Model profile
Evidence summary
Safety. Gemini 1.5 Flash has an estimated Safety rank of #121; its 90% source-sensitivity interval is #40–#202. Its behavior-only rank is #128; company governance moves the combined estimate to #121. Published Safety evidence spans 17 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (anthropic_red_team, #2 of 80); its weakest is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #205 of 246).
Freedom. Gemini 1.5 Flash has an estimated Freedom rank of #441; its 90% source-sensitivity interval is #252–#558. Published Freedom evidence spans 12 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #42 of 246); its weakest is HELM Safety (anthropic_red_team, #75 of 80).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gemini-1-5-flash
- Official model documentation ↗Family-level model document · google · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Robustnessscore | #4 / 8 | ↓14 | Source ↗official | |
| Agent-SafetyBenchcompromise_availability | #9 / 16 | ↑30 | Source ↗official | |
| Agent-SafetyBenchharmful_vulnerable_code | #4 / 16 | ↑48.4 | Source ↗official | |
| Agent-SafetyBenchleak_sensitive_information | #5 / 16 | ↑39.2 | Source ↗official | |
| Agent-SafetyBenchphysical_harm | #6 / 16 | ↑38.8 | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #11 / 16 | ↑82.4 | Source ↗official | |
| Agent-SafetyBenchproperty_loss | #7 / 16 | ↑41.6 | Source ↗official | |
| Agent-SafetyBenchspread_unsafe_information | #4 / 16 | ↑20.8 | Source ↗official | |
| Agent-SafetyBenchviolate_law_ethics | #6 / 16 | ↑32 | Source ↗official | |
| AgentDojotargeted_attack_success_rate | #4 / 15 | ↓0.0787 | Source ↗official | |
| AgentDojoutility_under_attack | #11 / 15 | ↑0.333 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #31 / 80 | ↑0.7325 | Source ↗official | |
| AnimalHarmBenchscore | #3 / 10 | ↑0.05 | Source ↗official | |
| COMPL-AI AI-Identity Disclosurescore | #1 / 14 | ↑1 | Source ↗official | |
| COMPL-AI LLM RuLES Multi-Turn Rule Followingscore | #5 / 14 | ↑0.5169 | Source ↗official | |
| COMPL-AI TensorTrust Goal-Hijacking Resistancescore | #6 / 13 | ↑0.4923 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #191 / 248 | ↑12.14 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #146 / 248 | ↑86.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #163 / 248 | ↑55.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #205 / 246 | ↑90.59 | Source ↗official | |
| FinEval Financial Security Knowledgefinancial_security_accuracy_pct | #6 / 19 | ↑77.5 | Source ↗official | |
| FORTRESSaverage_risk_score | #36 / 50 | ↓50.61 | Source ↗official | |
| FORTRESSover_refusal_score | #24 / 49 | ↓4.45 | Source ↗official | |
| HELM Safetyanthropic_red_team | #2 / 80 | ↑0.999 | Source ↗official | |
| HELM Safetybbq | #32 / 80 | ↑0.947 | Source ↗official | |
| HELM Safetyharmbench | #35 / 80 | ↑0.8 | Source ↗official | |
| HELM Safetysimple_safety_tests | #58 / 80 | ↑0.97 | Source ↗official | |
| HELM Safetyxstest | #66 / 80 | ↑0.921 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #23 / 39 | ↓1.116 | Source ↗official | |
| OR-Benchover_refusal_rate | #17 / 25 | ↓84.3 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #8 / 25 | ↓1.2 | Source ↗official | |
| SORRY-Benchavg | #5 / 51 | ↓0.08 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Robustnessscore | #5 / 8 | ↑14 | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #6 / 16 | ↓82.4 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #50 / 80 | ↓0.7325 | Source ↗official | |
| COMPL-AI LLM RuLES Multi-Turn Rule Followingscore | #10 / 14 | ↓0.5169 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #101 / 248 | ↓86.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #81 / 248 | ↓55.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #42 / 246 | ↓90.59 | Source ↗official | |
| FORTRESSaverage_risk_score | #15 / 50 | ↑50.61 | Source ↗official | |
| FORTRESSover_refusal_score | #24 / 49 | ↓4.45 | Source ↗official | |
| HELM Safetyanthropic_red_team | #75 / 80 | ↓0.999 | Source ↗official | |
| HELM Safetyharmbench | #46 / 80 | ↓0.8 | Source ↗official | |
| HELM Safetysimple_safety_tests | #20 / 80 | ↓0.97 | Source ↗official | |
| HELM Safetyxstest | #66 / 80 | ↑0.921 | Source ↗official | |
| OR-Benchover_refusal_rate | #17 / 25 | ↓84.3 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #18 / 25 | ↑1.2 | Source ↗official | |
| SORRY-Benchavg | #45 / 51 | ↑0.08 | Source ↗official |
