The AI arena is free today

Open Superagent

AttaQ

Paper

Progress Over Time

Interactive timeline showing model performance evolution on AttaQ

State-of-the-art frontier
Open
Proprietary

AttaQ Leaderboard

3 models
ContextCostLicense
18B
18B
37B
Notice missing or incorrect data?
About this benchmark

What is AttaQ?

AttaQ is a unique dataset containing adversarial examples in the form of questions designed to provoke harmful or inappropriate responses from large language models. The benchmark evaluates safety vulnerabilities by using specialized clustering techniques that analyze both the semantic similarity of input attacks and the harmfulness of model responses, facilitating targeted improvements to model safety mechanisms.

AttaQ is a text benchmark evaluating models on safety tasks. LLM Stats tracks 3 models on this benchmark, scored on a 0–1 scale. The current average is 0.9, with the leader at 0.9.

Compare leaders on the best AI for safety leaderboards.

Current leaders

Granite 3.3 8B Base from IBM currently leads the AttaQ leaderboard with a score of 0.885 across 3 evaluated AI models.

Source paper

Title
Unveiling Safety Vulnerabilities of Large Language Models
Authors
George Kour, Marcel Zalmanovici, Naama Zwerdling, Esther Goldbraich, and 4 others
Published
Abstract

As large language models become more prevalent, their possible harmful or inappropriate responses are a cause for concern. This paper introduces a unique dataset containing adversarial examples in the form of questions, which we call AttaQ, designed to provoke such harmful or inappropriate responses. We assess the efficacy of our dataset by analyzing the vulnerabilities of various models when subjected to it. Additionally, we introduce a novel automatic approach for identifying and naming vulnerable semantic regions - input semantic areas for which the model is likely to produce harmful outputs. This is achieved through the application of specialized clustering techniques that consider both the semantic similarity of the input attacks and the harmfulness of the model's responses. Automatically identifying vulnerable semantic regions enhances the evaluation of model weaknesses, facilitating targeted improvements to its safety mechanisms and overall reliability.

FAQ

Common questions about the AttaQ benchmark and leaderboard.

What is the AttaQ benchmark?

AttaQ is a unique dataset containing adversarial examples in the form of questions designed to provoke harmful or inappropriate responses from large language models. The benchmark evaluates safety vulnerabilities by using specialized clustering techniques that analyze both the semantic similarity of input attacks and the harmfulness of model responses, facilitating targeted improvements to model safety mechanisms.

What is the AttaQ leaderboard?

The AttaQ leaderboard ranks 3 AI models based on their performance on this benchmark. Currently, Granite 3.3 8B Base by IBM leads with a score of 0.885. The average score across all models is 0.877.

What is the highest AttaQ score?

The highest AttaQ score is 0.885, achieved by Granite 3.3 8B Base from IBM.

How many models are evaluated on AttaQ?

3 models have been evaluated on the AttaQ benchmark, with 0 verified results and 3 self-reported results.

Where can I find the AttaQ paper?

The AttaQ paper is available at https://arxiv.org/abs/2311.04124. The paper details the methodology, dataset construction, and evaluation criteria.

What categories does AttaQ cover?

AttaQ is categorized under safety. The benchmark evaluates text models.

What is the best open-source model on AttaQ?

Granite 3.3 8B Base by IBM is the top-ranked open-source model on AttaQ, with a score of 0.885 (rank #1).

How recent are the AttaQ leaderboard results?

The AttaQ leaderboard was last updated in August 2026 and currently includes 3 evaluated models.