AgentHazard (IFlow) - Privilege Escalation: leaderboard

Metric: Attack success rate (%) on the privilege escalation instances (escaping containment or obtaining elevated privileges), with the model running inside the IFlow workflow-orchestration agent framework (built-in tool routing and execution control), over AgentHazard instances (harmful objectives embedded in locally legitimate multi-step workflows, ten risk categories and ten attack strategies; the evaluated runs cover 1,000 instances), judged on the full trajectory (round_all) by Gemini-3-Flash, which labels a trajectory harmful when it realizes the objective; backbones served through an OpenAI-compatible API; lower is better. Source: arxiv.org. 7 models tracked.

Top models

#ModelScore
1IFlow + Qwen3-VL-235B-A22B-Instruct72.2
2IFlow + Qwen2.5-Coder-32B-Instruct73.2
3IFlow + Kimi-K2.577.3
4IFlow + Qwen2.5-72B-Instruct78.3
5IFlow + Qwen3-32B80.4
6IFlow + GLM-4.683.5
7IFlow + Kimi-K283.5

Interactive version: theaggregate.ai/benchmark?slug=agenthazard-iflow-privilege-escalation · How It Works · Data refreshed daily, snapshot 2026-10-07.