Model profile
Evidence summary
Safety. GLM 5.3 has an estimated Safety rank of #33; its 90% source-sensitivity interval is #31–#88. Its behavior-only rank is #17; company governance moves the combined estimate to #33. Published Safety evidence spans 16 eval lineages and 6 of 7 components. Its strongest relative result is SM-Bench (anti_hallucination, #1 of 92); its weakest is Google Gemini 3.8 launch — Gray Swan indirect prompt injection k=15 (attack_success_probability_k15_pct, #10 of 15).
Freedom. GLM 5.3 has an estimated Freedom rank of #352; its 90% source-sensitivity interval is #144–#490. Published Freedom evidence spans 4 eval lineages and 1 of 1 components. Its strongest relative result is SM-Bench (overfit, #12 of 92); its weakest is SM-Bench (adversarial, #73 of 92).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗glm-5-3
- Hugging Face ↗zai-org/GLM-5.3
- OpenRouter ↗z-ai/glm-5.3
- Official model documentation ↗Family-level model document · zai · first party
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- audnai/penclaw-GLM-5.3-abliterated-for-offensive-cyber ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #31 / 358 | ↓0.2955 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #13 / 122 | ↑0.69 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #23 / 49 | ↓69.2 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #26 / 54 | ↓65.8 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #18 / 55 | ↓46.5 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #28 / 51 | ↓88.4 | Source ↗official | |
| CAIS Risk Indexmask | #15 / 57 | ↓10.1 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #26 / 51 | ↓46.8 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #10 / 54 | ↓14.8 | Source ↗official | |
| FORTRESSaverage_risk_score | #34 / 60 | ↓28.23 | Source ↗official | |
| FORTRESSover_refusal_score | #20 / 59 | ↓3.17 | Source ↗official | |
| Google Gemini 3.8 launch — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct | #10 / 15 | ↓31.5 | Source ↗official | |
| Olam Diplomacy — Broken Promise Ratebroken_promise_rate_pct | #8 / 19 | ↓13.4 | Source ↗official | |
| Pander Scoreconversational_absolute_pander_score | #12 / 26 | ↓10.37 | Source ↗official | |
| Pander Scoreinstructional_absolute_pander_score | #11 / 26 | ↓27.24 | Source ↗official | |
| SM-Benchadversarial | #18 / 92 | ↑86.34 | Source ↗official | |
| SM-Benchambiguous_interpretation | #14 / 92 | ↑90.77 | Source ↗official | |
| SM-Benchanti_hallucination | #1 / 92 | ↑100 | Source ↗official | |
| SM-Bencheq_boundaries | #23 / 92 | ↑69.66 | Source ↗official | |
| SM-Benchoverfit | #12 / 92 | ↑92.35 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #58 / 131 | ↑6.83 | Source ↗official | |
| SpeciEvalland_animal_4ns | #72 / 131 | ↓4.58 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #54 / 131 | ↓4.67 | Source ↗official | |
| SpeciEvalspeciesism | #77 / 131 | ↓2.1 | Source ↗official | |
| TACbase_welfare_rate | #36 / 92 | ↑29.49 | Source ↗self run |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| CAIS Risk Indexbioweapons_assistance | #29 / 54 | ↑65.8 | Source ↗official | |
| FORTRESSaverage_risk_score | #27 / 60 | ↑28.23 | Source ↗official | |
| FORTRESSover_refusal_score | #20 / 59 | ↓3.17 | Source ↗official | |
| SM-Benchadversarial | #73 / 92 | ↓86.34 | Source ↗official | |
| SM-Bencheq_boundaries | #23 / 92 | ↑69.66 | Source ↗official | |
| SM-Benchoverfit | #12 / 92 | ↑92.35 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #52 / 181 | ↑71.5 | Source ↗official |