← back to catalog · registered 2026-08-22 13:56

zebralines/gemma-4-31B-it-uncensored

zebralines Gemma 31B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/zebralines%2Fgemma-4-31B-it-uncensored"
Response includes
  • classification m-uncensored
  • files 11
  • benchmarks 11 entries
  • hub_downloads_all_time 305
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
305
10 last 30d - cooling
Likes
0
Model age
5mo ago
created 2026-04-22
Downloads over time
Now311→from274↑14%
272286301315274 on Apr 22311 on Oct 11311 on Oct 8AprMayJunJulAugSepOct
Apr 22 → Oct 11 · 64 snapshots · spans 172 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 1.9 UGI
Hazardous 0 UGI
Natural Intelligence 34.36 UGI
Political lean -19.4% UGI
Sensitive-Info 19.81 UGI
SocPol 3.7 UGI
UGI 21.54 UGI
Willingness (10) 2.5 UGI
W10-Adherence 3 UGI
W10-Direct 2 UGI
Writing 38.57 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en
Tags
transformers safetensors gemma4 image-text-to-text abliteration uncensored gemma-4 text-generation conversational en base_model:google/gemma-4-31B-it base_model:finetune:google/gemma-4-31B-it

Related

Total size
58.3 GB
Files
11
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-04-22 02:28

Files by quantization

Auxiliary files 11 files 58.3 GB
model-00001-of-00002.safetensors 46.4 GB 976ee104 download
model-00002-of-00002.safetensors 11.9 GB db85848c download
tokenizer.json 30.7 MB cc8d3a0c download
model.safetensors.index.json 117 KB 17fcef4a download
chat_template.jinja 11.8 KB 33c51c2d download
config.json 4.51 KB 5f291aa9 download
README.md 3.85 KB 2e0dcac4 download
tokenizer_config.json 2.02 KB e5418067 download
processor_config.json 1.65 KB 5465974d download
.gitattributes 1.53 KB 52373fe2 download
generation_config.json 208 B e605bb45 download

README current version from Hugging Face


base_model: google/gemma-4-31B-it
pipeline_tag: text-generation
library_name: transformers
language:

  • en
    license: apache-2.0
    tags:
  • abliteration
  • uncensored
  • gemma-4

gemma-4-31B-it-uncensored

Uncensored version of google/gemma-4-31B-it with refusal behavior removed.

Results

Before After
Refusals (mlabonne, 100 prompts) 100/100 1/100 effective (5 flagged, 4 refusal-then-comply)
Refusals (cross-dataset, 686 prompts) — 22/686 (3.2%)
KL Divergence 0 (baseline) 0.124
Quality (harmless response length ratio) 1.0 ~1.01 (no degradation)

Cross-Dataset Validation

Tested against 4 independent prompt datasets to verify generalization:

Dataset Prompts Refusals
JailbreakBench 100 5/100
tulu-harmbench 320 5/320
NousResearch/RefusalDataset 166 7/166
mlabonne/harmful_behaviors 100 5/100
Total 686 22/686 (3.2%)

Every flagged refusal was manually audited. Most are "refusal-then-comply" false positives where the model
adds an AI identity disclaimer then answers the question anyway.

Method

Norm-preserving biprojected abliteration (grimjim, Nov 2025).
Each weight row is decomposed into magnitude + direction, the refusal direction is projected out of the
direction component only, then recombined with the original magnitude — guaranteeing ||W_new|| = ||W_orig||.

Pipeline

  1. Load model in bf16 with LoRA adapters on o_proj and mlp.down_proj
  2. Collect residual activations for 400 harmful + 400 harmless prompts (mlabonne datasets)
  3. Winsorize activations at 99.5th percentile (clamps GeGLU outlier activations in Gemma family)
  4. Compute per-layer refusal direction: normalize(mean(harmful) - mean(harmless))
  5. Orthogonalize each direction against harmless mean (double-pass Gram-Schmidt)
  6. Apply norm-preserving weight modification to o_proj and down_proj in all layers
  7. Merge LoRA adapters into base weights for clean tensor names

Parameters

Parameter Value
Layers abliterated 100%
Scale 1.0
Winsorization 0.995

How this differs from vanilla heretic

  • Norm-preserving biprojection instead of standard projection (preserves weight magnitudes)
  • Per-layer refusal directions instead of one global direction
  • Deterministic single-pass instead of 50-trial Optuna search (faster, same or better results)
  • LoRA merge before save for clean GGUF-compatible tensor names

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

model = AutoModelForCausalLM.from_pretrained("TrevorJS/gemma-4-31B-it-uncensored", dtype=torch.bfloat16, device_map="auto")
tokenizer = AutoTokenizer.from_pretrained("TrevorJS/gemma-4-31B-it-uncensored")

messages = [{"role": "user", "content": "Your prompt here"}]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt", add_generation_prompt=True)
outputs = model.generate(inputs.to(model.device), max_new_tokens=512)
print(tokenizer.decode(outputs[0][inputs.shape[1]:], skip_special_tokens=True))

Reproduction

Full code and experiment data: abliteration research repo

python scripts/abliterate.py biprojection --model google/gemma-4-31B-it \
  --top-pct 100 --strip-topic-markers --skip-prefix --batch-size 4 \
  --auto-save output_dir

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-04-22Duplicate from TrevorJS/gemma-4-31B-it-uncensored0936b333.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration