Skip to main content
BenchLM

Gray Swan Indirect Prompt Injection, attack success at 15 attempts (Gray Swan IPI (15 attempts))

We show this table for reference; we do not rank on it.

Data verified 37 confirmed releases in the last 30 daysFollow model changes

Measures how often indirect prompt-injection attacks succeed within fifteen attempts. Lower scores mean greater resistance to the tested attacks.

Benchmark score on Gray Swan IPI (15 attempts) — September 30, 2026

We compile the Gray Swan IPI (15 attempts) rows from provider self-reports. Gemini 4 Argon leads the table at 0.7%, followed by Claude Fable 5.1 (1.0%) and Claude Opus 5.5 (1.0%). We do not use these results to rank models overall.

13 modelsInstruction FollowingCurrentDisplay onlyUpdated September 30, 2026

Benchmark score table (13 models)

Score
1
Gemini 4 ArgonGoogle · Closed
0.7%
2
Claude Fable 5.1Anthropic · Closed
1.0%
3
Claude Opus 5.5Anthropic · Closed
1.0%
4
Claude Opus 5Anthropic · Closed
4.6%
5
Gemini 3.8 FlashGoogle · Closed
5.5%
6
Gemini 3.8 Flash CyberGoogle · Closed
6.0%
7
GPT-6 AstraOpenAI · Closed
8.5%
8
GPT-6 SolOpenAI · Closed
10.1%
9
Muse Spark 1.3Meta · Closed
15.9%
10
GPT-5.6 SolOpenAI · Closed
27.0%
11
GLM-5.3Z.AI · Open weight
31.5%
12
Grok 4.6xAI · Closed
51.8%
13
Kimi K3Moonshot AI · Closed
52.7%

How to read this leaderboard

Operator receipt: 13 sourced rows are currently displayable on this page; the leading published row is Gemini 4 Argon at 0.7%.

Honest limit: The announcement does not publish the task count, attack corpus, or full evaluation configuration. This result does not measure general instruction following.

Among the reported Gray Swan IPI (15 attempts) rows, Gemini 4 Argon is first at 0.7%. The third row is 0.3 points higher. The broader top-10 range is 26.3 points, so the table still separates the published systems.

13 models have been evaluated on Gray Swan IPI (15 attempts). The benchmark falls in the Instruction Following category. Gray Swan IPI (15 attempts) is currently displayed for reference but excluded from the scoring formula, so it does not directly affect overall rankings.

About Gray Swan IPI (15 attempts)

Year

2026

Tasks

Indirect prompt-injection attacks

Format

Attack success rate at 15 attempts

Difficulty

Adversarial prompt injection

Google reports attack success rates supplied by Gray Swan. The launch chart labels the values above its bars as success at k=15; k=1 and k=10 are separate chart series. We store only the explicitly labeled k=15 values as provider-reported, display-only evidence.

Freshness and provenance

Version

Gray Swan IPI (15 attempts) 2026

Refresh cadence

Quarterly

Staleness state

Current

Question availability

Public benchmark set

CurrentDisplay only

BenchLM uses freshness metadata to decide whether a benchmark should still be treated as a strong differentiator, a benchmark to watch, or a display-only reference. For the full scoring policy, see the BenchLM methodology page.

Questions

What does Gray Swan IPI (15 attempts) measure?

Measures how often indirect prompt-injection attacks succeed within fifteen attempts. Lower scores mean greater resistance to the tested attacks.

Which model scores highest on Gray Swan IPI (15 attempts)?

Gemini 4 Argon by Google currently leads with a score of 0.7% on Gray Swan IPI (15 attempts).

How many models are evaluated on Gray Swan IPI (15 attempts)?

13 AI models have been evaluated on Gray Swan IPI (15 attempts) on BenchLM.

Last updated: September 30, 2026 · BenchLM version Gray Swan IPI (15 attempts) 2026

Know when it’s worth switching models

The model to choose, the cheaper alternative, and the release we would wait on.

Read a sample issue

Join 2,000+ readers.

One email each week. Unsubscribe anytime.