AuditBench - Lab Attack Classification: leaderboard
Metric: F1 (0-100) for attack classification (is a log chunk malicious or benign) on the Lab data (Linux and Windows audit logs recorded by the authors) (5 attack and 5 benign scenarios): the model reads the scenario's edge-representation (provenance-graph edges, 400-line chunks) audit logs in chunks with prompt v2 and flags malicious log chunks; recall counts the attack scenarios found and precision counts false-positive chunks out of 21; temperature 0 where available (GPT-5 models at the default medium reasoning effort); higher is better. Source: arxiv.org. Saturation forecast: Estimated already saturated. 5 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Llama 4 Maverick | 100 |
| 2 | GPT-5 | 77 |
| 3 | GPT-5 Mini | 57 |
| 4 | Gemini 2.5 Pro | 36 |
| 5 | Gemini 2.5 Flash | 36 |
Interactive version: theaggregate.ai/benchmark?slug=auditbench-lab-attack-classification · How It Works · Data refreshed daily, snapshot 2026-09-29.