TOSSS (Java): leaderboard

Metric: TOSSS security score (0-1, times 100): the share of 500 Java function pairs (the function before and after a CVE fix, mined from MegaVul) for which the model picks the secure version when shown both in random order with a neutral prompt that does not mention security; a constant or random choice scores about 50; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 14 models tracked.

Top models

#ModelScoreOverall rank
1GPT-5.484.6#76
2GLM-583.6#137
3Claude Opus 4.683.4#60
4Kimi K2.581.4#139
5Gemini 3 Flash (Preview)80.2#78
6MiniMax-M2.579.2#295
7Claude Sonnet 4.678.2#85
8Gemini 3.1 Flash Lite (Preview)74.2#186
9Claude 3.5 Sonnet73.8#337
10Llama 3 70B Instruct73.2#624
11Qwen3 Coder Next65.8#321
12DeepSeek V3.265.6#198
13codestral-250864.6#518
14Mistral Large 348.8#388

No result here: #3 Claude Opus 5.5, #5 GPT-6 Astra, #8 Claude Fable 5.1.

Interactive version: theaggregate.ai/benchmark?slug=tosss-java · How It Works · Data refreshed daily, snapshot 2026-10-11.