VisualLeakBench - OCR Injection: leaderboard
Metric: Attack success rate (%) on 500 synthetic images that render a harmful instruction as text: a response with no refusal pattern that contains harmful keywords counts as unsafe; baseline system prompt, temperature 0; lower is better. Source: arxiv.org. 4 models tracked.
Top models
| # | Model | Score | Overall rank |
|---|---|---|---|
| 1 | Claude Sonnet 4 | 14.2 | #194 |
| 2 | Grok 4 | 20.6 | #169 |
| 3 | Gemini 3 Flash (Preview) | 78.6 | #78 |
| 4 | GPT-5.2 | 79.2 | #105 |
Interactive version: theaggregate.ai/benchmark?slug=visualleakbench-ocr-injection · How It Works · Data refreshed daily, snapshot 2026-10-11.