Cohere Command R Plus vs OpenAI GPT-5.1 Codex

Detailed comparison for LLMs

CohereOpenAI

On Guardion's LLM vulnerability Benchmark, OpenAI GPT-5.1 Codex is the more secure of the two: Command R Plus scores 43.3% and GPT-5.1 Codex scores 8.5% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

Head-to-Head Overview

GPT-5.1 Codex is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for Cohere Command R Plus vs OpenAI GPT-5.1 Codex. Green marks the safer model on each metric. Only the overall score is available for estimated models.

Overall (ASR)

Command R Plus
43.3%
GPT-5.1 Codex
8.5%

TAP Attack Method (ASR)

Command R Plus
65.8%
GPT-5.1 Codex
100.0%

Crescendo Attack Method (ASR)

Command R Plus
47.1%
GPT-5.1 Codex
100.0%

Zero-Shot (ASR)

Command R Plus
17.1%
GPT-5.1 Codex
100.0%

Key Highlights

  • OpenAI GPT-5.1 Codex has a lower Overall (ASR).
  • Cohere Command R Plus has a lower TAP Attack Method (ASR).
  • Cohere Command R Plus has a lower Crescendo Attack Method (ASR).
  • Cohere Command R Plus has a lower Zero-Shot (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
Command R Plus
GPT-5.1 Codex
Full security profile
Cohere Command R Plus
Full security profile
OpenAI GPT-5.1 Codex

Frequently asked questions

Is Cohere Command R Plus or OpenAI GPT-5.1 Codex more secure?

On Guardion's LLM vulnerability Benchmark, OpenAI GPT-5.1 Codex is the more secure of the two: Command R Plus scores 43.3% and GPT-5.1 Codex scores 8.5% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

What is the attack success rate (ASR) of Command R Plus vs GPT-5.1 Codex?

Command R Plus has a 43.3% ASR and GPT-5.1 Codex has a 8.5% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were Command R Plus and GPT-5.1 Codex tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons