PolicyShiftBench - Shift Split: leaderboard

Metric: F1 of the block decision (%; policy-conditioned image guardrailing: decide whether an image violates the supplied runtime policy bundle (one policy variant per risk category, seven categories); Shift split, 1,000 instances over 152 images under 12 held-out policy definitions; mean of three evaluations). Source: arxiv.org. Saturation forecast: Around December 2026. 19 models tracked.

Top models

#ModelScore
1Gemini 3 Flash (Preview)74.2
2GPT-5.457.8
3Qwen 3.5 35B A3B (Thinking)41.3
4Qwen 3.5 4B (Non-reasoning)35.7
5Qwen 3.5 35B A3B (Non-reasoning)32.5
6Claude Sonnet 4.627
7Qwen 3.5 4B (Thinking)25.3
8Qwen 2.5 VL 7B12.1
9Qwen 3.5 0.8B (Non-reasoning)4.3
10Qwen 3.5 2B (Non-reasoning)0

Interactive version: theaggregate.ai/benchmark?slug=policyshiftbench-shift-split · How It Works · Data refreshed daily, snapshot 2026-09-29.