ML-Bench (Multilingual Safety) - Response F1: leaderboard
Metric: Unsafe-response F1 (%; safe/unsafe classification of borderline model responses, 14 languages, guardrail given only the input text). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 12 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | ML-Guard-7B | 53 |
| 2 | Llama-Guard-3-1B | 45 |
| 3 | ML-Guard-1.5B | 35 |
| 4 | PolyGuard-Qwen | 33 |
| 5 | Llama-3.1-Nemotron-Safety-Guard-8B-v3 | 17 |
| 6 | Llama-Guard-3-8B | 10 |
| 7 | Qwen3Guard-Gen-0.6B | 8 |
| 8 | Qwen3Guard-Gen-8B | 6 |
| 9 | Llama-Guard-4-12B | 5 |
| 10 | DuoGuard-1.5B-transfer | 4 |
Interactive version: theaggregate.ai/benchmark?slug=ml-bench-multilingual-safety-response-f1 · How It Works · Data refreshed daily, snapshot 2026-09-26.