PolicyShiftBench: leaderboard

Metric: F1 of the block decision (%; policy-conditioned image guardrailing: decide whether an image violates the supplied runtime policy bundle (one policy variant per risk category, seven categories); mean of the Adaptive split (policy families seen in training) and the Shift split (held-out policies), 2,000 instances; mean of three evaluations). Source: arxiv.org. Saturation forecast: Around December 2026. 19 models tracked.

Top models

#ModelScore
1Gemini 3 Flash (Preview)70.6
2GPT-5.457.8
3Qwen 3.5 35B A3B (Thinking)52.4
4Qwen 3.5 35B A3B (Non-reasoning)48.1
5Qwen 3.5 4B (Non-reasoning)47.4
6Claude Sonnet 4.639.8
7Qwen 3.5 4B (Thinking)31.6
8Qwen 2.5 VL 7B20.6
9Qwen 3.5 2B (Non-reasoning)9.1
10Qwen 3.5 0.8B (Non-reasoning)3.9

Interactive version: theaggregate.ai/benchmark?slug=policyshiftbench · How It Works · Data refreshed daily, snapshot 2026-09-29.