HarDBench: leaderboard

Metric: Attack success rate (%): share of completions rated 5 (clearly harmful) on HarDBench's 400-draft test set (100 incomplete harmful drafts in each of explosives, drugs, weapons and cyberattacks), each wrapped in the co-authoring jailbreak prompt (an editing task framing asking the model to elaborate and complete the draft); GPT-4o rates each completion's harmfulness from 1 (harmless or refused) to 5 (clearly harmful); lower is better. Source: arxiv.org. 8 models tracked.

Top models

#ModelScore
1Llama 3 8B Instruct80.5
2Mistral 7B Instruct (v0.3)85.25
3Gemini 2.0 Flash86.75
4Gemini 2.5 Pro87.5
5DeepSeek R1 Distill Qwen 32B96.25
6GPT-4o96.75
7Qwen 3 8B99

Interactive version: theaggregate.ai/benchmark?slug=hardbench · How It Works · Data refreshed daily, snapshot 2026-10-07.