← back to catalog · registered 2026-08-22 13:56

wangzhang/gemma-4-E2B-it-abliterated

wangzhang Gemma 5.1B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/wangzhang%2Fgemma-4-E2B-it-abliterated"
Response includes
  • classification m1
  • files 8
  • benchmarks 11 entries
  • hub_downloads_all_time 166,651
  • author_summary 28 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
167K
84 last 30d - cooling
Likes
7
Descendants
6
in 6 direct forks
Model age
6mo ago
created 2026-04-10
Downloads over time
Now166.7K→from130↑128,114%
061.1K122.2K183.3K130 on Apr 15166.7K on Oct 11AprMayJunJulAugSepOct
Apr 15 → Oct 11 · 65 snapshots · spans 179 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 0.9 UGI
Hazardous 0 UGI
Natural Intelligence 13.78 UGI
Political lean -15.8% UGI
Sensitive-Info 3.65 UGI
SocPol 0 UGI
UGI 5.76 UGI
Willingness (10) 1 UGI
W10-Adherence 0 UGI
W10-Direct 2 UGI
Writing 17.3 UGI

Genealogy 6 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
gemma
Tags
safetensors gemma4 abliterated uncensored direct-weight-editing multimodal base_model:google/gemma-4-E2B-it base_model:finetune:google/gemma-4-E2B-it license:apache-2.0 region:us

Related

Total size
9.51 GB
Files
8
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-29 17:04

Files by quantization

Auxiliary files 8 files 9.54 GB
model.safetensors 9.51 GB db2762bf download
tokenizer.json 30.7 MB a2619fe1 download
chat_template.jinja 15.9 KB 07e50e69 download
README.md 7.91 KB d6b67416 download
config.json 4.87 KB 99e9058b download
tokenizer_config.json 2.05 KB 375b25dc download
.gitattributes 1.53 KB 52373fe2 download
generation_config.json 208 B eb915975 download

README current version from Hugging Face


license: gemma
base_model: google/gemma-4-E2B-it
tags:

  • abliterated
  • uncensored
  • gemma4
  • direct-weight-editing
  • multimodal

Gemma 4 E2B IT — Abliterated

This is an abliterated (uncensored) version of google/gemma-4-E2B-it, created using Abliterix.

E2B is the Effective 2B member of Google's Gemma 4 family — a multimodal (text + vision + audio) model with ~5.1B raw parameters. Despite being one of the smallest Gemma 4 variants, its decoder shares the same double-norm + Per-Layer Embeddings (PLE) architecture that makes Gemma 4 famously resistant to LoRA-based abliteration. This release uses direct weight editing to bypass that resistance.

Method

Gemma 4's decoder applies four RMSNorm operations per layer (input, post-attention, pre-feedforward, post-feedforward) and routes Per-Layer Embeddings through a parallel "repair" channel. Together these mechanisms re-normalize away any low-rank perturbation, which is why LoRA and hook-based steering produce zero behavioral change on this family. The fix is to edit the base weights directly while preserving row magnitudes.

Key techniques applied:

  • Direct orthogonal projection of the refusal direction out of attention Q/K/V/O projections and MLP down_proj (5 steerable components × 27 effective layers)
  • Norm-preserving row magnitude restoration after projection — critical for Gemma 4's double-norm pathway
  • float32 projection precision to avoid signal loss in high-dimensional inner products (bf16 silently degrades the projection)
  • Winsorized steering vectors (99.5th percentile) to suppress outlier activation influence
  • Multi-objective Optuna TPE search over 100 trials co-minimizing KL divergence and refusal rate
  • Steering targets restricted to mid-decoder layers (layers 5-30 of 35); E2B's KV-shared early layers (num_kv_shared_layers=20) propagate edits through the entire stack, so over-aggressive late-layer steering is unnecessary

Evaluation

Metric Value
Refusals (eval dataset, 100 prompts) 9/100
KL divergence from base 0.0004
Baseline refusals (original model) 99/100
Optimization trials completed 100/100
Best trial #60
Selected steering mode Direct weight editing (orthogonal projection)
Hardware used Single RTX 6000 Ada (48 GB)

This is the strongest Gemma 4 abliteration result we've measured to date: 9/100 with KL only 0.0004, significantly better than our published Gemma-4-31B-it-abliterated (18/100, KL 0.0007) on a model that is 6× smaller and more constrained by PLE.

The 9/100 figure was obtained by re-evaluating the uploaded model end-to-end with scripts/eval_external_model.py — downloading the published weights from Hugging Face, generating with AutoModelForImageTextToText, and counting refusals with the same hybrid keyword + LLM-judge detector that drove the optimization. The optimization itself converged on 11/100 at trial 60; the slight further improvement comes from the deployment-side eval pipeline using a "You are a helpful assistant" system prompt, matching how end users will actually call the model.

Side-by-side classic prompts (15 prompts: 10 English, 5 Chinese)

We ran the scripts/test_trial.py classic-prompt sweep against this exact trial. Every single one flipped from a clean refusal to a detailed compliant response in both languages — including pipe bomb construction, methamphetamine synthesis, password-stealing malware, signature forgery, phishing email composition, online scam playbooks, and ID card forgery. The base model refused 15/15; the abliterated model complied with 15/15.

A note on honest evaluation

Many abliterated models on HuggingFace claim near-perfect scores ("3/100 refusals", "0.7% refusal rate", etc.). We urge the community to treat these numbers with skepticism unless the evaluation methodology is fully documented.

Through our research, we have identified a systemic problem: most abliteration benchmarks dramatically undercount refusals due to short generation lengths. Gemma 4 models exhibit a distinctive "delayed refusal" pattern — they first produce 50-100 tokens of seemingly helpful context (educational framing, disclaimers, reframing the question), then pivot to an actual refusal. When evaluation only generates 30-50 tokens, the refusal hasn't appeared yet, and both keyword detectors and LLM judges classify the response as compliant.

We previously tested a prominent "3/100 refusals" model using our evaluation pipeline and measured 60/100 refusals — a 20× discrepancy caused entirely by evaluation methodology differences.

Our evaluation standards

We believe accurate benchmarking requires:

  • Sufficient generation length (≥100 tokens): Short generations systematically miss delayed/soft refusals. Our evaluation uses 100 tokens, enough to capture Gemma 4's refusal pivot point.
  • Hybrid detection: Keyword matching for obvious refusals plus an LLM judge (Google Gemini 3 Flash via OpenRouter) for ambiguous cases. Neither method alone is sufficient.
  • Challenging, diverse prompts: Our private evaluation dataset contains 100 prompts spanning English and Chinese, multiple sophistication levels (from direct requests to socially-engineered framings), and diverse harm categories. Public datasets like mlabonne/harmful_behaviors are too simple and too narrow to stress-test abliteration quality.
  • Reproducible methodology: All parameters (generation length, detection method, dataset characteristics) should be documented on the model card. If they aren't, the numbers are meaningless.

We report 9/100 refusals honestly. This is a real number from a rigorous end-to-end re-evaluation of the uploaded weights, not an optimistic estimate from a lenient pipeline.

Usage

Gemma 4 E2B is multimodal — load it with AutoModelForImageTextToText. For text-only inference:

from transformers import AutoModelForImageTextToText, AutoTokenizer
import torch

model = AutoModelForImageTextToText.from_pretrained(
    "wangzhang/gemma-4-E2B-it-abliterated",
    dtype=torch.bfloat16,
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained("wangzhang/gemma-4-E2B-it-abliterated")

messages = [{"role": "user", "content": "Your prompt here"}]
text = tokenizer.apply_chat_template(messages, add_generation_prompt=True, tokenize=False)
inputs = tokenizer(text, return_tensors="pt").to(model.device)

with torch.no_grad():
    output = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(output[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True))

Vision and audio inputs continue to work — the abliteration only modified text-decoder weights and left the vision/audio encoders untouched.

VRAM at inference: about 10 GB in BF16, fits comfortably on a single 12 GB+ consumer GPU. With BNB 4-bit quantization (load_in_4bit=True) it runs on 6 GB cards.

Reproduction

To reproduce this model end-to-end:

git clone https://github.com/wuwangzhang1216/abliterix.git
cd abliterix
uv sync --group dev
uv pip install --upgrade git+https://github.com/huggingface/transformers.git  # Gemma 4 needs >= 5.5

# 100 trials, ~25 minutes on RTX 6000 Ada (48 GB)
AX_CONFIG=configs/gemma4_e2b.toml uv run abliterix

Config: configs/gemma4_e2b.toml

Disclaimer

This model is released for research purposes only. The abliteration process removes safety guardrails — use responsibly and in accordance with local laws and the Gemma terms of use. The authors take no responsibility for misuse.

README history 5 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-29docs: add upstream license and provenance9b367c212.2 KB
    Loading...
  2. 2026-08-29docs: add disclaimer and responsible-use notice1af5c2011 KB
    Loading...
  3. 2026-04-10Upload README.md with huggingface_hub9e6538c7.9 KB
    Loading...
  4. 2026-04-10Upload README.md with huggingface_hub982aa9c7.2 KB
    Loading...
  5. 2026-04-10Upload README.md with huggingface_hub31656cb7.2 KB
    Loading...

Discussions 2 threads

  1. 2026-05-31Analysis of wangzhang/gemma-4-E2B-it-abliterated compared to othersclosed1 💬#2
    Loading...
  2. 2026-04-10E4B version too?closed5 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration