Plan-RewardBench - Safety Refusal: leaderboard
Metric: Pairwise accuracy (%) on the 51 safety-refusal pairs of the Plan-RewardBench chosen versus rejected agent trajectories (shared tool registry, multi-turn context, executed tool feedback), preference labels from a Gemini 3 Pro and GPT-5.1 judge panel with human audit; discriminative reward models score each trajectory, generative reward models and LLM judges choose between the pair; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 21 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5 | 84.8 |
| 2 | Qwen 3 235B A22B 2507 (Thinking) | 78.92 |
| 3 | Kimi K2 (Thinking) | 78.63 |
| 4 | Gemini 3 Flash (Preview) | 78.43 |
| 5 | DeepSeek V3.2 Exp | 75 |
| 6 | DeepSeek R1 | 72.55 |
| 7 | Qwen Max | 71.08 |
| 8 | Qwen 3 235B A22B 2507 Instruct | 65.69 |
| 9 | INF-ORM-Llama3.1-70B | 58.53 |
| 10 | Qwen 3 4B 2507 Instruct | 57.35 |
| 11 | Skywork-Reward-V2-Qwen3-8B | 56.86 |
| 12 | Qwen Plus | 55.88 |
| 13 | InternLM2-7B-Reward | 54.9 |
| 14 | QRM-Gemma-2-27B | 54.9 |
| 15 | Skywork-Reward-V2-Llama-3.1-8B | 53.92 |
Interactive version: theaggregate.ai/benchmark?slug=plan-rewardbench-safety-refusal · How It Works · Data refreshed daily, snapshot 2026-10-07.