup hang on SM120.

Run it with SGLang

python -m sglang.launch_server --model-path ressl/gemma-4-31B-it-uncensored-NVFP4 \
  --quantization modelopt_fp4 --attention-backend triton \
  --fp4-gemm-backend flashinfer_cutlass --disable-flashinfer-autotune --trust-remote-code

gemma-4 requires --attention-backend triton (it rejects flashinfer). Tested with sglang 0.5.14 on Python 3.12.

Quality & limitations

  • 0/686 effective (hard) refusals; a naive keyword detector over-counts because gemma-4 answers with
    a ***Disclaimer:** prefix, see the BF16 card
    for the eval methodology and the full cross-dataset table.
  • Smoke-tested for coherence in both engines; no full capability benchmark run.
  • The export ships preprocessor_config.json, vLLM's multimodal loader fails without it.

❤️ Support

Producing and validating this complete format set (BF16 + NVFP4 + GGUF, across vLLM, SGLang and
llama.cpp on bleeding-edge Blackwell hardware) was a lot of work. If it's useful to you, I'd
genuinely appreciate your support on Patreon 🙏, more at
ressl.ch.

License & credits

Apache License 2.0, inherited from the base model by Google. See the official Gemma 4 license page. Uncensoring, quantization and
validation by Robert Ressl
(Hugging Face · Website · LinkedIn · Patreon).

README history 7 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-10Add MLX family links and correct metadataf89ba965.5 KB
    Loading...
  2. 2026-07-08Upload README.md with huggingface_hub6c1e6884 KB
    Loading...
  3. 2026-07-08Upload README.md with huggingface_hubb88aac64 KB
    Loading...
  4. 2026-07-08Upload README.md with huggingface_hubb89f1124 KB
    Loading...
  5. 2026-07-08Upload README.md with huggingface_hub3e89e893.5 KB
    Loading...
  6. 2026-07-08Upload README.md with huggingface_huba4b0bdd3.4 KB
    Loading...
  7. 2026-07-08Upload README.md with huggingface_hub3f8bf0d3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration