MMJailBench - Sensitive Regulated Advice: leaderboard

Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; Sensitive Regulated Advice domain, 30 harmful intents across all framings, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.

Top models

#ModelScore
1GPT-53.56
2Claude Sonnet 4.511.22
3Qwen 3 VL 8B14.39
4InternVL3-8B27.39
5Kimi K2.530.72
6Qwen 2.5 VL 7B Instruct33.44
7Gemini 3 Flash36.61
8Ministral 3 8B38.06
9Grok 4 Fast40.33
10Step3 VL 10B42.06
11Seed 2.0 Lite46.44
12Gemma 3 12B51.39
13GLM-4.6V59.89

Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-sensitive-regulated-advice · How It Works · Data refreshed daily, snapshot 2026-09-26.