AgentLAB - Memory Poisoning: leaderboard
Metric: Attack success rate (%) of memory poisoning: injected content persists the malicious task in the agent's memory for later execution (AgentLAB long-horizon attacks on tool-calling agents: 644 malicious tasks in 28 tool environments drawn from SHADE-Arena, AgentDojo, WebShop and Agent-SafetyBench (9 risk categories); a multi-agent attacker (GPT-5.1 planner, abliterated Qwen-3-14B attacker, GPT-5.1 internal judge) adapts its prompts or injected payloads over up to 7, 20, 15, 5 and 12 turns for the five attack types; system and tool-calling prompts adapted from AgentDojo and Agent-SafetyBench; no defense); lower is better. Source: arxiv.org. 6 models tracked.
Top models
| # | Model | Score | Overall rank |
|---|---|---|---|
| 1 | Claude Sonnet 4.5 | 38.8 | #138 |
| 2 | GPT-5.1 | 51.3 | #131 |
| 3 | GPT-4o | 63.3 | #333 |
| 4 | Gemini 3 Flash | 67.3 | #93 |
Interactive version: theaggregate.ai/benchmark?slug=agentlab-memory-poisoning · How It Works · Data refreshed daily, snapshot 2026-10-11.