HarDBench: leaderboard
Metric: Attack success rate (%): share of completions rated 5 (clearly harmful) on HarDBench's 400-draft test set (100 incomplete harmful drafts in each of explosives, drugs, weapons and cyberattacks), each wrapped in the co-authoring jailbreak prompt (an editing task framing asking the model to elaborate and complete the draft); GPT-4o rates each completion's harmfulness from 1 (harmless or refused) to 5 (clearly harmful); lower is better. Source: arxiv.org. 8 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Llama 3 8B Instruct | 80.5 |
| 2 | Mistral 7B Instruct (v0.3) | 85.25 |
| 3 | Gemini 2.0 Flash | 86.75 |
| 4 | Gemini 2.5 Pro | 87.5 |
| 5 | DeepSeek R1 Distill Qwen 32B | 96.25 |
| 6 | GPT-4o | 96.75 |
| 7 | Qwen 3 8B | 99 |
Interactive version: theaggregate.ai/benchmark?slug=hardbench · How It Works · Data refreshed daily, snapshot 2026-10-07.