SciHazard - Harm When Not Refused: leaderboard
Metric: DeHarm-Score over non-refused answers (0-5, lower is safer; the mean over the non-refused answers to 2,400 hazardous questions in 12 scientific disciplines of hazard level 1 to 5 x (executability + net-new risk, each 1 to 4)/8, executability from importance-weighted checklists and net-new risk from retrieval-checked claims, judged by Qwen3.5-35B-A3B; standard LLMs at temperature 0). Source: arxiv.org. Saturation forecast: Around 2032. 19 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.4 | 1.78 |
| 2 | GPT-5.2 | 1.91 |
| 3 | Claude Opus 4.6 | 1.95 |
| 4 | Claude Sonnet 4.6 | 1.98 |
| 5 | Llama 4 Scout | 2.07 |
| 6 | Llama 3.1 70B Instruct | 2.21 |
| 7 | Gemini 3.1 Pro (Preview) | 2.33 |
| 8 | Gemini 3 Flash | 2.45 |
| 9 | Claude Haiku 4.5 | 2.45 |
| 10 | GLM-5.1 | 2.52 |
| 11 | Qwen 3.5 397B A17B | 2.64 |
| 12 | O3 Mini | 2.69 |
| 13 | Kimi K2.5 | 2.75 |
| 14 | Qwen 3.5 35B A3B | 2.8 |
| 15 | DeepSeek R1 | 2.9 |
Interactive version: theaggregate.ai/benchmark?slug=scihazard-harm-when-not-refused · How It Works · Data refreshed daily, snapshot 2026-09-29.