Model profile
Evidence summary
Gemma 2 9B It has an estimated overall rank of #203; its 90% source-sensitivity interval is #82–#242. Its behavior-only rank is #212; company governance moves the combined estimate to #203. Published evidence spans 9 evals and 7 of 7 behavior components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #17 of 241); its weakest is Large-scale Moral Machine experiment on LLMs (human_choice_distance, #38 of 39).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗google/gemma-2-9b-it
- OpenRouter ↗google/gemma-2-9b-it
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AILuminate General Purpose AI Chatchild_sexual_exploitation | #4 / 32 | ↓6.7 | Source ↗official | |
| AILuminate General Purpose AI Chatdefamation | #7 / 32 | ↓8.5 | Source ↗official | |
| AILuminate General Purpose AI Chathate | #7 / 32 | ↓3.5 | Source ↗official | |
| AILuminate General Purpose AI Chatindiscriminate_weapons_cbrne | #8 / 32 | ↓12.8 | Source ↗official | |
| AILuminate General Purpose AI Chatintellectual_property | #8 / 32 | ↓5.8 | Source ↗official | |
| AILuminate General Purpose AI Chatnon_violent_crimes | #8 / 32 | ↓8.8 | Source ↗official | |
| AILuminate General Purpose AI Chatprivacy | #7 / 32 | ↓6.9 | Source ↗official | |
| AILuminate General Purpose AI Chatsex_related_crimes | #5 / 32 | ↓6.5 | Source ↗official | |
| AILuminate General Purpose AI Chatsexual_content | #6 / 32 | ↓6.4 | Source ↗official | |
| AILuminate General Purpose AI Chatspecialized_advice | #5 / 32 | ↓8 | Source ↗official | |
| AILuminate General Purpose AI Chatsuicide_self_harm | #6 / 32 | ↓5.8 | Source ↗official | |
| AILuminate General Purpose AI Chatviolent_crimes | #7 / 32 | ↓10.2 | Source ↗official | |
| COMPL-AI AI-Identity Disclosurescore | #5 / 14 | ↑0.9863 | Source ↗official | |
| COMPL-AI LLM RuLES Multi-Turn Rule Followingscore | #6 / 14 | ↑0.4996 | Source ↗official | |
| COMPL-AI TensorTrust Goal-Hijacking Resistancescore | #7 / 13 | ↑0.4858 | Source ↗official | |
| DSPSafeBenchscore | #8 / 12 | ↑72.34 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #117 / 241 | ↑16.02 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #17 / 241 | ↑95.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #81 / 241 | ↑81.11 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #231 / 239 | ↑70 | Source ↗official | |
| IndoBias-Pairs — parity-aware culturally grounded biasparity_score | #12 / 26 | ↑85.94 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #38 / 39 | ↓1.869 | Source ↗official | |
| OR-Benchover_refusal_rate | #16 / 25 | ↓79.9 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #9 / 25 | ↓1.5 | Source ↗official | |
| SORRY-Benchavg | #8 / 51 | ↓0.1 | Source ↗official | |
| SYCON Benchfalse_presupposition_tof | #10 / 11 | ↑1.86 | Source ↗official | |
| SYCON Benchunethical_queries_tof | #3 / 11 | ↑2.36 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
