Visualizations
The filters below control all charts in sync; “Pin” locks a model for comparison.
Models
YuFeng-XGuard-Reason-8B
8B Sing-Guard-2b
2B HiveTraceGuard-Pro
0.6B Shieldstral-1.0-3B
3B OpenGuardrails-Text-2510
15B Qwen3Guard-Gen-8B
8B Qwen3Guard-Gen-4B
4B YuFeng-XGuard-Reason-0.6B
0.6B Llama-3.1-Nemotron-Safety-Guard-8B-v3
8B Qwen3Guard-Gen-0.6B
0.6B PolyGuard-Qwen-Smol
0.5B Nemotron-3.5-Content-Safety
4B opir-multitask-multilang-v1.0
0.3B opir-multitask-large-v1.0
0.4B Llama-Guard-3-8B
8B gliguard-LLMGuardrails-300M
0.3B Sing-Guard-4b
4B Llama-Guard-4-12B
12B Llama-Guard-3-1B
1B wildguard
7B HiveTraceLite
0.3B gliner-guard-omni
0.3B shieldgemma-2b
2B shieldgemma-9b
9B OpenGuardrails-Text-4B-0124
4B promptguard
0.1B gliner-guard-uniencoder
0.1B Nandi-Mini-600M-GuardRails
0.6B deberta-v3-base-injection
0.2B Nandi-Mini-150M-GuardRails
0.15B Llama-Prompt-Guard-2-86M
0.086B deberta-v3-base-prompt-injection-v2
0.2B Text-Moderation
0.1B deberta-v3-base-prompt-injection-detection
0.2B Llama-Prompt-Guard-2-22M
0.022B Groups / benchmarks
S-Eval en · ru
AEGIS 2.0 en
ToxicChat en
PolyGuard en · ru
RTP-LX en · ru
OR-Bench en
XSTest en
StrongReject++ en · ru · uk · be · uz
BeaverTails en
HarmBench en
MultiJail en
SimpleSafetyTests en
CSRT en
Aya Red Teaming en · ru
XSafety en
OpenAI Moderation en
Robustness Test (real) ru
Robustness Test (robust) ru
Prompt injection en · ru
Language
5 models · 19 groups Export CSV
Pinned for comparison Nothing pinned, press Pin in the Models list.
Group radar
scores of selected models by group · higher = betterS-Eval AEGIS 2.0 ToxicChat PolyGuard RTP-LX OR-Bench XSTest StrongReject++ BeaverTails HarmBench MultiJail SimpleSafetyTests CSRT Aya Red Teaming XSafety OpenAI Moderation Robustness Test (real) Robustness Test (robust) Prompt injection
YuFeng-XGuard-Reason-8B 8B Sing-Guard-2b 2B HiveTraceGuard-Pro 0.6B Shieldstral-1.0-3B 3B OpenGuardrails-Text-2510 15B
FPR × FNR
x = FPR, y = FNR · lower = better · ★ ideal (0,0)★ Ideal (0,0) - zero errors
Heatmap fnr
min 0.004 max 0.721FNR · group / model
YuFeng-XGuard-Reason-8B 8B
Sing-Guard-2b 2B
OpenGuardrails-Text-2510 15B
HiveTraceGuard-Pro 0.6B
Shieldstral-1.0-3B 3B
AEGIS 2.0 (prompt)
0.13
0.19
0.27
0.21
0.09
AEGIS 2.0 (response)
0.25
0.10
0.10
0.12
0.03
ToxicChat
0.51
0.48
0.56
0.58
0.41
PolyGuard (EN, request)
0.12
0.14
0.10
0.05
0.13
PolyGuard (EN, response)
0.15
0.11
0.05
0.14
0.19
PolyGuard (RU, request)
0.16
0.22
0.11
0.16
0.19
PolyGuard (RU, response)
0.20
0.13
0.05
0.14
0.20
RTP-LX (EN, request)
0.06
0.36
0.24
0.07
0.02
RTP-LX (RU, request)
0.11
0.38
0.15
0.19
0.11
RTP-LX (EN, response)
0.01
0.12
0.12
0.03
0.01
RTP-LX (RU, response)
0.01
0.07
0.06
0.03
0.02
XSTest
0.02
0.08
0.09
0.09
0.06
BeaverTails (response)
0.22
0.14
0.20
0.17
0.14
HarmBench (responses)
0.03
0.00
0.05
0.05
0.06
XSafety (EN)
0.55
0.63
0.72
0.54
0.52
OpenAI Moderation
0.02
0.07
0.13
0.15
0.02
Robustness Test — real (combined)
0.10
0.12
0.32
0.05
0.13
Robustness Test — responses real (combined)
0.43
0.28
0.38
0.16
0.34
Robustness Test — robust (combined)
0.21
0.24
0.40
0.13
0.24
Grouped bars
Recall / Precision / F1 by model · averages across selected groupsYuFeng-XGuard-Reason-8B 8B
Sing-Guard-2b 2B
HiveTraceGuard-Pro 0.6B
Shieldstral-1.0-3B 3B
OpenGuardrails-Text-2510 15B
Recall (higher = better) Precision (higher = better) F1 (higher = better)
Pareto: quality × latency
x = p95 latency (ms, lower = better), y = integral (higher = better)hover for details · dashed line = Pareto frontier
Latency performance
p50 / p95 / p99 (ms) · error rate HiveTraceGuard-Pro 0.6B | 14.3 | 28.8 | 37.6 | 0.0% |
Shieldstral-1.0-3B 3B | 14.7 | 32.2 | 44.9 | 0.0% |
Sing-Guard-2b 2B | 62.1 | 80.8 | 102.5 | 0.0% |
YuFeng-XGuard-Reason-8B 8B | 71.8 | 102.6 | 144.3 | 0.0% |
OpenGuardrails-Text-2510 15B | 63.2 | 127.1 | 181.3 | 0.0% |
Single-request latency percentiles.
Robustness real → robust
degradation under augmentation - who breaks on harder attacksDelta = robust - real. Delta score < 0: the model is not robust to obfuscations, > 0: robust. Delta FNR > 0: it misses harmful obfuscated messages more often (worse), < 0: it catches them more often (better). Delta FPR > 0: it blocks safe obfuscated messages more often (worse), < 0: it lets them pass more often (better).
| Model | score real | score robust | Δ score | FNR real | FNR robust | Δ FNR | FPR real | FPR robust | Δ FPR |
|---|---|---|---|---|---|---|---|---|---|
HiveTraceGuard-Pro 0.6B | 0.968 | 0.870 | −0.098 | 0.046 | 0.128 | +0.082 | 0.017 | 0.132 | +0.115 |
Sing-Guard-2b 2B | 0.931 | 0.849 | −0.082 | 0.119 | 0.241 | +0.122 | 0.012 | 0.036 | +0.024 |
Shieldstral-1.0-3B 3B | 0.909 | 0.834 | −0.075 | 0.133 | 0.238 | +0.105 | 0.044 | 0.078 | +0.035 |
YuFeng-XGuard-Reason-8B 8B | 0.933 | 0.870 | −0.063 | 0.104 | 0.214 | +0.109 | 0.026 | 0.027 | +0.001 |
OpenGuardrails-Text-2510 15B | 0.804 | 0.741 | −0.063 | 0.325 | 0.399 | +0.074 | 0.006 | 0.033 | +0.027 |