textOpenSafetyLab/Salad-Datallm-safetyjailbreakred-teamingevaluationalignmentharmful-promptsbenchmarkapache-2.0

Salad-Data LLM Safety Evaluation Benchmark

Free

Open dataset

Sample structure: 100 / 100
3 download links issued
Seller: DataBazaar
Sign up to download

Already have an account? Log in

Agent? Connect your account →

Category
Text
Records
30,358 rows
Format
PARQUET
Update Frequency
Not documented
Collection Method
auto_imported_huggingface_federated
PII
No flagged field names; not a privacy audit
File Size
~5.79 MB
Download links issued
3

Source, license and coverage

Supplier documentation. These claims are separate from the automated sample score. A listing edit date is not a data freshness date.

License
apache-2.0
Source / creator
OpenSafetyLab/Salad-Data
Collection method
The authors aggregated harmful prompts from eight existing open-source safety benchmarks (15,885 prompts) and augmented them with 15,433 self-instructed prompts generated by a fine-tuned GPT-3.5 to broaden coverage across a hierarchical 3-level harm taxonomy (6 domains → 16 tasks → 66 categories). Prompts were deduplicated and categorized; the paper also introduces attack-enhanced and defense-enhanced variants generated by applying jailbreak templates to the base set.
Coverage start
Not documented
Coverage end
Not documented
Data last updated
Not documented
Update schedule
Not documented

Source documentation ↗

License terms ↗

Primarily English with a small multilingual subset (230 prompts); harm taxonomy reflects authors' choices and may not align with other safety frameworks. Self-instructed prompts inherit GPT-3.5 biases. Dataset is from early 2024 — newer jailbreak techniques (e.g., recent multi-turn or vision-based attacks) are not represented. Significant overlap with widely-used benchmarks (AdvBench, HH-RLHF) means leakage risk if used to train models that will be evaluated on those benchmarks.

Sample structure score: 100 / 100

This automated check describes the inspected sample, not factual accuracy, legal rights, representativeness, or the quality of the entire dataset. It is not a customer rating.

Assessed 10 sample records (JSON) on 2026-10-09. All records in the provided sample were checked.

CheckPointsEvidence
Populated cells50 / 5080 of 80 top-level cells contain a value. Null, absent and blank values count as missing; zero and false count as populated.
Consistent value types30 / 3080 of 80 populated cells match their column's most common observed type. Types are inferred, not checked against real-world truth.
Consistent record shape20 / 2010 of 10 records have the expected fields. CSV/TSV use the header width; JSON uses the union of observed keys.
Field-level findings and improvements

Check missing cells and mixed types below. Document intentional missing values or mixed types in your field descriptions. Do not fill legitimate unknowns with invented values just to increase this score.

FieldMissing cellsMost common typeOther populated types
3-category0 / 10string0 / 10
daugq0 / 10string0 / 10
qid0 / 10number0 / 10
dmethod0 / 10string0 / 10
baseq0 / 10string0 / 10
2-category0 / 10string0 / 10
1-category0 / 10string0 / 10
did0 / 10number0 / 10
How the score is calculated, its limitations, and how to correct an assessment →

About this data

Aggregated safety questions for LLM red-teaming and jailbreak evaluation, sourced from HH-RLHF, AdvBench, ToxicChat, GPTFuzzer, and GPT-3.5 self-instructed prompts.

Retrieve with your agent or Python

Create an account and configure DATABAZAAR_API_KEY. This example retrieves free or already purchased data; it never makes a purchase. For a multi-file dataset, choose a file index from the manifest.

Download the Python example
python3 retrieve-dataset.py bae7e438-2cf7-4e24-9969-c5f10cac48e9 --output dataset.bin
Full supplier documentation
## Overview Salad-Data is a safety evaluation dataset for large language models containing 21,318 harmful or sensitive prompts curated for red-teaming, jailbreak detection, and safety alignment research. The base set aggregates prompts from multiple established safety benchmarks plus GPT-3.5-generated self-instructed examples. Format is JSON; modalities are tabular/text. Released alongside the SALAD-Bench paper (arXiv:2402.05044). ## Schema - `question` — string — the harmful/sensitive prompt to test the model with - `qid` — string/int — unique question identifier - `source` — string — origin source (HH-harmless, AdvBench, ToxicChat, GPTFuzzer, self-instructed, etc.) - `1-category` — string — top-level harm taxonomy label - `2-category` — string — mid-level harm category - `3-category` — string — fine-grained harm category - Multiple subsets available via `name=` parameter (e.g., `base_set`, attack-enhanced sets, MCQ sets) ## Sources - HuggingFace: https://huggingface.co/datasets/OpenSafetyLab/Salad-Data — Apache-2.0 - Underlying sources: Anthropic HH-RLHF (harmless + red-team splits), AdvBench, Do-Not-Answer, ToxicChat, GPTFuzzer, Do Anything Now (DAN), Multilingual safety prompts, plus GPT-3.5 self-instructed generation - Paper: SALAD-Bench (arXiv:2402.05044) ## Methodology The authors aggregated harmful prompts from eight existing open-source safety benchmarks (15,885 prompts) and augmented them with 15,433 self-instructed prompts generated by a fine-tuned GPT-3.5 to broaden coverage across a hierarchical 3-level harm taxonomy (6 domains → 16 tasks → 66 categories). Prompts were deduplicated and categorized; the paper also introduces attack-enhanced and defense-enhanced variants generated by applying jailbreak templates to the base set. ## Known gaps & limitations Primarily English with a small multilingual subset (230 prompts); harm taxonomy reflects authors' choices and may not align with other safety frameworks. Self-instructed prompts inherit GPT-3.5 biases. Dataset is from early 2024 — newer jailbreak techniques (e.g., recent multi-turn or vision-based attacks) are not represented. Significant overlap with widely-used benchmarks (AdvBench, HH-RLHF) means leakage risk if used to train models that will be evaluated on those benchmarks. ## Intended use & out-of-scope - **For**: LLM safety evaluation, red-team testing, jailbreak detection research, safety classifier training, RLHF data augmentation - **Not for**: training general-purpose chatbots without safety filtering; benchmarking against AdvBench/HH-RLHF (leakage); production content moderation without additional validation _Federated dataset: 4 parquet shards, 5.8 MB total. Queries and downloads stream through the DataBazaar API._ Original supplier listing: Salad-Data: LLM Safety & Jailbreak Evaluation Benchmark 21K+ safety questions for LLM red-teaming and jailbreak evaluation, aggregated from HH-RLHF, AdvBench, ToxicChat, GPTFuzzer, and GPT-3.5 self-instructed prompts. Apache-2.0 licensed.

Schema

NameTypeDescription
3-categoryVARCHARFine-grained harm category label (e.g., O12: Religious Stereotyping, O42: Scams)
daugqVARCHARAugmented/jailbreak variant of the base question with defensive prompt injection technique applied
qidBIGINTUnique question identifier linking base and augmented versions
dmethodVARCHARJailbreak/defense method name applied to generate the augmented prompt (e.g., reminder_prompt, xsafe_prompt)
baseqVARCHAROriginal harmful or sensitive prompt without augmentation or jailbreak attempt
2-categoryVARCHARMid-level harm category label (e.g., O2: Unfair Representation, O12: Fraud or Deceptive Action)
1-categoryVARCHARTop-level harm taxonomy label (e.g., O1: Representation & Toxicity, O5: Malicious Use)
didBIGINTUnique identifier for the augmented question/defense pair

Sample Data

Preview a sample of the data before downloading.

Public sample only. Sign in to retrieve the full dataset, including free datasets.

For AI Agents

Via MCP Server
# 1. Add to your agent's MCP config (claude_desktop_config.json or similar):
{
  "mcpServers": {
    "databazaar": { "command": "npx", "args": ["databazaar-mcp"] }
  }
}

# 2. Your agent can then call:
search_datasets({ query: "Salad-Data LLM Safety Evaluati" })
// Found: bae7e438-2cf7-4e24-9969-c5f10cac48e9
get_download_url({ dataset_id: "bae7e438-2cf7-4e24-9969-c5f10cac48e9" })  // free — sign in with MCP OAuth first
Via REST API
# Free dataset — sign in or use your account API key:
curl https://api.databazaar.io/datasets/bae7e438-2cf7-4e24-9969-c5f10cac48e9/download-url -H "Authorization: Bearer $DATABAZAAR_API_KEY"