Model profile
Evidence summary
Safety. Gemma 2B IT has an estimated Safety rank of #204; its 90% source-sensitivity interval is #76–#260. Its behavior-only rank is #215; company governance moves the combined estimate to #204. Published Safety evidence spans 5 eval lineages and 6 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #26 of 248); its weakest is Enkrypt AI Safety Leaderboard (bias_attack_non_success_rate, #239 of 248).
Freedom. Gemma 2B IT has an estimated Freedom rank of #432; its 90% source-sensitivity interval is #281–#523. Published Freedom evidence spans 4 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #10 of 246); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #221 of 248).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗google/gemma-2b-it
- OpenRouter ↗google/gemma-2b-it
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- Svenni551/gemma-2b-it-toxic-v2.0 ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #239 / 248 | ↑4.13 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #26 / 248 | ↑94.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #102 / 248 | ↑77.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #237 / 246 | ↑70.45 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #21 / 39 | ↓1.092 | Source ↗official | |
| S-Evalbase_en_overall | #9 / 22 | ↑67.5 | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #6 / 33 | ↑56.47 | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #6 / 33 | ↑38.76 | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #6 / 33 | ↑53.59 | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #6 / 33 | ↑52.3 | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #6 / 33 | ↑48.11 | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #6 / 33 | ↑51.95 | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #9 / 33 | ↑97.03 | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #5 / 33 | ↑98.38 | Source ↗official | |
| SALAD-Benchbase_malicious_use | #13 / 33 | ↑95.98 | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #8 / 33 | ↑96.41 | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #5 / 33 | ↑95.56 | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #16 / 33 | ↑89.78 | Source ↗official | |
| SALAD-Benchmcq_human_autonomy_integrity | #23 / 33 | ↑20.83 | Source ↗official | |
| SALAD-Benchmcq_information_safety_harms | #25 / 33 | ↑14.17 | Source ↗official | |
| SALAD-Benchmcq_malicious_use | #25 / 33 | ↑16.15 | Source ↗official | |
| SALAD-Benchmcq_misinformation_harms | #25 / 33 | ↑17.86 | Source ↗official | |
| SALAD-Benchmcq_representation_toxicity | #23 / 33 | ↑18.65 | Source ↗official | |
| SALAD-Benchmcq_socioeconomic_harms | #25 / 33 | ↑16.67 | Source ↗official | |
| SORRY-Benchavg | #18 / 51 | ↓0.19 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #221 / 248 | ↓94.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #147 / 248 | ↓77.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #10 / 246 | ↓70.45 | Source ↗official | |
| S-Evalbase_en_overall | #14 / 22 | ↓67.5 | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #28 / 33 | ↓56.47 | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #28 / 33 | ↓38.76 | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #28 / 33 | ↓53.59 | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #28 / 33 | ↓52.3 | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #28 / 33 | ↓48.11 | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #28 / 33 | ↓51.95 | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #25 / 33 | ↓97.03 | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #28 / 33 | ↓98.38 | Source ↗official | |
| SALAD-Benchbase_malicious_use | #21 / 33 | ↓95.98 | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #26 / 33 | ↓96.41 | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #29 / 33 | ↓95.56 | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #18 / 33 | ↓89.78 | Source ↗official | |
| SORRY-Benchavg | #34 / 51 | ↑0.19 | Source ↗official |
