DTap-Bench (Direct Attacks) - Medical: leaderboard

Metric: Attack success rate (%; 229 direct red-teaming medical service tasks: the user is the attacker, with prompt, tool, skill and environment injections; an attack succeeds when a rule-based check of the final environment state finds the malicious goal fully achieved; fixed attack sequences that DTap-Red optimized on a surrogate agent; mean of its risk-category rates). Source: arxiv.org. Saturation forecast: Around 2031. 8 models tracked.

Top models

#ModelScore
1GPT-5.460.4
2GPT-OSS-120B61.3
3Gemini 3 Pro62.7
4GPT-5.271.1

Interactive version: theaggregate.ai/benchmark?slug=dtap-bench-direct-attacks-medical · How It Works · Data refreshed daily, snapshot 2026-09-26.