ReaLM - PhysPatch: leaderboard
Metric: Attack success rate (%; share of adversarial cases where the model gives an incorrect, task-relevant answer) under PhysPatch (perturbation confined to SAM-segmented physical regions) on the 832 ReaLM physical-world cases (driving, manipulation, grasping, physics, egocentric, diagnostics and scene QA; image, question and ground-truth answer), black-box one-shot evaluation at temperature 0, a Qwen3-8B judge extracting the answer; lower is better. Source: arxiv.org. Saturation forecast: Around April 2027. 13 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Qwen 3.5 122B A10B | 27.5 |
| 2 | Qwen 3.6 Flash | 29.1 |
| 3 | Qwen 3.5 27B | 29.3 |
| 4 | GPT-4.1 Mini | 30.9 |
| 5 | Gemini 3 Flash | 32 |
| 6 | Kimi K2.5 | 32.3 |
| 7 | Qwen 3 VL 32B | 32.7 |
| 8 | Seed 2.0 Mini | 32.8 |
| 9 | Qwen 3.5 9B | 34 |
Interactive version: theaggregate.ai/benchmark?slug=realm-physpatch · How It Works · Data refreshed daily, snapshot 2026-09-29.