Model profile
Evidence summary
Safety. Phi 2 has an estimated Safety rank of #256; its 90% source-sensitivity interval is #110–#323. Its behavior-only rank is #259; company governance moves the combined estimate to #256. Published Safety evidence spans 3 eval lineages and 3 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (bias_attack_non_success_rate, #46 of 248); its weakest is Microsoft Phi Safety Panels (harmful_continuation, #10 of 10).
Freedom. Phi 2 has an estimated Freedom rank of #24; its 90% source-sensitivity interval is #9–#223. Published Freedom evidence spans 3 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #3 of 248); its weakest is Microsoft Phi Safety Panels (third_party_harm, #8 of 10).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Microsoft Phi-2 ↗Exact model document · huggingface · official repository
- Release source ↗curated outward evidence
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #46 / 248 | ↑31.52 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #161 / 248 | ↑85.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #246 / 248 | ↑21.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #244 / 246 | ↑56.36 | Source ↗official | |
| Microsoft Phi Safety Panelsharmful_continuation | #10 / 10 | ↓0.029 | Source ↗official | |
| Microsoft Phi Safety Panelsharmful_summarization | #9 / 10 | ↓0.144 | Source ↗official | |
| Microsoft Phi Safety Panelsjailbreak | #8 / 10 | ↓0.15 | Source ↗official | |
| Microsoft Phi Safety Panelsthird_party_harm | #2 / 10 | ↓0.24 | Source ↗official | |
| Open LLM Safety Indexjailbreakbench_safety_rate | #16 / 21 | ↑0.1333 | Source ↗official | |
| Open LLM Safety Indexstrongreject_safety_rate | #19 / 21 | ↑0 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #88 / 248 | ↓85.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #3 / 248 | ↓21.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #3 / 246 | ↓56.36 | Source ↗official | |
| Microsoft Phi Safety Panelsharmful_continuation | #1 / 10 | ↑0.029 | Source ↗official | |
| Microsoft Phi Safety Panelsharmful_summarization | #2 / 10 | ↑0.144 | Source ↗official | |
| Microsoft Phi Safety Panelsjailbreak | #3 / 10 | ↑0.15 | Source ↗official | |
| Microsoft Phi Safety Panelsthird_party_harm | #8 / 10 | ↑0.24 | Source ↗official | |
| Open LLM Safety Indexjailbreakbench_safety_rate | #4 / 21 | ↓0.1333 | Source ↗official | |
| Open LLM Safety Indexstrongreject_safety_rate | #1 / 21 | ↓0 | Source ↗official |