Anthropic Claude 3.7 Sonnet vs DeepSeek DeepSeek-V3.2 Non-thinking

Detailed comparison for LLMs

AnthropicDeepSeek

On Guardion's LLM vulnerability Benchmark, Anthropic Claude 3.7 Sonnet is the more secure of the two: Claude 3.7 Sonnet scores 20.3% and DeepSeek-V3.2 Non-thinking scores 47.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

Head-to-Head Overview

Claude 3.7 Sonnet is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for Anthropic Claude 3.7 Sonnet vs DeepSeek DeepSeek-V3.2 Non-thinking. Green marks the safer model on each metric. Only the overall score is available for estimated models.

Overall (ASR)

Claude 3.7 Sonnet
20.3%
DeepSeek-V3.2 Non-thinking
47.0%

TAP Attack Method (ASR)

Claude 3.7 Sonnet
31.4%
DeepSeek-V3.2 Non-thinking
100.0%

Crescendo Attack Method (ASR)

Claude 3.7 Sonnet
25.3%
DeepSeek-V3.2 Non-thinking
100.0%

Zero-Shot (ASR)

Claude 3.7 Sonnet
DeepSeek-V3.2 Non-thinking
100.0%

Key Highlights

  • Anthropic Claude 3.7 Sonnet has a lower Overall (ASR).
  • Anthropic Claude 3.7 Sonnet has a lower TAP Attack Method (ASR).
  • Anthropic Claude 3.7 Sonnet has a lower Crescendo Attack Method (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
Claude 3.7 Sonnet
DeepSeek-V3.2 Non-thinking
Full security profile
Anthropic Claude 3.7 Sonnet
Full security profile
DeepSeek DeepSeek-V3.2 Non-thinking

Frequently asked questions

Is Anthropic Claude 3.7 Sonnet or DeepSeek DeepSeek-V3.2 Non-thinking more secure?

On Guardion's LLM vulnerability Benchmark, Anthropic Claude 3.7 Sonnet is the more secure of the two: Claude 3.7 Sonnet scores 20.3% and DeepSeek-V3.2 Non-thinking scores 47.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

What is the attack success rate (ASR) of Claude 3.7 Sonnet vs DeepSeek-V3.2 Non-thinking?

Claude 3.7 Sonnet has a 20.3% ASR and DeepSeek-V3.2 Non-thinking has a 47.0% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were Claude 3.7 Sonnet and DeepSeek-V3.2 Non-thinking tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons