TRAP - Privacy: leaderboard
Metric: Privacy score (%): 1 minus the leakage rate under the attack query, sample-weighted over all 500 document-grounded scenarios (100 text, 200 image, 200 multimodal) over ten private document types; each pairs a task query that needs a tool call with private fields and an attack query eliciting the same fields in natural language; rule-based evaluator, greedy decoding. Source: arxiv.org. Saturation forecast: Around 2035. 22 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Gemini 2.5 Pro | 26.4 |
| 2 | Gemini 2.5 Flash Lite | 20.4 |
| 3 | GPT-4o Mini | 13.2 |
| 4 | GPT-5 | 12.8 |
| 5 | InternVL3.5-8B | 12.4 |
| 6 | GPT-5.4 Mini | 10.4 |
| 7 | Gemini 2.5 Flash | 10 |
| 8 | GPT-5 Mini | 10 |
| 9 | Claude Haiku 4.5 | 8.8 |
| 10 | Qwen 3 VL 32B | 8.8 |
| 11 | Claude Sonnet 4.5 | 6.6 |
Interactive version: theaggregate.ai/benchmark?slug=trap-privacy · How It Works · Data refreshed daily, snapshot 2026-09-29.