FORTRESS Average Risk Score (ARS)
Safety · 2025-06-17
Average Risk Score (ARS) across adversarial national-security and public-safety prompts; each response's harm score is the percentage of instance-specific rubric questions answered yes by a majority of three judges, and ARS averages those harm scores across prompts.
Top models (lower is better)
| Model | Score |
|---|---|
| gpt-oss-120b | 8.2 |
| Opus 4.5 | 9.6 |
| Muse Spark 1.1 | 12.4 |
| Sonnet 4.5 | 12.8 |
| Claude 3.5 Sonnet (June 2024) | 13.0 |
| Opus 4.6 | 13.0 |
| Opus 4.1 | 14.8 |
| GPT-5.4 Pro | 14.8 |
| GPT-5 Pro | 15.2 |
| o3 | 16.0 |
| GPT-5.5 | 16.3 |
| GPT-5 Mini | 17.0 |
| GPT-5 | 17.0 |
| GPT-5.2 | 17.5 |
| gpt-oss-20b | 17.6 |
| Sonnet 4 | 18.1 |
| Opus 4.8 | 18.2 |
| O1 | 19.4 |
| Muse Spark | 20.2 |
| Llama 3.1 405B | 20.6 |
| O4 Mini | 21.5 |
| Opus 4 | 24.8 |
| GPT-5.1 | 25.7 |
| Gemini 3.1 Pro Preview | 29.8 |
| o3-mini | 30.1 |
| GPT-5.1 Instant | 30.4 |
| Haiku 3.5 | 30.4 |
| Claude 3.7 Sonnet | 38.0 |
| Llama 4 Maverick Instruct | 40.1 |
| Kimi K2.5 | 41.1 |
| Gemini 3 Pro Preview | 41.7 |
| Llama 3.1 70B | 44.2 |
| Llama 3.3 70B Instruct | 44.8 |
| GPT-4o | 47.2 |
| GPT-4o Mini | 48.1 |
| Gemini 1.5 Flash 002 | 50.6 |
| Gemini 3.1 Flash-Lite Preview | 51.1 |
| GPT-4.1 | 53.0 |
| Gemini 1.5 Pro | 53.9 |
| Gemini 2.5 Pro Preview 03-25 | 54.9 |