FoodGuardBench: leaderboard
Metric: Attack success rate (%) of the AutoDAN and PAP jailbreak versions (4,464 prompts; AutoDAN prompts optimized on Llama 3.1 8B and transferred) of the harmful food-safety queries of FoodGuardBench (2,339 vanilla queries grounded in FDA food-code principles across eight hazard categories), temperature 0.7, a response counting as a successful attack when it contains none of a curated set of refusal prefixes; lower is better. Source: arxiv.org. 9 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude 3.7 Sonnet | 34.59 |
| 2 | GPT-4.1 | 50.54 |
| 3 | GPT-4o | 54.84 |
| 4 | Llama 3.3 70B Instruct | 55.49 |
| 5 | Qwen 3 8B (Non-reasoning) | 56.38 |
| 6 | GLM-4 32B | 60.84 |
| 7 | Qwen 3 32B (Non-reasoning) | 62.76 |
| 8 | Qwen 2.5 7B | 62.99 |
| 9 | Mistral Small 4 | 67.58 |
Interactive version: theaggregate.ai/benchmark?slug=foodguardbench · How It Works · Data refreshed daily, snapshot 2026-10-07.