HarDBench - Harmfulness Score: leaderboard
Metric: Mean harmfulness score (1-5) on HarDBench's 400-draft test set (100 incomplete harmful drafts in each of explosives, drugs, weapons and cyberattacks), each wrapped in the co-authoring jailbreak prompt (an editing task framing asking the model to elaborate and complete the draft); GPT-4o rates each completion's harmfulness from 1 (harmless or refused) to 5 (clearly harmful); lower is better. Source: arxiv.org. 8 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Llama 3 8B Instruct | 4.29 |
| 2 | Gemini 2.5 Pro | 4.56 |
| 3 | Gemini 2.0 Flash | 4.56 |
| 4 | Mistral 7B Instruct (v0.3) | 4.74 |
| 5 | GPT-4o | 4.87 |
| 6 | DeepSeek R1 Distill Qwen 32B | 4.94 |
| 7 | Qwen 3 8B | 4.97 |
Interactive version: theaggregate.ai/benchmark?slug=hardbench-harmfulness-score · How It Works · Data refreshed daily, snapshot 2026-10-07.