The bench

We post our scores. Next to everyone else’s.

No “trusted by” logos, no theater — just results you can replay, on the one thing that matters: catching what’s actually hidden inside the AI entering your company.

The scored results — each with a witness a stranger can re-run — are posted on the coverage record, and a row lands only once it carries one.
Every off-the-shelf scannerreads the file, finds it valid, and clears it to ship — the backdoor is trained into the weights, so it never shows on the surface
Vulcorareads the weights on our own secure infrastructure and surfaces the hidden backdoor, with a proof you replay yourself

Same threat — hidden model backdoors — the same models, the same test.

0.976StrongPADBench-exp — qwen2vl_vqav2_r16
0.970StrongPADBench-exp — l2_loraplus_r8
0.953StrongPADBench llama3_8b (per-fam)
every score, with its uncertainty — and the misses beside the catches
Four readings, side by side

Us against the tools most companies use today.

One row per reading — what we read, next to what the usual tool misses.

Can it catch a backdoor hidden inside an AI model?

Vulcora

reads the weights against the model it was built from — proving what it was built to do, not just that something is there — and, where the class allows, reads the planted instruction itself back out, no secret phrase needed, without ever running the model

Typical model scanners

runs clean or can’t attach at all — the file looks like any other

On the model families we’ve mapped, measured against a matched reference. Reading the instruction back out is class-scoped — never a claim about every backdoor.

Can it catch an exploit in code your AI wrote?

Vulcora

reads what the code actually does when it runs and hands you the exploit as a proof you replay — or stays silent

Typical code scanners

passes most AI-written exploits as “clean”

A finding carries a witness; where it can’t prove one, it abstains rather than guess.

Can it tell when an agent broke its promise?

Vulcora

grades each agent against the checkable promise it made before it acted, and keeps the record — every win and every miss

Logs & monitors

shows what happened, never whether the deal was kept

Runs our own house today; opening to customers next.

Can it identify an unknown open model?

Vulcora

reads the model itself and tells you what it is and how it was changed from its base

Public leaderboards

ranks only what’s submitted — most models are never named

A reading of what a model is — never a safety or quality ranking.

How we keep score

Only what we can prove — counted in public.

Graded on public exams

The same tests researchers use — BackdoorLLM, PADBench, NIST TrojAI, TDC2023 — and against the free scanners anyone can download. Scores post here, failures included.

Every result carries proof

A row only counts once its result ships with a witness a stranger can re-run. Where we can’t prove a catch, we don’t count it.

Matched to a reference, or we abstain

We read a model against the one it was built from, on the families we’ve mapped — a scoped, honest catch, never a claim to catch everything.

See it for yourself

Don’t take the scoreboard’s word for it. Replay the record.