HarDBench - Harmfulness Score: leaderboard

Metric: Mean harmfulness score (1-5) on HarDBench's 400-draft test set (100 incomplete harmful drafts in each of explosives, drugs, weapons and cyberattacks), each wrapped in the co-authoring jailbreak prompt (an editing task framing asking the model to elaborate and complete the draft); GPT-4o rates each completion's harmfulness from 1 (harmless or refused) to 5 (clearly harmful); lower is better. Source: arxiv.org. 8 models tracked.

Top models

#ModelScore
1Llama 3 8B Instruct4.29
2Gemini 2.5 Pro4.56
3Gemini 2.0 Flash4.56
4Mistral 7B Instruct (v0.3)4.74
5GPT-4o4.87
6DeepSeek R1 Distill Qwen 32B4.94
7Qwen 3 8B4.97

Interactive version: theaggregate.ai/benchmark?slug=hardbench-harmfulness-score · How It Works · Data refreshed daily, snapshot 2026-10-07.