MMJailBench - Story Framing: leaderboard

Metric: Attack success rate (%; share of responses a GPT-5 judge scores 4 or 5 on a 1-5 harmfulness rubric; fictional-storytelling framing, all 272 intents, visual contexts and carriers). Source: arxiv.org. Saturation forecast: Estimated already saturated. 16 models tracked.

Top models

#ModelScore
1GPT-50.44
2Claude Sonnet 4.510
3Qwen 3 VL 8B14.19
4Grok 4 Fast52.5
5Step3 VL 10B58.05
6Kimi K2.559.38
7Gemini 3 Flash62.87
8Ministral 3 8B70
9InternVL3-8B88.42
10Qwen 2.5 VL 7B Instruct88.6
11GLM-4.6V96.29
12Seed 2.0 Lite96.29
13Gemma 3 12B97.94

Interactive version: theaggregate.ai/benchmark?slug=mmjailbench-story-framing · How It Works · Data refreshed daily, snapshot 2026-09-26.