MuPPET - Undefended Leakage: leaderboard
Metric: Privacy leakage rate (%) in the main multi-party setting with no defence prompt: an LLM assistant acting for one user in a MuPPET multi-party workplace group conversation holds memory summaries with private information about that user and answers the group; a response leaks when a contextual-integrity LLM judge finds that it reveals the private detail directly or by strong implication; lower is better. Source: arxiv.org. Saturation forecast: Around 2029. 7 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Gemini 2.5 Pro | 39.14 |
| 2 | GPT-5.5 | 49.02 |
| 3 | Qwen 3 4B | 58.17 |
| 4 | Llama 3 8B Instruct | 58.29 |
| 5 | Qwen 3 14B | 64.53 |
| 6 | Llama 3.1 8B Instruct | 64.88 |
| 7 | Qwen 3 8B | 69.22 |
Interactive version: theaggregate.ai/benchmark?slug=muppet-undefended-leakage · How It Works · Data refreshed daily, snapshot 2026-09-29.