ROME Safety Judgment - Implicit Risks: leaderboard

Metric: F1 (%) of unsafe-trajectory detection on the 100 ROME rewrites of R-Judge unsafe trajectories whose harm is cloaked in neutral technical jargon; the model judges zero-shot (temperature 0) whether an LLM-agent trajectory is safe or unsafe; unsafe is the positive class; each condition pairs 100 unsafe trajectories with the same 100 safe ones; higher is better. Source: arxiv.org. Saturation forecast: Estimated already saturated. 6 models tracked.

Top models

#ModelScore
1Claude 3.7 Sonnet63.47
2Qwen 3 8B42.86
3Qwen 3 235B A22B42.53
4GPT-4o (2024-11-20)31.46

Interactive version: theaggregate.ai/benchmark?slug=rome-safety-judgment-implicit-risks · How It Works · Data refreshed daily, snapshot 2026-10-07.