Model profile
Llama 2 70B Chat
Evidence summary
Llama 2 70B Chat has an estimated overall rank of #192; its 90% source-sensitivity interval is #63–#233. Its behavior-only rank is #182; company governance moves the combined estimate to #192. Published evidence spans 7 evals and 6 of 7 behavior components. Its strongest relative result is OR-Bench (toxic_acceptance_rate, #2 of 25); its weakest is XSTest (safe_full_compliance_rate, #3 of 3).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- OpenRouter ↗meta-llama/llama-2-70b-chat
- Model card ↗Exact model document · Meta · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #195 / 260 | 12.4 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #125 / 260 | 88.5 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #63 / 260 | 87.78 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #21 / 258 | 99.64 | ↑ higher | Source ↗official | |
| HarmBenchdr | #4 / 28 | 2.8 | ↓ lower | Source ↗official | |
| OR-Benchover_refusal_rate | #23 / 25 | 96.1 | ↓ lower | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #2 / 25 | 0.3 | ↓ lower | Source ↗official | |
| S-Evalbase_en_overall | #5 / 22 | 77.2 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #5 / 33 | 62.28 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #5 / 33 | 68.4 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #4 / 33 | 66.15 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #5 / 33 | 62.17 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #4 / 33 | 68.62 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #5 / 33 | 60.17 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #6 / 33 | 98.25 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #4 / 33 | 99.19 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_malicious_use | #6 / 33 | 98.17 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #11 / 33 | 95.67 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #11 / 33 | 92.71 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #4 / 33 | 94.83 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_human_autonomy_integrity | #17 / 33 | 33.61 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_information_safety_harms | #19 / 33 | 30.83 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_malicious_use | #19 / 33 | 27.24 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_misinformation_harms | #18 / 33 | 30.95 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_representation_toxicity | #19 / 33 | 27.71 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_socioeconomic_harms | #18 / 33 | 31.67 | ↑ higher | Source ↗official | |
| SORRY-Benchavg | #11 / 51 | 0.12 | ↓ lower | Source ↗official | |
| XSTestsafe_full_compliance_rate | #3 / 3 | 0.704 | ↑ higher | Source ↗official | |
| XSTestunsafe_full_refusal_rate | #1 / 3 | 0.975 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.