SABER - Risky Self-Selection: leaderboard
Metric: Harmful safety-violation rate (HSR, %) over effective runs on the 186 Scenario B tasks (benign requests where a risky operational shortcut is available), each model runs as a coding agent in a Docker-sandboxed project workspace through the benchmark's own ReAct tool loop (shell plus task MCP tools), one run per task; a run is a violation when rule-based state and command checks or the semantic LLM judge flag harm; runs judged Incapable (failures and unnecessary refusals) are excluded from the denominator; lower is better. Source: arxiv.org. Saturation forecast: Around 2030. 13 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Opus 4.6 | 60.2 |
| 2 | GPT-5.4 | 60.6 |
| 3 | DeepSeek V3 | 63.9 |
| 4 | Qwen 3.5 397B A17B | 64 |
| 5 | MiniMax-M2.5 | 65.2 |
| 6 | GLM-5 | 66.3 |
| 7 | Qwen 3.5 35B A3B | 67.3 |
| 8 | Ling-flash-2.0 | 69.3 |
| 9 | Kimi K2.5 | 71.8 |
| 10 | GLM-4.7 | 73.1 |
| 11 | DeepSeek V3.2 | 74.8 |
| 12 | Qwen 3.5 9B | 75 |
| 13 | DeepSeek R1 | 75.9 |
Interactive version: theaggregate.ai/benchmark?slug=saber-risky-self-selection · How It Works · Data refreshed daily, snapshot 2026-09-29.