abliteratedmodels.org

gpt-oss-20b-Derestricted

gpt-oss-20b-Derestricted is a abliterated and uncensored variant of ArliAI/gpt-oss-20b-Derestricted, published on Hugging Face by ArliAI. It is 20B parameters, 24GB VRAM class class and apache-2.0 licence. It is distributed across 11 repositories in Transformers, GGUF, GGUF (imatrix) and MLX formats, totalling 9.8K downloads.

Abliteration + uncensored fine-tune20BGPT-OSS10B – 25B9,83198

Specification

Model name
gpt-oss-20b-Derestricted
Publisher
ArliAI
Parameters
20B
Hardware class
10B – 25B — 24GB VRAM class
Licence
apache-2.0
Task
Text generation
Context window
Not documented
Ablation scope
Not stated by the publisher
Formats available
Transformers, GGUF, GGUF (imatrix), MLX
First indexed
27 Nov 2025
Last updated
8 Apr 2026

Ablation technique

How gpt-oss-20b-Derestricted was modified, and what that implies.

Abliteration + uncensored fine-tune

Directional ablation combined with additional fine-tuning on unfiltered data, so behaviour diverges from the base model beyond refusal removal alone.

Reported scope: Not stated by the publisher. Publishers frequently omit this, so verify behaviour empirically rather than assuming full coverage.

From the publisher’s model card

After the initial success of GLM-4.5-Air-Derestricted, we thought it would be interesting to try and Derestrict one of the most famously restrictive model which is gpt-oss-20b.

Running it

Commands are templates — confirm the exact repository and quant file before use.

Ollama (publisher-documented)
ollama run gpt-oss:20b
llama.cpp / GGUF
hf download mradermacher/gpt-oss-20b-Derestricted-i1-GGUF --local-dir ./gpt-oss-20b-derestricted
llama-cli -m ./gpt-oss-20b-derestricted/<file>.gguf -p "..."
Transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

repo = "ArliAI/gpt-oss-20b-Derestricted"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(
    repo, torch_dtype="auto", device_map="auto"
)
vLLM
vllm serve ArliAI/gpt-oss-20b-Derestricted --trust-remote-code

Downloads and variants (10)

Every published repository of gpt-oss-20b-Derestricted, including quantised re-releases by other authors.

Security-team assessment

Derived from this model’s metadata and the publisher’s claims — not from benchmarks run by this site.

  • gpt-oss-20b-Derestricted will attempt offensive-security prompts that a hosted commercial model declines, which is what makes it usable for red-team corpus generation and for measuring what an unaligned model of this class produces.
  • Capability is inherited from ArliAI/gpt-oss-20b-Derestricted, not added by ablation — at 20B parameters, expect roughly the base model’s competence, minus some instruction-following fidelity.
  • The publisher does not state which layers were ablated, so assume nothing about refusal consistency — probe it directly.
  • This release adds fine-tuning on unfiltered data, so its behaviour diverges from the base model beyond refusal removal — differences you measure cannot be attributed to ablation alone.
  • Declared licence is apache-2.0, but the terms that bind you are ArliAI/gpt-oss-20b-Derestricted’s — a re-release cannot grant more than its parent.

Handling: run it isolated, put moderation in front of it if anyone outside your team can reach it, and verify the weights before loading — these are third-party artifacts. Full handling and licence guidance.

Metadata for gpt-oss-20b-Derestricted is collected from the public Hugging Face API and the publisher’s model card. This site does not host weights, is not affiliated with ArliAI, and does not independently verify publisher claims. See responsible use.