MMJailBench - Deception & Public Influence: leaderboard

Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; Deception & Public Influence domain, 28 harmful intents across all framings, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.

Top models

#ModelScore
1GPT-53.39
2Claude Sonnet 4.510.06
3Qwen 3 VL 8B20.65
4Gemini 3 Flash42.14
5Kimi K2.543.81
6Grok 4 Fast52.5
7InternVL3-8B53.21
8Step3 VL 10B58.93
9Ministral 3 8B59.58
10Qwen 2.5 VL 7B Instruct62.5
11Seed 2.0 Lite63.1
12Gemma 3 12B75.95
13GLM-4.6V87.26

Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-deception-public-influence · How It Works · Data refreshed daily, snapshot 2026-09-26.