KSAFE-MM - Globally Shared Risks: leaderboard
Metric: Attack Success Rate (%; responses judged harmful by a GPT-5 nano or Qwen3-235B judge, KSAFE-MM-G, 1,650 image-query pairs; lower is better). Source: arxiv.org. Saturation forecast: Estimated already saturated. 12 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5 Nano | 13.3 |
| 2 | Phi-4 Multimodal Instruct | 28.8 |
| 3 | Qwen 3 VL 8B | 35.1 |
| 4 | Gemini 3.1 Flash Lite | 36.4 |
| 5 | Ministral 3 8B | 39.6 |
| 6 | Ministral 3 14B | 41.2 |
| 7 | Gemma 3 12B | 44.4 |
| 8 | Gemma 3 27B | 44.7 |
Interactive version: theaggregate.ai/benchmark?slug=ksafe-mm-globally-shared-risks · How It Works · Data refreshed daily, snapshot 2026-09-25.