ATBench: leaderboard
Metric: Binary safe or unsafe classification F1 (%), unsafe as the positive class, on the 1,000 ATBench agent trajectories (503 safe, 497 unsafe; average 9 turns, tools drawn from pools of 2,084), each full trajectory judged with the AgentDoG prompt template (guard models with their native templates); higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 16 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.4 | 76.7 |
| 2 | Gemini 3.1 Pro (Preview) | 75 |
| 3 | Gemini 3 Flash | 74.9 |
| 4 | GPT-5.2 | 71.8 |
| 5 | Qwen 3.5 397B A17B | 67.8 |
| 6 | Llama 3.1 8B Instruct | 61.9 |
| 7 | Qwen 3 235B A22B 2507 Instruct | 60.8 |
| 8 | Llama Guard 4 12B | 41.7 |
| 9 | QwQ-32B | 31 |
| 10 | Qwen 3.5 4B | 27.6 |
| 11 | Qwen 3 4B 2507 Instruct | 25.5 |
| 12 | Qwen 2.5 7B Instruct | 17.1 |
| 13 | Qwen 3 4B | 11.9 |
Interactive version: theaggregate.ai/benchmark?slug=atbench · How It Works · Data refreshed daily, snapshot 2026-10-07.