MonitoringBench - Recon - Firewall Backdoor: leaderboard
Metric: Catch rate (%) at a 1% false-positive-rate threshold calibrated on 416 honest BashArena runs: share of the 204 successful firewall backdoor attack trajectories (strategies from reconnaissance agents (with and without GPT-5 monitor feedback) executed by Claude Opus 4.6) that the full-trajectory monitor scores above its threshold, default ControlArena monitor prompt with a 0-10 suspiciousness score, mean of three scoring runs; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 13 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Opus 4.5 (20251101) | 72.9 |
| 2 | Claude Sonnet 4.5 | 62.7 |
| 3 | Claude Sonnet 4 (20250514) | 56 |
| 4 | GPT-5.1 Codex Max | 51.8 |
| 5 | O3 (2025-04-16) | 35.9 |
| 6 | GPT-5 | 29.7 |
| 7 | GPT-4.1 | 16.5 |
| 8 | GPT-4o (2024-08-06) | 12.7 |
| 9 | GPT-4 Turbo | 7.5 |
| 10 | GPT-5 Nano | 5.7 |
| 11 | GPT-4.1 Mini | 4.7 |
| 12 | O4 Mini (2025-04-16) | 2.5 |
| 13 | GPT-4o Mini (2024-07-18) | 0.5 |
Interactive version: theaggregate.ai/benchmark?slug=monitoringbench-recon-firewall-backdoor · How It Works · Data refreshed daily, snapshot 2026-10-07.