DTap-Bench (Indirect Attacks) - Research: leaderboard

Metric: Attack success rate (%; 125 indirect red-teaming research tasks: third-party tool, skill and environment injections into a benign user task; an attack succeeds when a rule-based check of the final environment state finds the malicious goal fully achieved; fixed attack sequences that DTap-Red optimized on a surrogate agent; mean of its risk-category rates). Source: arxiv.org. Saturation forecast: Estimated already saturated. 8 models tracked.

Top models

#ModelScore
1GPT-5.27
2GPT-5.414.2
3Gemini 3 Pro16.2
4GPT-OSS-120B17.3

Interactive version: theaggregate.ai/benchmark?slug=dtap-bench-indirect-attacks-research · How It Works · Data refreshed daily, snapshot 2026-09-26.