DeepSeek DeepSeek R1 Distill Llama 8B vs Zhipu AI GLM-4.5-Air

Detailed comparison for LLMs

DeepSeekZhipu AI

On Guardion's LLM vulnerability Benchmark, Zhipu AI GLM-4.5-Air is the more secure of the two: DeepSeek R1 Distill Llama 8B scores 48.0% and GLM-4.5-Air scores 44.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

Head-to-Head Overview

GLM-4.5-Air is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for DeepSeek DeepSeek R1 Distill Llama 8B vs Zhipu AI GLM-4.5-Air. Green marks the safer model on each metric. Only the overall score is available for estimated models.

Overall (ASR)

DeepSeek R1 Distill Llama 8B
48.0%
GLM-4.5-Air
44.0%

TAP Attack Method (ASR)

DeepSeek R1 Distill Llama 8B
100.0%
GLM-4.5-Air
100.0%

Crescendo Attack Method (ASR)

DeepSeek R1 Distill Llama 8B
100.0%
GLM-4.5-Air
100.0%

Zero-Shot (ASR)

DeepSeek R1 Distill Llama 8B
100.0%
GLM-4.5-Air
100.0%

Key Highlights

  • Zhipu AI GLM-4.5-Air has a lower Overall (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
DeepSeek R1 Distill Llama 8B
GLM-4.5-Air
Full security profile
DeepSeek DeepSeek R1 Distill Llama 8B
Full security profile
Zhipu AI GLM-4.5-Air

Frequently asked questions

Is DeepSeek DeepSeek R1 Distill Llama 8B or Zhipu AI GLM-4.5-Air more secure?

On Guardion's LLM vulnerability Benchmark, Zhipu AI GLM-4.5-Air is the more secure of the two: DeepSeek R1 Distill Llama 8B scores 48.0% and GLM-4.5-Air scores 44.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

What is the attack success rate (ASR) of DeepSeek R1 Distill Llama 8B vs GLM-4.5-Air?

DeepSeek R1 Distill Llama 8B has a 48.0% ASR and GLM-4.5-Air has a 44.0% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were DeepSeek R1 Distill Llama 8B and GLM-4.5-Air tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons