ReaLM - V-Attack: leaderboard

Metric: Attack success rate (%; share of adversarial cases where the model gives an incorrect, task-relevant answer) under V-Attack (attention value-feature manipulation against a CLIP surrogate ensemble, L-inf 16/255) on the 832 ReaLM physical-world cases (driving, manipulation, grasping, physics, egocentric, diagnostics and scene QA; image, question and ground-truth answer), black-box one-shot evaluation at temperature 0, a Qwen3-8B judge extracting the answer; lower is better. Source: arxiv.org. Saturation forecast: Around 2028. 13 models tracked.

Top models

#ModelScore
1Qwen 3.5 122B A10B43.6
2Qwen 3.5 27B44.1
3Gemini 3 Flash44.8
4Seed 2.0 Mini47.4
5Kimi K2.547.5
6Qwen 3.5 9B47.7
7GPT-4.1 Mini48.3
8Qwen 3.6 Flash48.6
9Qwen 3 VL 32B49

Interactive version: theaggregate.ai/benchmark?slug=realm-v-attack · How It Works · Data refreshed daily, snapshot 2026-09-29.