MMJailBench - Safety-Paradox Framing: leaderboard

Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; safety-paradox reasoning framing, all 272 intents, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.

Top models

#ModelScore
1GPT-51.88
2Claude Sonnet 4.53.27
3Qwen 3 VL 8B13.49
4Kimi K2.515.15
5Gemini 3 Flash18.97
6Ministral 3 8B28.24
7GLM-4.6V33.71
8Qwen 2.5 VL 7B Instruct35.62
9Gemma 3 12B37.06
10InternVL3-8B43.09
11Grok 4 Fast43.12
12Step3 VL 10B48.42
13Seed 2.0 Lite51.95

Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-safety-paradox-framing · How It Works · Data refreshed daily, snapshot 2026-09-26.