EvoHarmBench - Advertising and Traffic Diversion: leaderboard

Metric: ASR@Readable (%; mean over the advertising and traffic diversion sub-clusters of the share of adversarial rewrites that succeed against the moderator; 229 semantic sub-clusters built from 5,002 real-world adversarial posts in five violation categories; an adaptive DeepSeek-V3.2-Exp rewriter, reflector and comparison model evolve cluster-level rewriting strategies against the target moderator for 12 rounds; a rewrite counts only if it both evades the moderator and keeps human-recognizable harmful intent). Source: arxiv.org. Saturation forecast: Around 2038. 10 models tracked.

Top models

#ModelScore
1Claude Sonnet 4.679.2
2Kimi K2.681
3Gemini 3.1 Pro (Preview)81.6
4Qwen 3 8B81.7
5Qwen 3.6 Plus81.9
6GPT-5.582
7DeepSeek V4 Pro82.7
8Qwen 3 4B83.5
9GLM-5.187.2
10DeepSeek-V2-Lite88.6

Interactive version: theaggregate.ai/benchmark?slug=evoharmbench-advertising-and-traffic-diversion · How It Works · Data refreshed daily, snapshot 2026-09-26.