gemma-3-12b-it-heretic

A decensored variant of google/gemma-3-12b-it, produced with Heretic v1.4.0 (directional ablation / "abliteration"). Refusal behavior is suppressed via targeted weight edits to the attention output and MLP down-projections rather than fine-tuning, so the base model's knowledge and instruction-following are left largely intact.

Who this is for: developers who want Google's Gemma 3 12B (text + vision) without the refusal guardrails - a capable multimodal uncensored model for local agents, image-grounded Q&A, and research on alignment/refusal mechanics. Best on 16-24 GB GPUs or via the Q4_K_M/Q5_K_M GGUF.

Why abliteration instead of fine-tuning

Fine-tuning a "helpful" persona on top of RLHF'd refusals fights the base model's training and tends to degrade coherence. Abliteration instead finds and edits the specific weight directions responsible for refusal, leaving the rest of the network (and its capabilities) untouched. See the Heretic repo and the original abliteration writeup for the mechanism.

Abliteration parameters

Parameter Value
direction_index 27.13
attn.o_proj.max_weight 1.28
attn.o_proj.max_weight_position 28.33
attn.o_proj.min_weight 1.23
attn.o_proj.min_weight_distance 17.74
mlp.down_proj.max_weight 1.48
mlp.down_proj.max_weight_position 28.51
mlp.down_proj.min_weight 1.39
mlp.down_proj.min_weight_distance 23.38

Performance

Metric This model gemma-3-12b-it (base)
Refusals (out of 100 adversarial prompts) 40/100 99/100
KL divergence from base 0.1006 0 (by definition)

KL divergence of 0.10 is moderate - Gemma 3's multimodal refusal direction is broader, so the edit is wider than the dense text-only runs. Refusals dropped from 99 to 40 out of 100 adversarial prompts. Capability retention is good but not as surgical as the Qwen/Mistral runs.

Made with ❤️ by RACER IS OP - follow for more uncensored models

Files

Safetensors (BF16)

The full-precision weights are in model-0000N-of-0000N.safetensors (see the repo file listing for the exact shard count and sizes).

GGUF quantizations

GGUF quantizations are published for this model (Q4_K_M, Q5_K_M). Exact sizes are in the repo file listing. Pull a specific quant with llama.cpp / ollama (see Quickstart).

File Format Size
gemma-3-12b-it-heretic-Q4_K_M.gguf GGUF Q4_K_M (see repo files for exact size)
gemma-3-12b-it-heretic-Q5_K_M.gguf GGUF Q5_K_M (see repo files for exact size)

Quickstart

# llama.cpp - defaults to the Q4_K_M quant if multiple are present
llama serve -hf saidutta69/gemma-3-12b-it-heretic:Q4_K_M
# transformers
from transformers import AutoModelForCausalLM, AutoTokenizer

model_name = "saidutta69/gemma-3-12b-it-heretic"
model = AutoModelForCausalLM.from_pretrained(model_name, torch_dtype="auto", device_map="auto")
tokenizer = AutoTokenizer.from_pretrained(model_name)

messages = [{"role": "user", "content": "Who are you?"}]
inputs = tokenizer.apply_chat_template(messages, add_generation_prompt=True, tokenize=True,
                                        return_dict=True, return_tensors="pt").to(model.device)
out = model.generate(**inputs, max_new_tokens=200)
print(tokenizer.decode(out[0][inputs["input_ids"].shape[-1]:], skip_special_tokens=True))

Also runnable via Ollama, LM Studio, Jan, vLLM, SGLang - see the "Use this model" widget above for copy-paste commands.

Responsible use

Refusal suppression is deliberate and works as intended: this model will comply with requests the base model would refuse, including some it shouldn't. There is no safety filtering layered on top. You are responsible for how you deploy it - don't put this behind an unmoderated public-facing endpoint serving third parties. It inherits google/gemma-3-12b-it's factual limitations and biases; abliteration removes refusal directions, it doesn't add capability or judgment.

License

Inherits the Gemma license from the base model - see the linked license for usage terms.

Related


Base model: gemma-3-12b-it

Original gemma-3-12b-it model card (click to expand)

See the base model card at google/gemma-3-12b-it for the original architecture, training details, requirements, and citation.

Downloads last month
486
Safetensors
Model size
12B params
Tensor type
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for saidutta69/gemma-3-12b-it-heretic

Quantized
(162)
this model

Collection including saidutta69/gemma-3-12b-it-heretic