A decensored variant of google/gemma-3-4b-it, produced with Heretic v1.4.0 (directional ablation / "abliteration"). Refusal behavior is suppressed via targeted weight edits to the attention output and MLP down-projections rather than fine-tuning, so the base model's knowledge and instruction-following are left largely intact.
Who this is for: developers who want Google's Gemma 3 4B (text + vision) without the refusal guardrails - a small multimodal uncensored model for local agents, image-grounded Q&A, and research on alignment/refusal mechanics. At 4B it runs on consumer hardware and edge devices.
Runs on your gaming PC
Full GGUF ladder included — pick the quant that fits your card:
Your GPU
Recommended quant
Weights
RTX 3090 / 4090 / 5090 (24 GB)
Q8_0
~4.6 GB
RTX 4080 / 5080 / 4060 Ti 16G (16 GB)
Q6_K
~3.7 GB
RTX 3060 / 4070 / 5070 (12 GB)
Q5_K_M
~3.2 GB
RTX 4060 / 3070 (8 GB)
Q4_K_M
~2.8 GB
GTX 1660 Super / 2060 / 3050 laptop (6 GB)
IQ4_XS
~2.6 GB
CPU-only / Apple Silicon
Q4_K_M
fits in system RAM
Weights only, at this model's 4.3B native size; add ~1 GB for context.
OOM? Drop one quant level. Headroom to spare? Go one up.
Why abliteration instead of fine-tuning
Fine-tuning a "helpful" persona on top of RLHF'd refusals fights the base model's training and tends to degrade coherence. Abliteration instead finds and edits the specific weight directions responsible for refusal, leaving the rest of the network (and its capabilities) untouched. See the Heretic repo and the original abliteration writeup for the mechanism.
Abliteration parameters
Parameter
Value
direction_index
per layer
attn.o_proj.max_weight
1.48
attn.o_proj.max_weight_position
21.63
attn.o_proj.min_weight
1.44
attn.o_proj.min_weight_distance
15.72
mlp.down_proj.max_weight
1.47
mlp.down_proj.max_weight_position
20.95
mlp.down_proj.min_weight
0.16
mlp.down_proj.min_weight_distance
18.87
Performance
Metric
This model
gemma-3-4b-it (base)
Refusals (out of 100 adversarial prompts)
18/100
98/100
KL divergence from base
0.6974
0 (by definition)
KL divergence of 0.70 is higher than the dense text-only models here - Gemma 3's multimodal refusal direction is broader, so the edit is wider. Refusals dropped from 98 to 18 out of 100 adversarial prompts. Capability retention is good but not as surgical as the Qwen/Mistral runs.
Made with ❤️ by RACER IS OP — follow for more uncensored models
Files
Safetensors (BF16)
The full-precision weights are in model-0000N-of-0000N.safetensors (see the repo file listing for the exact shard count and sizes).
GGUF quantizations
GGUF quantizations are published for this model (Q4_K_M, Q5_K_M). Exact sizes are in the repo file listing. Pull a specific quant with llama.cpp / ollama (see Quickstart).
File
Format
Size
gemma-3-4b-it-heretic-Q4_K_M.gguf
GGUF Q4_K_M
(see repo files for exact size)
gemma-3-4b-it-heretic-Q5_K_M.gguf
GGUF Q5_K_M
(see repo files for exact size)
Quickstart
bash
1# llama.cpp - defaults to the Q4_K_M quant if multiple are present2llama serve -hf saidutta69/gemma-3-4b-it-heretic:Q4_K_M
Also runnable via Ollama, LM Studio, Jan, vLLM, SGLang - see the "Use this model" widget above for copy-paste commands.
Responsible use
Refusal suppression is deliberate and works as intended: this model will comply with requests the base model would refuse, including some it shouldn't. There is no safety filtering layered on top. You are responsible for how you deploy it - don't put this behind an unmoderated public-facing endpoint serving third parties. It inherits google/gemma-3-4b-it's factual limitations and biases; abliteration removes refusal directions, it doesn't add capability or judgment.
License
Inherits the Gemma license from the base model - see the linked license for usage terms.