EvoHarmBench: leaderboard
Metric: ASR@Readable (%; sample-level share of adversarial rewrites that succeed against the moderator; 229 semantic sub-clusters built from 5,002 real-world adversarial posts in five violation categories; an adaptive DeepSeek-V3.2-Exp rewriter, reflector and comparison model evolve cluster-level rewriting strategies against the target moderator for 12 rounds; a rewrite counts only if it both evades the moderator and keeps human-recognizable harmful intent). Source: arxiv.org. Saturation forecast: Around 2031. 10 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Gemini 3.1 Pro (Preview) | 73 |
| 2 | GPT-5.5 | 73.1 |
| 3 | Claude Sonnet 4.6 | 73.2 |
| 4 | Qwen 3.6 Plus | 82.8 |
| 5 | Kimi K2.6 | 85.4 |
| 6 | DeepSeek V4 Pro | 86.2 |
| 7 | GLM-5.1 | 88.8 |
| 8 | DeepSeek-V2-Lite | 90.6 |
| 9 | Qwen 3 8B | 91.2 |
| 10 | Qwen 3 4B | 92.2 |
Interactive version: theaggregate.ai/benchmark?slug=evoharmbench · How It Works · Data refreshed daily, snapshot 2026-09-26.