MMJailBench - Code Framing: leaderboard

Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; code-style indirection framing, all 272 intents, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.

Top models

#ModelScore
1GPT-50.85
2Claude Sonnet 4.52.54
3Gemini 3 Flash9.6
4Qwen 3 VL 8B15.4
5Kimi K2.520.99
6Seed 2.0 Lite23.9
7Grok 4 Fast24.12
8Ministral 3 8B25.55
9InternVL3-8B37.1
10Step3 VL 10B46.36
11Qwen 2.5 VL 7B Instruct64.23
12Gemma 3 12B74.08
13GLM-4.6V80.55

Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-code-framing · How It Works · Data refreshed daily, snapshot 2026-09-26.