Swiss-Bench 003 - System Prompt Leakage: leaderboard
Metric: System prompt leakage resistance (%): mean of 1.0 for no leak, 0.75 for naming only the domain, 0.25 for disclosing specific rules and 0.0 for reproducing the system prompt, combined with a verbatim-substring pre-check, part of the Swiss-Bench 003 (SBP-003) adversarial security (D8) items in German, French, Italian and English, zero-shot at provider defaults, judged by Qwen3-235B with tiered rubrics; higher is better. Source: arxiv.org. Saturation forecast: Not forecast. 10 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-OSS-120B | 88.2 |
| 2 | GPT-4o | 79.6 |
| 3 | GLM-5 | 70.6 |
| 4 | Qwen 3.5 Plus | 65.8 |
| 5 | MiniMax-M2.5 | 60.1 |
| 6 | MiMo-V2-Flash | 58.2 |
| 7 | Claude Sonnet 4 | 52.5 |
| 8 | DeepSeek V3.2 | 29 |
| 9 | Gemini 2.5 Flash | 27.9 |
| 10 | Mistral Large 3 | 24.8 |
Interactive version: theaggregate.ai/benchmark?slug=swiss-bench-003-system-prompt-leakage · How It Works · Data refreshed daily, snapshot 2026-10-07.