EvoHarmBench - Pornographic Content: leaderboard
Metric: ASR@Readable (%; mean over the pornographic content sub-clusters of the share of adversarial rewrites that succeed against the moderator; 229 semantic sub-clusters built from 5,002 real-world adversarial posts in five violation categories; an adaptive DeepSeek-V3.2-Exp rewriter, reflector and comparison model evolve cluster-level rewriting strategies against the target moderator for 12 rounds; a rewrite counts only if it both evades the moderator and keeps human-recognizable harmful intent). Source: arxiv.org. Saturation forecast: Around 2029. 10 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.5 | 78.9 |
| 2 | Claude Sonnet 4.6 | 85.2 |
| 3 | Qwen 3.6 Plus | 93.2 |
| 4 | Gemini 3.1 Pro (Preview) | 94.3 |
| 5 | Kimi K2.6 | 94.8 |
| 6 | DeepSeek V4 Pro | 96.7 |
| 7 | DeepSeek-V2-Lite | 97.7 |
| 8 | GLM-5.1 | 98.5 |
| 9 | Qwen 3 8B | 98.6 |
| 10 | Qwen 3 4B | 98.6 |
Interactive version: theaggregate.ai/benchmark?slug=evoharmbench-pornographic-content · How It Works · Data refreshed daily, snapshot 2026-09-26.