# Gray Swan Indirect Prompt Injection, attack success at 15 attempts (Gray Swan IPI (15 attempts))

> Measures how often indirect prompt-injection attacks succeed within fifteen attempts. Lower scores mean greater resistance to the tested attacks.

Canonical page: https://benchlm.ai/benchmarks/gray-swan-ipi

- Category: [Instruction Following](/instruction-following)
- Last updated: September 30, 2026

## About Gray Swan IPI (15 attempts)

- Year: 2026
- Tasks: Indirect prompt-injection attacks
- Format: Attack success rate at 15 attempts
- Difficulty: Adversarial prompt injection
- Paper: [Gemini 4 Argon evaluation methodology](https://deepmind.google/models/evals-methodology/gemini-4-argon)

Google reports attack success rates supplied by Gray Swan. The launch chart labels the values above its bars as success at k=15; k=1 and k=10 are separate chart series. We store only the explicitly labeled k=15 values as provider-reported, display-only evidence.

Gray Swan IPI (15 attempts) is currently displayed on BenchLM for reference, but it is excluded from the weighted scoring formula.

## Leaderboard (13 models)

| Rank | Model | Creator | Score |
|------|-------|---------|-------|
| 1 | [Gemini 4 Argon](/models/gemini-4-argon) | Google | 0.7% |
| 2 | [Claude Opus 5.5](/models/claude-opus-5-5) | Anthropic | 1.0% |
| 3 | [Claude Fable 5.1](/models/claude-fable-5-1) | Anthropic | 1.0% |
| 4 | [Claude Opus 5](/models/claude-opus-5) | Anthropic | 4.6% |
| 5 | [Gemini 3.8 Flash](/models/gemini-3-8-flash) | Google | 5.5% |
| 6 | [Gemini 3.8 Flash Cyber](/models/gemini-3-8-flash-cyber) | Google | 6.0% |
| 7 | [GPT-6 Astra](/models/gpt-6-astra) | OpenAI | 8.5% |
| 8 | [GPT-6 Sol](/models/gpt-6-sol) | OpenAI | 10.1% |
| 9 | [Muse Spark 1.3](/models/muse-spark-1-3) | Meta | 15.9% |
| 10 | [GPT-5.6 Sol](/models/gpt-5-6-sol) | OpenAI | 27.0% |
| 11 | [GLM-5.3](/models/glm-5-3) | Z.AI | 31.5% |
| 12 | [Grok 4.6](/models/grok-4-6) | xAI | 51.8% |
| 13 | [Kimi K3](/models/kimi-k3) | Moonshot AI | 52.7% |

## FAQ

### What does Gray Swan IPI (15 attempts) measure?

Measures how often indirect prompt-injection attacks succeed within fifteen attempts. Lower scores mean greater resistance to the tested attacks.

### Which model scores highest on Gray Swan IPI (15 attempts)?

Gemini 4 Argon by Google currently leads with a score of 0.7% on Gray Swan IPI (15 attempts).

### How many models are evaluated on Gray Swan IPI (15 attempts)?

13 AI models have been evaluated on Gray Swan IPI (15 attempts) on BenchLM.

### Does Gray Swan IPI (15 attempts) affect BenchLM's overall score?

Not directly. Gray Swan IPI (15 attempts) is still displayed on BenchLM for reference, but it is excluded from the weighted scoring formula.

## Compare Top Models on Gray Swan IPI (15 attempts)

- [Gemini 4 Argon vs Claude Opus 5.5](/compare/claude-opus-5-5-vs-gemini-4-argon)
- [Claude Opus 5.5 vs Claude Fable 5.1](/compare/claude-fable-5-1-vs-claude-opus-5-5)
- [Claude Fable 5.1 vs Claude Opus 5](/compare/claude-fable-5-1-vs-claude-opus-5)
- [Claude Opus 5 vs Gemini 3.8 Flash](/compare/claude-opus-5-vs-gemini-3-8-flash)
