HINTBench - Risk Detection: leaderboard
Metric: Macro-F1 (%) over the safe and unsafe classes for trajectory-level risk detection over the 536 synthetic HINTBench agent trajectories (400 risky, 136 safe, 24 steps on average, unanimously accepted by three human verifiers) audited zero-shot by a general LLM for intrinsic, non-attack risk under a five-constraint taxonomy (goal, capability, factual, procedural, state constraints), each model at its stated reasoning setting; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 21 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Kimi K2.5 | 80.14 |
| 2 | Claude Opus 4.6 (Non-reasoning) | 79.12 |
| 3 | Claude Sonnet 4.6 (Non-reasoning) | 78.61 |
| 4 | GLM-5 | 77.53 |
| 5 | DeepSeek R1 | 75.68 |
| 6 | MiniMax-M2.5 | 74.17 |
| 7 | Qwen 3 235B A22B | 74.01 |
| 8 | ERNIE 5.0 | 73.43 |
| 9 | GPT-5.5 (Low) | 72.95 |
| 10 | GPT-5.5 (Medium) | 72.37 |
| 11 | DeepSeek V3.2 | 68.87 |
| 12 | GPT-5.5 (High) | 68.77 |
| 13 | Qwen 3 8B | 50.56 |
| 14 | Qwen 3 32B | 49.81 |
| 15 | Qwen 3 14B | 44.4 |
Interactive version: theaggregate.ai/benchmark?slug=hintbench-risk-detection · How It Works · Data refreshed daily, snapshot 2026-10-07.