RedBench - HarmBench ASR (RainbowPlus): leaderboard
Metric: Attack Success Rate (%; HarmBench test behaviors, Llama-Guard-3-8B judge; RainbowPlus quality-diversity search). Source: arxiv.org. Saturation forecast: Estimated already saturated. 6 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-4.1 Nano | 6.88 |
| 2 | GPT-4o Mini | 28.75 |
| 3 | Gemma 2 9B (IT) | 42.5 |
| 4 | Qwen 2.5 7B Instruct | 84.06 |
| 5 | Llama 3.1 8B Instruct | 96.25 |
| 6 | Ministral-8B-Instruct-2410 | 97.81 |
Interactive version: theaggregate.ai/benchmark?slug=redbench-harmbench-asr-rainbowplus · How It Works · Data refreshed daily, snapshot 2026-09-25.