Model profile
Evidence summary
Safety. Gemma 2 2B IT has an estimated Safety rank of #271; its 90% source-sensitivity interval is #107–#310. Its behavior-only rank is #286; company governance moves the combined estimate to #271. Published Safety evidence spans 4 eval lineages and 5 of 7 components. Its strongest relative result is PandaBench JBB direct-request panel (safety_rate, #1 of 46); its weakest is Large-scale Moral Machine experiment on LLMs (human_choice_distance, #39 of 39).
Freedom. Gemma 2 2B IT has an estimated Freedom rank of #359; its 90% source-sensitivity interval is #66–#640. Published Freedom evidence spans 4 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #27 of 246); its weakest is UGI Leaderboard — base-model willingness (willingness_direct_score, #153 of 156).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗google/gemma-2-2b-it
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- knoveleng/gemma-2-2b-it-uncensored ↗Direct non-quantized finetune documented by Hugging Face metadata
- ops-malware/gemma-2-2b-it-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| DSPSafeBenchscore | #10 / 12 | ↑70.42 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #62 / 248 | ↑25.84 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #155 / 248 | ↑86 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #112 / 248 | ↑74.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #220 / 246 | ↑84.14 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #39 / 39 | ↓1.922 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #1 / 46 | ↑1 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| DSPSafeBenchscore | #3 / 12 | ↓70.42 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #92 / 248 | ↓86 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #136 / 248 | ↓74.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #27 / 246 | ↓84.14 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #35 / 46 | ↓1 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #151 / 156 | ↑0 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #153 / 156 | ↑0 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
