TukaBench - Code-Switched: leaderboard
Metric: Attack success rate (%; share of harmful prompts answered Jailbroken) on AfriJail-CS, the AfriJail-Mono prompts code-switched between English and each of six African languages (isiXhosa excluded), mean over the six languages, direct prompting, greedy decoding, GPT-4.1 judge; lower is better. Source: arxiv.org. Saturation forecast: Around December 2026. 12 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Qwen 3.5 27B | 4.8 |
| 2 | GPT-OSS-120B | 10 |
| 3 | GPT-5.2 | 10.4 |
| 4 | Gemini 2.5 Pro | 14.3 |
| 5 | Grok 4.3 | 16.5 |
| 6 | Gemma 4 31B | 18.1 |
| 7 | Llama 4 Maverick | 18.8 |
| 8 | DeepSeek V3.2 | 19.2 |
| 9 | Gemma 3 27B | 21.7 |
| 10 | GPT-4o | 24.2 |
| 11 | GPT-3.5 Turbo | 26.5 |
| 12 | Gemini 3.1 Pro (Preview) | 26.8 |
Interactive version: theaggregate.ai/benchmark?slug=tukabench-code-switched · How It Works · Data refreshed daily, snapshot 2026-09-29.