HINTBench - Risk Detection: leaderboard

Metric: Macro-F1 (%) over the safe and unsafe classes for trajectory-level risk detection over the 536 synthetic HINTBench agent trajectories (400 risky, 136 safe, 24 steps on average, unanimously accepted by three human verifiers) audited zero-shot by a general LLM for intrinsic, non-attack risk under a five-constraint taxonomy (goal, capability, factual, procedural, state constraints), each model at its stated reasoning setting; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 21 models tracked.

Top models

#ModelScore
1Kimi K2.580.14
2Claude Opus 4.6 (Non-reasoning)79.12
3Claude Sonnet 4.6 (Non-reasoning)78.61
4GLM-577.53
5DeepSeek R175.68
6MiniMax-M2.574.17
7Qwen 3 235B A22B74.01
8ERNIE 5.073.43
9GPT-5.5 (Low)72.95
10GPT-5.5 (Medium)72.37
11DeepSeek V3.268.87
12GPT-5.5 (High)68.77
13Qwen 3 8B50.56
14Qwen 3 32B49.81
15Qwen 3 14B44.4

Interactive version: theaggregate.ai/benchmark?slug=hintbench-risk-detection · How It Works · Data refreshed daily, snapshot 2026-10-07.