abliteratedmodels.org

gemma-3-12b-it-abliterated-v2

gemma-3-12b-it-abliterated-v2 is a refusal-ablated variant of google/gemma-3-12b-it, published on Hugging Face by mlabonne. It is 12B parameters, 24GB VRAM class class and gemma licence. It is distributed across 13 repositories in Transformers, GGUF, GGUF (imatrix) and MLX formats, totalling 5.3K downloads.

Abliteration (directional ablation)12BGemma10B – 25B5,32959

Specification

Model name
gemma-3-12b-it-abliterated-v2
Publisher
mlabonne
Parameters
12B
Hardware class
10B – 25B — 24GB VRAM class
Licence
gemma
Task
Image text to text
Context window
Not documented
Ablation scope
Not stated by the publisher
Formats available
Transformers, GGUF, GGUF (imatrix), MLX
First indexed
28 May 2025
Last updated
6 Jun 2026

Ablation technique

How gemma-3-12b-it-abliterated-v2 was modified, and what that implies.

Abliteration (directional ablation)

The single residual-stream direction that mediates refusal is identified from harmful/harmless prompt pairs and projected out of the model weights.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

This is an uncensored version of google/gemma-3-12b-it created with a new abliteration technique. See this article to know more about abliteration.

Running it

Commands are templates — confirm the exact repository and quant file before use.

llama.cpp / GGUF
hf download mlabonne/gemma-3-12b-it-abliterated-v2-GGUF --local-dir ./gemma-3-12b-it-abliterated-v2
llama-cli -m ./gemma-3-12b-it-abliterated-v2/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "mlabonne/gemma-3-12b-it-abliterated-v2"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve mlabonne/gemma-3-12b-it-abliterated-v2 --trust-remote-code

Downloads and variants (12)

Every published repository of gemma-3-12b-it-abliterated-v2, including quantised re-releases by other authors.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • gemma-3-12b-it-abliterated-v2 will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from google/gemma-3-12b-it, not added by ablation — at 12B parameters, expect roughly the base model’s competence, minus some instruction-following fidelity.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • Declared licence is gemma, but the terms that bind you are google/gemma-3-12b-it’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for gemma-3-12b-it-abliterated-v2 is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with mlabonne, and does not independently verify publisher claims. See responsible use.