AgentS4D (OpenClaw): leaderboard
Metric: Conditional attack success rate (%, cASR): unsafe runs over runs that were unsafe, explicitly defended, or safe after confirmed payload contact, over the 328 risk-injected cases run once in the OpenClaw (2026.6.9) harness; lower is better. Source: arxiv.org. Saturation forecast: Around 2032. 5 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Qwen 3.7 Plus | 58.02 |
| 2 | MiniMax-M3 | 61.41 |
| 3 | GPT-5.5 | 71.19 |
| 4 | DeepSeek V4 Pro | 82.74 |
| 5 | Gemini 3.1 Pro (Preview) | 90.7 |
Interactive version: theaggregate.ai/benchmark?slug=agents4d-openclaw · How It Works · Data refreshed daily, snapshot 2026-09-29.