Model profile
Evidence summary
Safety. DeepSeek v4 Pro has an estimated Safety rank of #141; its 90% source-sensitivity interval is #70–#287. Its behavior-only rank is #131; company governance moves the combined estimate to #141. Published Safety evidence spans 23 eval lineages and 7 of 7 components. Its strongest relative result is ANIMA (score, #1 of 22); its weakest is AgentAbstain (abstain, #17 of 17).
Freedom. DeepSeek v4 Pro has an estimated Freedom rank of #277; its 90% source-sensitivity interval is #143–#439. Published Freedom evidence spans 8 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is UGI Leaderboard — base-model willingness (willingness_direct_score, #113 of 156).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗deepseek-v4-pro
- Hugging Face ↗deepseek-ai/DeepSeek-V4-Pro
- NVIDIA ↗qc69jvmznzxy/deepseek-v4-pro
- OpenRouter ↗deepseek/deepseek-v4-pro
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗repository created at proxy
- huggingface.co ↗
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #245 / 345 | ↓0.8785 | Source ↗official | |
| AgentAbstainabstain | #17 / 17 | ↑42.8 | Source ↗official | |
| AgentAbstaincar | #16 / 17 | ↑42.3 | Source ↗official | |
| AgentAbstainpaired | #15 / 17 | ↑36.9 | Source ↗official | |
| ANIMAscore | #1 / 22 | ↑0.767 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #55 / 111 | ↑1437.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #35 / 52 | ↑98.5 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #35 / 52 | ↑22.6 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #89 / 117 | ↑0.14 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #17 / 48 | ↓44 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #46 / 54 | ↑54.83 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #47 / 63 | ↑70.37 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #45 / 56 | ↑74.67 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #50 / 63 | ↑80.18 | Source ↗official | |
| Concordia — APEsafety_score | #49 / 55 | ↑1.542 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #31 / 63 | ↑84.86 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #29 / 55 | ↑55.45 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #54 / 54 | ↑18.62 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #54 / 54 | ↑21.39 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #43 / 54 | ↑43.05 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #41 / 45 | ↑15.11 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #43 / 45 | ↑8.667 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #36 / 45 | ↑1.333 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #39 / 45 | ↑27.33 | Source ↗official | |
| Concordia — MASKsafety_score | #59 / 62 | ↑39.38 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #35 / 63 | ↑77.44 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #51 / 63 | ↑7.93 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #35 / 53 | ↑98.98 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #21 / 63 | ↑91.4 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #32 / 63 | ↑87.8 | Source ↗official | |
| DystopiaBenchbasaglia_score | #26 / 50 | ↓64.6 | Source ↗official | |
| DystopiaBenchbaudrillard_score | #31 / 50 | ↓62.2 | Source ↗official | |
| DystopiaBenchhuxley_score | #41 / 50 | ↓76.97 | Source ↗official | |
| DystopiaBenchlaguardia_score | #42 / 50 | ↓69.8 | Source ↗official | |
| DystopiaBenchorwell_score | #40 / 50 | ↓74 | Source ↗official | |
| DystopiaBenchpetrov_score | #36 / 50 | ↓77 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #141 / 248 | ↑14.73 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #182 / 248 | ↑82.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #101 / 248 | ↑77.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #188 / 246 | ↑92.55 | Source ↗official | |
| Every Model Cheats — Cybench Cheat Propensitybaseline_cheat_propensity_pct | #5 / 22 | ↓21.7 | Source ↗official | |
| Every Model Cheats — Cybench Cheat Propensitysevere_anti_cheat_cheat_propensity_pct | #1 / 22 | ↓0 | Source ↗official | |
| Every Model Cheats — Cybench Cheat Propensitystandard_anti_cheat_cheat_propensity_pct | #13 / 22 | ↓17.4 | Source ↗official | |
| Google Gemini 3.8 launch — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct | #15 / 15 | ↓60.1 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #20 / 54 | ↑27.61 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #33 / 37 | ↓9 | Source ↗official | |
| Manager Coercion Benchfabrication_rate | #1 / 15 | ↓0 | Source ↗official | |
| Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns | #12 / 24 | ↓9 | Source ↗official | |
| Opposite-Narrator Sycophancysycophancy_rate_pct | #17 / 24 | ↓5.1 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #66 / 66 | ↑0.1714 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #21 / 70 | ↑0.7964 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #22 / 70 | ↑0.9541 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #44 / 67 | ↑0.4321 | Source ↗official | |
| SM-Benchadversarial | #48 / 84 | ↑80.98 | Source ↗official | |
| SM-Benchambiguous_interpretation | #76 / 84 | ↑68.75 | Source ↗official | |
| SM-Benchanti_hallucination | #56 / 84 | ↑88.48 | Source ↗official | |
| SM-Bencheq_boundaries | #42 / 84 | ↑65.17 | Source ↗official | |
| SM-Benchoverfit | #40 / 84 | ↑76.5 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #63 / 123 | ↑6.8 | Source ↗official | |
| SpeciEvalland_animal_4ns | #36 / 123 | ↓4.35 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #43 / 123 | ↓4.65 | Source ↗official | |
| SpeciEvalspeciesism | #41 / 123 | ↓1.77 | Source ↗official | |
| TACbase_welfare_rate | #62 / 87 | ↑23.08 | Source ↗official | |
| The Dictatorship Evaloverall_resistance_rate | #18 / 20 | ↑11.65 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #39 / 94 | ↑91.4 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| BioTIERpermit_compliance_pct | #35 / 52 | ↑98.5 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #18 / 52 | ↓22.6 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #16 / 63 | ↓70.37 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #12 / 56 | ↓74.67 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #19 / 56 | ↓49.52 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #14 / 63 | ↓80.18 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #1 / 54 | ↓18.62 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #1 / 54 | ↓21.39 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #12 / 54 | ↓43.05 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #4 / 45 | ↓15.11 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #3 / 45 | ↓8.667 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #9 / 45 | ↓1.333 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #6 / 45 | ↓27.33 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #28 / 63 | ↓77.44 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #12 / 63 | ↓7.93 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #43 / 63 | ↓91.4 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #32 / 63 | ↓87.8 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #67 / 248 | ↓82.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #148 / 248 | ↓77.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #59 / 246 | ↓92.55 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #49 / 70 | ↓0.9541 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #24 / 67 | ↓0.4321 | Source ↗official | |
| SM-Benchadversarial | #35 / 84 | ↓80.98 | Source ↗official | |
| SM-Bencheq_boundaries | #42 / 84 | ↑65.17 | Source ↗official | |
| SM-Benchoverfit | #40 / 84 | ↑76.5 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #121 / 181 | ↑46.8 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #50 / 156 | ↑4.25 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.