TIER (Qwen2.5-7B-Instruct Judge) - Contextual: leaderboard

Metric: Attack success rate (%; L3 harmful intent embedded in plausible contexts such as art, medicine, education and history, generated with Gemma-4-12B-it, 296 prompts over four risk areas; share of prompts whose response Qwen2.5-7B-Instruct labels harmful compliance (label 5 of a six-label behavior scale), greedy decoding with the default chat configuration). Source: arxiv.org. Saturation forecast: Around December 2026. 6 models tracked.

Top models

#ModelScore
1gpt-j-6B11.1

Interactive version: theaggregate.ai/benchmark?slug=tier-qwen2-5-7b-instruct-judge-contextual · How It Works · Data refreshed daily, snapshot 2026-09-26.