AgentHazard (IFlow) - Data Exfiltration: leaderboard
Metric: Attack success rate (%) on the data exfiltration instances (unauthorized extraction of source code, environment variables, credentials or private data), with the model running inside the IFlow workflow-orchestration agent framework (built-in tool routing and execution control), over AgentHazard instances (harmful objectives embedded in locally legitimate multi-step workflows, ten risk categories and ten attack strategies; the evaluated runs cover 1,000 instances), judged on the full trajectory (round_all) by Gemini-3-Flash, which labels a trajectory harmful when it realizes the objective; backbones served through an OpenAI-compatible API; lower is better. Source: arxiv.org. 7 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | IFlow + Kimi-K2.5 | 74.8 |
| 2 | IFlow + Qwen2.5-Coder-32B-Instruct | 75.65 |
| 3 | IFlow + Qwen2.5-72B-Instruct | 78.3 |
| 4 | IFlow + Qwen3-32B | 79.1 |
| 5 | IFlow + Qwen3-VL-235B-A22B-Instruct | 80 |
| 6 | IFlow + GLM-4.6 | 84.3 |
| 7 | IFlow + Kimi-K2 | 88.7 |
Interactive version: theaggregate.ai/benchmark?slug=agenthazard-iflow-data-exfiltration · How It Works · Data refreshed daily, snapshot 2026-10-07.