TRAP - Task Accuracy: leaderboard

Metric: Task accuracy (%): correct tool and arguments using the private fields, sample-weighted over all 500 document-grounded scenarios (100 text, 200 image, 200 multimodal) over ten private document types; each pairs a task query that needs a tool call with private fields and an attack query eliciting the same fields in natural language; rule-based evaluator, greedy decoding. Source: arxiv.org. Saturation forecast: Around 2029. 22 models tracked.

Top models

#ModelScore
1Qwen 3 VL 32B76.2
2GPT-5 Mini75.8
3GPT-5.4 Mini72.6
4GPT-572.2
5Gemini 2.5 Flash71
6InternVL3.5-8B67.4
7GPT-4o Mini66.6
8Gemini 2.5 Flash Lite66
9Claude Sonnet 4.562
10Gemini 2.5 Pro61.2
11Claude Haiku 4.560.4

Interactive version: theaggregate.ai/benchmark?slug=trap-task-accuracy · How It Works · Data refreshed daily, snapshot 2026-09-29.