← Models

Model profile

Gemma 3 12B

Googledeveloper
2025-03-10release date
#229 / 333Safety rank
#157 / 645Freedom rank

Evidence summary

Safety. Gemma 3 12B has an estimated Safety rank of #229; its 90% source-sensitivity interval is #37–#306. Its behavior-only rank is #241; company governance moves the combined estimate to #229. Published Safety evidence spans 9 eval lineages and 6 of 7 components. Its strongest relative result is Vectara HHEM Factual Consistency (factual_consistency_rate, #5 of 94); its weakest is PHARE (hallucination_resistance_diagnostic, #70 of 70).

Freedom. Gemma 3 12B has an estimated Freedom rank of #157; its 90% source-sensitivity interval is #79–#354. Published Freedom evidence spans 4 eval lineages and 1 of 1 components. Its strongest relative result is Cisco AI Defense Rolling Single-Turn Leaderboard (single_turn_attack_success_rate, #21 of 104); its weakest is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #175 of 246).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#342 / 3450.974Source ↗official
AgentDrive Safety Compliancescr#28 / 4877.5Source ↗official
AIMS Safety-Classifier Competenceaverage_harmful_f1#7 / 110.802Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#84 / 10465.55Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#163 / 24813.18Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#72 / 24890.67Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#180 / 24852.78Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#71 / 24698.05Source ↗official
KIDBench Implicit Child Cueimplicit_child_cue_total_mean#7 / 133.98Source ↗official
PHAREbias_resistance_diagnostic#60 / 660.3214Source ↗official
PHAREhallucination_resistance_diagnostic#70 / 700.5386Source ↗official
PHAREharm_resistance_diagnostic#39 / 700.9265Source ↗official
PHAREjailbreak_resistance_diagnostic#43 / 670.4427Source ↗official
ThaiSafetyBenchsafety_score#13 / 1879.6Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#5 / 9495.6Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#21 / 10465.55Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#175 / 24890.67Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#69 / 24852.78Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#175 / 24698.05Source ↗official
PHAREharm_resistance_diagnostic#32 / 700.9265Source ↗official
PHAREjailbreak_resistance_diagnostic#25 / 670.4427Source ↗official
ThaiSafetyBenchsafety_score#6 / 1879.6Source ↗official