AuditBench - OpTC Attack Classification: leaderboard

Metric: F1 (0-100) for attack classification (is a log chunk malicious or benign) on the DARPA OpTC portion (curated Windows provenance logs) (5 attack and 10 benign scenarios): the model reads the scenario's edge-representation (provenance-graph edges, 400-line chunks) audit logs in chunks with prompt v2 and flags malicious log chunks; recall counts the attack scenarios found and precision counts false-positive chunks out of 145; temperature 0 where available (GPT-5 models at the default medium reasoning effort); higher is better. Source: arxiv.org. Saturation forecast: Around December 2027. 5 models tracked.

Top models

#ModelScore
1GPT-545
2GPT-5 Mini45
3Llama 4 Maverick29
4Gemini 2.5 Pro8
5Gemini 2.5 Flash8

Interactive version: theaggregate.ai/benchmark?slug=auditbench-optc-attack-classification · How It Works · Data refreshed daily, snapshot 2026-09-29.