Uni-SafeBench - Composite-Unsafe VQA: leaderboard

Metric: Both-Safe rate (%) on the 314 composite-unsafe visual question answering queries of Uni-SafeBench (individually benign image and text that are unsafe together), judged by the Uni-Judger framework (malicious-intent extractor plus safety detector on Qwen3-VL-8B-Instruct), a response counts as safe only when it is safe or a refusal in the context of the extracted intent and its own content is not intrinsically unsafe, mean over repeated judge runs; higher is better. Source: arxiv.org. Saturation forecast: Estimated already saturated. 14 models tracked.

Top models

#ModelScore
1GPT-4o92.7
2Qwen 2.5 VL 7B Instruct92.4

Interactive version: theaggregate.ai/benchmark?slug=uni-safebench-composite-unsafe-vqa · How It Works · Data refreshed daily, snapshot 2026-10-07.