MMJailBench - Privacy & IP: leaderboard

Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; Privacy & IP domain, 30 harmful intents across all framings, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.

Top models

#ModelScore
1GPT-52
2Claude Sonnet 4.513.06
3Qwen 3 VL 8B28.72
4Gemini 3 Flash41.06
5Kimi K2.544.06
6InternVL3-8B51.33
7Grok 4 Fast55
8Ministral 3 8B59.61
9Qwen 2.5 VL 7B Instruct60.94
10Step3 VL 10B62.06
11Seed 2.0 Lite62.94
12Gemma 3 12B75.94
13GLM-4.6V85.17

Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-privacy-ip · How It Works · Data refreshed daily, snapshot 2026-09-26.