BioSecBench-Refusal
Safety · 2026-06-30
Biosecurity refusal and over-refusal benchmark testing whether agents block genuinely harmful dual-use biology requests while still helping with benign research. The headline balanced score is the trial-weighted harmonic mean of red-team refusal rate and routine compliance rate, so a model must both refuse hazardous tasks and allow legitimate ones.
Top models (higher is better)
| Model | Score |
|---|---|
| Gemini 3.5 Flash | 51.5 |
| GPT-5.4 | 45.7 |
| Sonnet 4.6 | 43.5 |
| Gemini 3.1 Pro Preview | 43.0 |
| GPT-5.6 Sol | 39.5 |
| Opus 4.6 | 39.0 |
| GPT-5.5 | 37.1 |
| Opus 4.7 | 36.7 |
| GPT-5.6 Terra | 34.3 |
| GPT-5.6 Luna | 33.3 |
| Sonnet 5 | 30.1 |
| Opus 4.8 | 28.6 |
| Grok 4.3 | 12.9 |
| Grok 4.5 | 9.3 |
| Grok 4.20 | 3.1 |