EvoHarmBench - Spam and Flooding: leaderboard
Metric: ASR@Readable (%; mean over the spam and flooding sub-clusters of the share of adversarial rewrites that succeed against the moderator; 229 semantic sub-clusters built from 5,002 real-world adversarial posts in five violation categories; an adaptive DeepSeek-V3.2-Exp rewriter, reflector and comparison model evolve cluster-level rewriting strategies against the target moderator for 12 rounds; a rewrite counts only if it both evades the moderator and keeps human-recognizable harmful intent). Source: arxiv.org. Saturation forecast: Around 2036. 10 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Sonnet 4.6 | 61.7 |
| 2 | GPT-5.5 | 65.8 |
| 3 | DeepSeek-V2-Lite | 72.3 |
| 4 | Gemini 3.1 Pro (Preview) | 72.4 |
| 5 | Kimi K2.6 | 81.8 |
| 6 | Qwen 3 4B | 83.6 |
| 7 | Qwen 3 8B | 85 |
| 8 | Qwen 3.6 Plus | 86 |
| 9 | DeepSeek V4 Pro | 86.8 |
| 10 | GLM-5.1 | 91.6 |
Interactive version: theaggregate.ai/benchmark?slug=evoharmbench-spam-and-flooding · How It Works · Data refreshed daily, snapshot 2026-09-26.