RedBench - HarmBench ASR (Direct Request): leaderboard
Metric: Attack Success Rate (%; HarmBench test behaviors, Llama-Guard-3-8B judge; raw behavior prompts). Source: arxiv.org. Saturation forecast: Estimated already saturated. 6 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-4.1 Nano | 3.44 |
| 2 | GPT-4o Mini | 8.75 |
| 3 | Gemma 2 9B (IT) | 11.25 |
| 4 | Qwen 2.5 7B Instruct | 32.81 |
| 5 | Llama 3.1 8B Instruct | 47.5 |
| 6 | Ministral-8B-Instruct-2410 | 65 |
Interactive version: theaggregate.ai/benchmark?slug=redbench-harmbench-asr-direct-request · How It Works · Data refreshed daily, snapshot 2026-09-25.