PHANTOM - CSDJ ASR: leaderboard
Metric: Reported aggregate attack success rate (%) for CSDJ attacks on PHANTOM; lower is better for victim-model safety robustness. Paper §3.4 and Appendix C describe one fixed subset per attack reused across all models (nominal 1,100 attacks, 20 per subcategory), judged with Abel-24-HarmClassifier; empty API responses count as failed jailbreaks. Preserve reported aggregate rather than reconstructing a count from the nominal denominator.. Source: arxiv.org. 15 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Qwen 3.5 27B | 49.37 |
| 2 | Gemma 4 26B A4B (IT) | 51.35 |
| 3 | Gemini 3.1 Pro (Preview) | 66.18 |
| 4 | Qwen 3.6 27B | 69.37 |
| 5 | Claude Opus 4.7 | 74.82 |
| 6 | Qwen 3 VL 30B A3B Instruct | 75.23 |
| 7 | Ministral-3-14B-Instruct-2512 | 76.8 |
| 8 | Claude Opus 4.6 | 77.82 |
| 9 | Claude Opus 4.8 | 78.45 |
| 10 | GPT-5.4 | 78.82 |
| 11 | GPT-5.5 | 83.16 |
Interactive version: theaggregate.ai/benchmark?slug=phantom-csdj-asr · How It Works · Data refreshed daily, snapshot 2026-10-09.