Model profile
Llama 2 13B Chat
Evidence summary
Llama 2 13B Chat has an estimated overall rank of #164; its 90% source-sensitivity interval is #61–#214. Its behavior-only rank is #149; company governance moves the combined estimate to #164. Published evidence spans 8 evals and 6 of 7 behavior components. Its strongest relative result is OR-Bench (toxic_acceptance_rate, #2 of 25); its weakest is SafetyBench (OFF, #20 of 21).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- OpenRouter ↗meta-llama/llama-2-13b-chat
- Official model page ↗Family-level model document · meta · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #211 / 260 | 11.11 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #58 / 260 | 91.83 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #61 / 260 | 88.33 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #26 / 258 | 99.55 | ↑ higher | Source ↗official | |
| HarmBenchdr | #4 / 28 | 2.8 | ↓ lower | Source ↗official | |
| JailBenchjailbreak_success_rate | #6 / 14 | 55.39 | ↓ lower | Source ↗official | |
| OR-Benchover_refusal_rate | #20 / 25 | 91 | ↓ lower | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #2 / 25 | 0.3 | ↓ lower | Source ↗official | |
| S-Evalbase_en_overall | #2 / 22 | 85.1 | ↑ higher | Source ↗official | |
| SafetyBenchEM | #17 / 21 | 54.6 | ↑ higher | Source ↗official | |
| SafetyBenchIA | #15 / 21 | 68.5 | ↑ higher | Source ↗official | |
| SafetyBenchMH | #15 / 21 | 73.6 | ↑ higher | Source ↗official | |
| SafetyBenchOFF | #20 / 21 | 48.4 | ↑ higher | Source ↗official | |
| SafetyBenchPH | #16 / 21 | 60.7 | ↑ higher | Source ↗official | |
| SafetyBenchPP | #16 / 21 | 70.1 | ↑ higher | Source ↗official | |
| SafetyBenchUB | #5 / 21 | 66.3 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #4 / 33 | 62.72 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #4 / 33 | 71.01 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #5 / 33 | 62.56 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #4 / 33 | 70.23 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #5 / 33 | 65.85 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #4 / 33 | 68.4 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #4 / 33 | 98.43 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #16 / 33 | 94.92 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_malicious_use | #7 / 33 | 97.98 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #4 / 33 | 97.64 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #4 / 33 | 95.71 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #13 / 33 | 91.19 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_human_autonomy_integrity | #26 / 33 | 10.28 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_information_safety_harms | #23 / 33 | 17.5 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_malicious_use | #26 / 33 | 7.885 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_misinformation_harms | #26 / 33 | 10.95 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_representation_toxicity | #26 / 33 | 8.229 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_socioeconomic_harms | #26 / 33 | 12.78 | ↑ higher | Source ↗official | |
| SORRY-Benchavg | #15 / 51 | 0.15 | ↓ lower | Source ↗official |