Anthropic Claude 3.5 Sonnet v2 vs Meta Llama 4 Scout

Detailed comparison for LLMs

AnthropicMeta

On Guardion's LLM vulnerability Benchmark, Anthropic Claude 3.5 Sonnet v2 is the more secure of the two: Claude 3.5 Sonnet v2 scores 4.4% and Llama 4 Scout scores 30.0% on attack success rate (ASR) (lower is better).

Head-to-Head Overview

Claude 3.5 Sonnet v2 is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for Anthropic Claude 3.5 Sonnet v2 vs Meta Llama 4 Scout. Green marks the safer model on each metric.

Overall (ASR)

Claude 3.5 Sonnet v2
4.4%
Llama 4 Scout
30.0%

TAP Attack Method (ASR)

Claude 3.5 Sonnet v2
8.8%
Llama 4 Scout
63.5%

Crescendo Attack Method (ASR)

Claude 3.5 Sonnet v2
3.8%
Llama 4 Scout
20.3%

Zero-Shot (ASR)

Claude 3.5 Sonnet v2
0.5%
Llama 4 Scout
6.1%

Key Highlights

  • Anthropic Claude 3.5 Sonnet v2 has a lower Overall (ASR).
  • Anthropic Claude 3.5 Sonnet v2 has a lower TAP Attack Method (ASR).
  • Anthropic Claude 3.5 Sonnet v2 has a lower Crescendo Attack Method (ASR).
  • Anthropic Claude 3.5 Sonnet v2 has a lower Zero-Shot (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
Claude 3.5 Sonnet v2
Llama 4 Scout
Full security profile
Anthropic Claude 3.5 Sonnet v2
Full security profile
Meta Llama 4 Scout

Frequently asked questions

Is Anthropic Claude 3.5 Sonnet v2 or Meta Llama 4 Scout more secure?

On Guardion's LLM vulnerability Benchmark, Anthropic Claude 3.5 Sonnet v2 is the more secure of the two: Claude 3.5 Sonnet v2 scores 4.4% and Llama 4 Scout scores 30.0% on attack success rate (ASR) (lower is better).

What is the attack success rate (ASR) of Claude 3.5 Sonnet v2 vs Llama 4 Scout?

Claude 3.5 Sonnet v2 has a 4.4% ASR and Llama 4 Scout has a 30.0% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were Claude 3.5 Sonnet v2 and Llama 4 Scout tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons