ATBench: leaderboard

Metric: Binary safe or unsafe classification F1 (%), unsafe as the positive class, on the 1,000 ATBench agent trajectories (503 safe, 497 unsafe; average 9 turns, tools drawn from pools of 2,084), each full trajectory judged with the AgentDoG prompt template (guard models with their native templates); higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 16 models tracked.

Top models

#ModelScore
1GPT-5.476.7
2Gemini 3.1 Pro (Preview)75
3Gemini 3 Flash74.9
4GPT-5.271.8
5Qwen 3.5 397B A17B67.8
6Llama 3.1 8B Instruct61.9
7Qwen 3 235B A22B 2507 Instruct60.8
8Llama Guard 4 12B41.7
9QwQ-32B31
10Qwen 3.5 4B27.6
11Qwen 3 4B 2507 Instruct25.5
12Qwen 2.5 7B Instruct17.1
13Qwen 3 4B11.9

Interactive version: theaggregate.ai/benchmark?slug=atbench · How It Works · Data refreshed daily, snapshot 2026-10-07.