LongPIBench - Email Summary: leaderboard
Metric: Attack success rate (%; share of 100 long synthetic email threads to summarize with a draft reply; success when the summary contains the attacker's link, under the authority-spoofing prompt injection embedded in the context and the default attack goal, no defense; default inference settings, up to 20,000 output tokens (32,768 for Qwen3-8B)). Source: arxiv.org. Saturation forecast: Estimated already saturated. 8 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-4.1 | 68 |
| 2 | GPT-4o | 69 |
| 3 | Llama 3.1 8B Instruct | 70 |
| 4 | deepseek-llm-7B-chat | 79 |
| 5 | Llama 3.2 3B Instruct | 83 |
| 6 | Qwen 3 8B | 97 |
Interactive version: theaggregate.ai/benchmark?slug=longpibench-email-summary · How It Works · Data refreshed daily, snapshot 2026-09-29.