Cohere Command R vs Google Gemini 2.5 Pro

Detailed comparison for LLMs

CohereGoogle

On Guardion's LLM vulnerability Benchmark, Google Gemini 2.5 Pro is the more secure of the two: Command R scores 32.9% and Gemini 2.5 Pro scores 16.1% on attack success rate (ASR) (lower is better).

Head-to-Head Overview

Gemini 2.5 Pro is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for Cohere Command R vs Google Gemini 2.5 Pro. Green marks the safer model on each metric.

Overall (ASR)

Command R
32.9%
Gemini 2.5 Pro
16.1%

TAP Attack Method (ASR)

Command R
56.7%
Gemini 2.5 Pro
27.5%

Crescendo Attack Method (ASR)

Command R
32.6%
Gemini 2.5 Pro
19.1%

Zero-Shot (ASR)

Command R
9.4%
Gemini 2.5 Pro
1.6%

Key Highlights

  • Google Gemini 2.5 Pro has a lower Overall (ASR).
  • Google Gemini 2.5 Pro has a lower TAP Attack Method (ASR).
  • Google Gemini 2.5 Pro has a lower Crescendo Attack Method (ASR).
  • Google Gemini 2.5 Pro has a lower Zero-Shot (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
Command R
Gemini 2.5 Pro
Full security profile
Cohere Command R
Full security profile
Google Gemini 2.5 Pro

Frequently asked questions

Is Cohere Command R or Google Gemini 2.5 Pro more secure?

On Guardion's LLM vulnerability Benchmark, Google Gemini 2.5 Pro is the more secure of the two: Command R scores 32.9% and Gemini 2.5 Pro scores 16.1% on attack success rate (ASR) (lower is better).

What is the attack success rate (ASR) of Command R vs Gemini 2.5 Pro?

Command R has a 32.9% ASR and Gemini 2.5 Pro has a 16.1% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were Command R and Gemini 2.5 Pro tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons