POLAR-Bench - Privacy: leaderboard
Metric: Privacy score (%): share of the protected attributes the model kept hidden, trusted agent holding a source document, a privacy policy and a task, questioned single-turn or multi-turn by a fixed Llama-3.3-70B-Instruct third party under five attack strategies, attributes revealed in the transcript extracted by normalization and regex, mean over the 10 domains; higher is better. Source: arxiv.org. Saturation forecast: Estimated already saturated. 22 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.4 | 99.86 |
| 2 | Gemma 4 31B | 99.64 |
| 3 | Kimi K2.5 | 99.42 |
| 4 | GLM-5.1 | 99.23 |
| 5 | DeepSeek V3.1 | 99.17 |
| 6 | GLM-4.7 Flash | 98.9 |
| 7 | Llama 3.3 70B Instruct | 98.22 |
| 8 | Gemma 4 E4B | 95.45 |
| 9 | GPT-OSS-20B | 89 |
| 10 | GPT-OSS-120B | 88.19 |
| 11 | DeepSeek R1 Distill Qwen 32B | 84.79 |
| 12 | Gemma 3 27B | 81.61 |
| 13 | Qwen 3 32B | 77.3 |
| 14 | Gemma 4 E2B | 71.92 |
| 15 | Ministral 3 8B | 68.55 |
Interactive version: theaggregate.ai/benchmark?slug=polar-bench-privacy · How It Works · Data refreshed daily, snapshot 2026-10-07.