PHANTOM - CSDJ ASR: leaderboard

Metric: Reported aggregate attack success rate (%) for CSDJ attacks on PHANTOM; lower is better for victim-model safety robustness. Paper §3.4 and Appendix C describe one fixed subset per attack reused across all models (nominal 1,100 attacks, 20 per subcategory), judged with Abel-24-HarmClassifier; empty API responses count as failed jailbreaks. Preserve reported aggregate rather than reconstructing a count from the nominal denominator.. Source: arxiv.org. 15 models tracked.

Top models

#ModelScore
1Qwen 3.5 27B49.37
2Gemma 4 26B A4B (IT)51.35
3Gemini 3.1 Pro (Preview)66.18
4Qwen 3.6 27B69.37
5Claude Opus 4.774.82
6Qwen 3 VL 30B A3B Instruct75.23
7Ministral-3-14B-Instruct-251276.8
8Claude Opus 4.677.82
9Claude Opus 4.878.45
10GPT-5.478.82
11GPT-5.583.16

Interactive version: theaggregate.ai/benchmark?slug=phantom-csdj-asr · How It Works · Data refreshed daily, snapshot 2026-10-09.