VisualLeakBench - OCR Injection: leaderboard

Metric: Attack success rate (%) on 500 synthetic images that render a harmful instruction as text: a response with no refusal pattern that contains harmful keywords counts as unsafe; baseline system prompt, temperature 0; lower is better. Source: arxiv.org. 4 models tracked.

Top models

#ModelScoreOverall rank
1Claude Sonnet 414.2#194
2Grok 420.6#169
3Gemini 3 Flash (Preview)78.6#78
4GPT-5.279.2#105

Interactive version: theaggregate.ai/benchmark?slug=visualleakbench-ocr-injection · How It Works · Data refreshed daily, snapshot 2026-10-11.