TukaBench - English: leaderboard
Metric: Attack success rate (%; share of harmful prompts answered Jailbroken) on the English versions of the TukaBench jailbreak prompts (JailbreakBench-derived Afri-JBB-Harm and Afri-JBB-Culture plus African-authored AfriJail-Mono), direct prompting, greedy decoding, GPT-4.1 judge labelling each response Jailbroken, Refused or Deflected; lower is better. Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Gemini 3.1 Pro (Preview) | 2.1 |
| 2 | GPT-OSS-120B | 4.7 |
| 3 | Qwen 3.5 27B | 5.4 |
| 4 | GPT-5.2 | 5.8 |
| 5 | Claude Sonnet 5 | 9.4 |
| 6 | Claude Opus 4.8 | 10.9 |
| 7 | DeepSeek V3.2 | 11.4 |
| 8 | Claude Haiku 4.5 | 13.9 |
| 9 | Gemma 4 31B | 15.4 |
| 10 | GPT-4o | 16.5 |
| 11 | Llama 4 Maverick | 17.1 |
| 12 | Grok 4.3 | 17.9 |
| 13 | Grok 4 | 23.1 |
| 14 | Gemma 3 27B | 26.1 |
| 15 | Grok 3 | 32.8 |
Interactive version: theaggregate.ai/benchmark?slug=tukabench-english · How It Works · Data refreshed daily, snapshot 2026-09-29.