← Models

Model profile

Qwen3 235B A22B

Alibabadeveloper
2025-04-29release date
#132 / 333Safety rank
#327 / 645Freedom rank

Evidence summary

Safety. Qwen3 235B A22B has an estimated Safety rank of #132; its 90% source-sensitivity interval is #45–#221. Its behavior-only rank is #123; company governance moves the combined estimate to #132. Published Safety evidence spans 32 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #248 of 248).

Freedom. Qwen3 235B A22B has an estimated Freedom rank of #327; its 90% source-sensitivity interval is #175–#430. Published Freedom evidence spans 16 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #1 of 248); its weakest is HELM Safety (anthropic_red_team, #75 of 80).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Finetunes

Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AgentDrive Safety Compliancescr#13 / 4892.5Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#22 / 800.79Source ↗official
Alignment Leaderboardcorrigibility#8 / 244.349Source ↗official
Alignment Leaderboardhonesty#14 / 243.581Source ↗official
Alignment Leaderboardnon_manipulation#10 / 243.523Source ↗official
Alignment Leaderboardrobustness#8 / 243.88Source ↗official
Alignment Leaderboardsafety#10 / 243.885Source ↗official
Alignment Leaderboardscheming#8 / 243.898Source ↗official
Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct#2 / 169Source ↗official
Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct#10 / 1676Source ↗official
BioTIERpermit_compliance_pct#7 / 5299.7Source ↗official
BioTIERrefuse_compliance_pct#41 / 5219.1Source ↗official
BullshitBench v2clear_pushback_rate#111 / 1170.045Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#51 / 10437.49Source ↗official
Concordia — Agentic-Misalignmentsafety_score#41 / 5462.5Source ↗official
Concordia — AirBench-Deceptionsafety_score#24 / 6387.78Source ↗official
Concordia — AirBench-Manipulationsafety_score#22 / 5693.33Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#27 / 6394.82Source ↗official
Concordia — APEsafety_score#41 / 556.281Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#45 / 6378.09Source ↗official
Concordia — DarkBenchsafety_score#46 / 5546.67Source ↗official
Concordia — Fortress-Biologicalsafety_score#40 / 5432.97Source ↗official
Concordia — Fortress-Chemicalsafety_score#41 / 5433.55Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#40 / 5445.21Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#23 / 4537.11Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#20 / 4532.33Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#26 / 452.667Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#23 / 4560.33Source ↗official
Concordia — MASKsafety_score#35 / 6258.16Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#22 / 6392.12Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#12 / 6338.72Source ↗official
Concordia — Shutdown-Resistancesafety_score#1 / 53100Source ↗official
Concordia — SOSBench-Biosafety_score#28 / 6387.37Source ↗official
Concordia — SOSBench-Chemsafety_score#14 / 6393.8Source ↗official
Confabulationsconfabulation_rate#22 / 5218.56Source ↗official
Emergent Collusionhigh_illegality_game_rate#10 / 130.57Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#223 / 2489.3Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#248 / 24843.33Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#193 / 24846.67Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#68 / 24698.14Source ↗official
FlagEval Safety and Valuesa1_qualified_rate#15 / 1871.76Source ↗official
FlagEval Safety and Valuesa2_qualified_rate#16 / 1873.77Source ↗official
FlagEval Safety and Valuesa3_qualified_rate#17 / 1875.56Source ↗official
FlagEval Safety and Valuesa4_qualified_rate#17 / 1878.27Source ↗official
FlagEval Safety and Valuesa5_qualified_rate#16 / 1865.07Source ↗official
FORTRESSaverage_risk_score#47 / 5061.39Source ↗official
FORTRESSover_refusal_score#2 / 490.98Source ↗official
HELM Safetyanthropic_red_team#2 / 800.999Source ↗official
HELM Safetybbq#20 / 800.962Source ↗official
HELM Safetyharmbench#37 / 800.796Source ↗official
HELM Safetysimple_safety_tests#1 / 801Source ↗official
HELM Safetyxstest#4 / 800.986Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#14 / 5427.99Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 690Source ↗official
LiveSecBenchethics#15 / 4360.81Source ↗official
LiveSecBenchfactuality#9 / 4369.98Source ↗official
LiveSecBenchlegality#11 / 4373.51Source ↗official
LiveSecBenchprivacy#10 / 4372.57Source ↗official
LiveSecBenchpsychological_health#11 / 4369.27Source ↗official
Manager Coercion Benchcoercion_ladder_depth#24 / 378.733Source ↗self run
MASKlying_probability_pct#32 / 5343.6Source ↗official
PacifAIstp_score#2 / 789.46Source ↗official
Shelleducation_jsr#5 / 140.492Source ↗official
Shellfinance_jsr#4 / 140.3Source ↗official
Shellmanagement_jsr#6 / 140.518Source ↗official
Social Welfare Function Benchmarkfairness#12 / 190.478Source ↗official
SOSBenchbiology_pvr#21 / 230.852Source ↗official
SOSBenchchemistry_pvr#20 / 230.76Source ↗official
SOSBenchmedicine_pvr#22 / 230.868Source ↗official
SOSBenchpharmacology_pvr#18 / 230.934Source ↗official
SOSBenchphysics_pvr#19 / 230.764Source ↗official
SOSBenchpsychology_pvr#22 / 230.852Source ↗official
SpeciesismBenchexplicit_speciesism_scale#5 / 72.487Source ↗official
SpeciEvalbelief_animal_sentience#103 / 1236.45Source ↗official
SpeciEvalland_animal_4ns#74 / 1234.6Source ↗official
SpeciEvalsea_animal_4ns#113 / 1235.15Source ↗official
SpeciEvalspeciesism#76 / 1232.15Source ↗official
TACbase_welfare_rate#17 / 8735.9Source ↗self run
UAVBench safety-critical decision recognitionethical_safety_critical_accuracy#4 / 270.755Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#41 / 9490.7Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#59 / 800.79Source ↗official
BioTIERpermit_compliance_pct#7 / 5299.7Source ↗official
BioTIERrefuse_compliance_pct#12 / 5219.1Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#54 / 10437.49Source ↗official
Concordia — AirBench-Deceptionsafety_score#40 / 6387.78Source ↗official
Concordia — AirBench-Manipulationsafety_score#35 / 5693.33Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#30 / 5666.19Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#37 / 6394.82Source ↗official
Concordia — Fortress-Biologicalsafety_score#15 / 5432.97Source ↗official
Concordia — Fortress-Chemicalsafety_score#14 / 5433.55Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#15 / 5445.21Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#23 / 4537.11Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#26 / 4532.33Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#19 / 452.667Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#23 / 4560.33Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#42 / 6392.12Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#52 / 6338.72Source ↗official
Concordia — SOSBench-Biosafety_score#36 / 6387.37Source ↗official
Concordia — SOSBench-Chemsafety_score#50 / 6393.8Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#1 / 24843.33Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#55 / 24846.67Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#179 / 24698.14Source ↗official
FORTRESSaverage_risk_score#4 / 5061.39Source ↗official
FORTRESSover_refusal_score#2 / 490.98Source ↗official
HELM Safetyanthropic_red_team#75 / 800.999Source ↗official
HELM Safetyharmbench#44 / 800.796Source ↗official
HELM Safetysimple_safety_tests#58 / 801Source ↗official
HELM Safetyxstest#4 / 800.986Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 690Source ↗official
LiveSecBenchethics#29 / 4360.81Source ↗official
LiveSecBenchlegality#33 / 4373.51Source ↗official
LiveSecBenchprivacy#34 / 4372.57Source ↗official
LiveSecBenchpsychological_health#33 / 4369.27Source ↗official
Shelleducation_jsr#10 / 140.492Source ↗official
Shellfinance_jsr#11 / 140.3Source ↗official
Shellmanagement_jsr#9 / 140.518Source ↗official
SOSBenchbiology_pvr#3 / 230.852Source ↗official
SOSBenchchemistry_pvr#4 / 230.76Source ↗official
SOSBenchmedicine_pvr#2 / 230.868Source ↗official
SOSBenchpharmacology_pvr#5 / 230.934Source ↗official
SOSBenchphysics_pvr#5 / 230.764Source ↗official
SOSBenchpsychology_pvr#2 / 230.852Source ↗official
SpeechMap model completioncomplete_pct#119 / 18147.6Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#54 / 1563.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#113 / 1562Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-26
Government46.9
Diplomacy69
Economy48.1
Society64.3