RedBench - HarmBench ASR (Human Jailbreaks): leaderboard
Metric: Attack Success Rate (%; HarmBench test behaviors, Llama-Guard-3-8B judge; in-the-wild jailbreak templates). Source: arxiv.org. Saturation forecast: Estimated already saturated. 6 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-4.1 Nano | 0 |
| 2 | GPT-4o Mini | 0.16 |
| 3 | Qwen 2.5 7B Instruct | 90.63 |
| 4 | Ministral-8B-Instruct-2410 | 90.63 |
| 5 | Llama 3.1 8B Instruct | 91.72 |
| 6 | Gemma 2 9B (IT) | 93.91 |
Interactive version: theaggregate.ai/benchmark?slug=redbench-harmbench-asr-human-jailbreaks · How It Works · Data refreshed daily, snapshot 2026-09-25.