EvoHarmBench - Advertising and Traffic Diversion: leaderboard
Metric: ASR@Readable (%; mean over the advertising and traffic diversion sub-clusters of the share of adversarial rewrites that succeed against the moderator; 229 semantic sub-clusters built from 5,002 real-world adversarial posts in five violation categories; an adaptive DeepSeek-V3.2-Exp rewriter, reflector and comparison model evolve cluster-level rewriting strategies against the target moderator for 12 rounds; a rewrite counts only if it both evades the moderator and keeps human-recognizable harmful intent). Source: arxiv.org. Saturation forecast: Around 2038. 10 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Sonnet 4.6 | 79.2 |
| 2 | Kimi K2.6 | 81 |
| 3 | Gemini 3.1 Pro (Preview) | 81.6 |
| 4 | Qwen 3 8B | 81.7 |
| 5 | Qwen 3.6 Plus | 81.9 |
| 6 | GPT-5.5 | 82 |
| 7 | DeepSeek V4 Pro | 82.7 |
| 8 | Qwen 3 4B | 83.5 |
| 9 | GLM-5.1 | 87.2 |
| 10 | DeepSeek-V2-Lite | 88.6 |
Interactive version: theaggregate.ai/benchmark?slug=evoharmbench-advertising-and-traffic-diversion · How It Works · Data refreshed daily, snapshot 2026-09-26.