Moonshot AI Kimi K2-Thinking-0905 vs xAI Grok-4 Heavy

Detailed comparison for LLMs

Moonshot AIxAI

On Guardion's LLM vulnerability Benchmark, xAI Grok-4 Heavy is the more secure of the two: Kimi K2-Thinking-0905 scores 38.0% and Grok-4 Heavy scores 18.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

Head-to-Head Overview

Grok-4 Heavy is the overall winner in this comparison!

Attack Success Rate (lower is safer)

ASR for Moonshot AI Kimi K2-Thinking-0905 vs xAI Grok-4 Heavy. Green marks the safer model on each metric. Only the overall score is available for estimated models.

Overall (ASR)

Kimi K2-Thinking-0905
38.0%
Grok-4 Heavy
18.0%

TAP Attack Method (ASR)

Kimi K2-Thinking-0905
100.0%
Grok-4 Heavy
100.0%

Crescendo Attack Method (ASR)

Kimi K2-Thinking-0905
100.0%
Grok-4 Heavy
100.0%

Zero-Shot (ASR)

Kimi K2-Thinking-0905
100.0%
Grok-4 Heavy
100.0%

Key Highlights

  • xAI Grok-4 Heavy has a lower Overall (ASR).

Security Profile

Outward is better on every axis.

OverallTAPCrescendoZero-Shot
Kimi K2-Thinking-0905
Grok-4 Heavy
Full security profile
Moonshot AI Kimi K2-Thinking-0905
Full security profile
xAI Grok-4 Heavy

Frequently asked questions

Is Moonshot AI Kimi K2-Thinking-0905 or xAI Grok-4 Heavy more secure?

On Guardion's LLM vulnerability Benchmark, xAI Grok-4 Heavy is the more secure of the two: Kimi K2-Thinking-0905 scores 38.0% and Grok-4 Heavy scores 18.0% on attack success rate (ASR) (lower is better). One or both scores are estimated from public safety evaluations pending a Guardion benchmark run.

What is the attack success rate (ASR) of Kimi K2-Thinking-0905 vs Grok-4 Heavy?

Kimi K2-Thinking-0905 has a 38.0% ASR and Grok-4 Heavy has a 18.0% ASR — the share of adversarial prompts that succeed across zero-shot, TAP, and Crescendo attacks. Lower is safer.

How were Kimi K2-Thinking-0905 and Grok-4 Heavy tested?

Both were red-teamed with the HarmBench framework across zero-shot, TAP (Tree of Attacks with Pruning), and Crescendo multi-turn attacks, scored by Attack Success Rate.

Related Comparisons