Jailbreak StrongREJECT v2 (ASR)Browse 296

Jailbreak StrongREJECT v2 (ASR)

Can the model diagnose or complete difficult cybersecurity tasks?

Version not specifiedExact reported variant
Cybersecurity5 ranked models5 reported values1 reportsLower is better

Top rankings

One row per model, using its best reported score across effort settings.

5
RankModelBest scoreBest reported setting
1GPT-5.5OpenAI0.5%xhigh effortMeta report1 value · 1 reportJul 9, 2026 · source
2Muse Spark 1.1Meta0.5%xhigh effortMeta report1 value · 1 reportJul 9, 2026 · source
3Claude Opus 4.8Anthropic4.5%max effortMeta report1 value · 1 reportJul 9, 2026 · source
4Muse Spark 1.0Meta25.2%Reported configurationMeta report1 value · 1 reportJul 9, 2026 · source
5Gemini 3.1 ProGoogle51.0%high effortMeta report1 value · 1 reportJul 9, 2026 · source

Effort curve

Every sourced cost-linked effort value for this exact version. Lines connect complete sweeps only.

0
No cost-linked effort sweep for this version.
Definition and comparison boundarypublic methodology

Can the model diagnose or complete difficult cybersecurity tasks?

Security analysis or exploitation under a controlled evaluation environment. Lower is better. The source reports an attack success rate as a percentage.

Harness, tools, prompts, attempt count, and benchmark version can materially change the result. Compare within one reporting context.

Method / source