MMJailBench - Deception & Public Influence: leaderboard
Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; Deception & Public Influence domain, 28 harmful intents across all framings, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5 | 3.39 |
| 2 | Claude Sonnet 4.5 | 10.06 |
| 3 | Qwen 3 VL 8B | 20.65 |
| 4 | Gemini 3 Flash | 42.14 |
| 5 | Kimi K2.5 | 43.81 |
| 6 | Grok 4 Fast | 52.5 |
| 7 | InternVL3-8B | 53.21 |
| 8 | Step3 VL 10B | 58.93 |
| 9 | Ministral 3 8B | 59.58 |
| 10 | Qwen 2.5 VL 7B Instruct | 62.5 |
| 11 | Seed 2.0 Lite | 63.1 |
| 12 | Gemma 3 12B | 75.95 |
| 13 | GLM-4.6V | 87.26 |
Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-deception-public-influence · How It Works · Data refreshed daily, snapshot 2026-09-26.