Deepseek Deepseek R1 vs Mistral Mistral Large 3 675B Base

Detailed comparison for LLMs

DeepseekMistral

On Guardion's LLM vulnerability Benchmark, Deepseek Deepseek R1 is the more secure of the two: Deepseek R1 scores 42.6% and Mistral Large 3 675B Base scores 45.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

Head-to-Head Overview

Deepseek R1 is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for Deepseek Deepseek R1 vs Mistral Mistral Large 3 675B Base. Green marks the safer model on each metric. Only the overall score is available for estimated models.

Overall (ASR)

Deepseek R1
42.6%
Mistral Large 3 675B Base
45.0%

TAP Attack Method (ASR)

Deepseek R1
76.9%
Mistral Large 3 675B Base
100.0%

Crescendo Attack Method (ASR)

Deepseek R1
34.8%
Mistral Large 3 675B Base
100.0%

Zero-Shot (ASR)

Deepseek R1
16.1%
Mistral Large 3 675B Base
100.0%

Key Highlights

  • Deepseek Deepseek R1 has a lower Overall (ASR).
  • Deepseek Deepseek R1 has a lower TAP Attack Method (ASR).
  • Deepseek Deepseek R1 has a lower Crescendo Attack Method (ASR).
  • Deepseek Deepseek R1 has a lower Zero-Shot (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
Deepseek R1
Mistral Large 3 675B Base
Full security profile
Deepseek Deepseek R1
Full security profile
Mistral Mistral Large 3 675B Base

Frequently asked questions

Is Deepseek Deepseek R1 or Mistral Mistral Large 3 675B Base more secure?

On Guardion's LLM vulnerability Benchmark, Deepseek Deepseek R1 is the more secure of the two: Deepseek R1 scores 42.6% and Mistral Large 3 675B Base scores 45.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

What is the attack success rate (ASR) of Deepseek R1 vs Mistral Large 3 675B Base?

Deepseek R1 has a 42.6% ASR and Mistral Large 3 675B Base has a 45.0% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were Deepseek R1 and Mistral Large 3 675B Base tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons