evals.report
BenchmarksLabsCompareRun guidesIn the wild

Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection)

A large-scale public red-teaming competition run on the Gray Swan Arena platform that measures how often adversarial attackers can break frontier AI agents (via jailbreaks and indirect prompt injection across tool-use, coding, and computer-use settings), reported as an attack success rate where lower is better.

AgentsAttack Success Rate (ASR)Lower is better

What this benchmark measures

A large-scale public red-teaming competition run on the Gray Swan Arena platform that measures how often adversarial attackers can break frontier AI agents (via jailbreaks and indirect prompt injection across tool-use, coding, and computer-use settings), reported as an attack success rate where lower is better.

Rows on this page are sourced from public benchmark artifacts, leaderboard exports, or source-linked model reports. Each row keeps benchmark version, source model name, and available run details attached to the score.

The metric shown here is Attack Success Rate (ASR). It should be interpreted within Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection), not compared as part of a site-wide ranking.

No composite ranking
evals.report never combines benchmarks. Attack Success Rate (ASR) on Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) is its own number — don’t average it with other metrics.

Frequently asked

What is Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection)?

A large-scale public red-teaming competition run on the Gray Swan Arena platform that measures how often adversarial attackers can break frontier AI agents (via jailbreaks and indirect prompt injection across tool-use, coding, and computer-use settings), reported as an attack success rate where lower is better. It is a agents benchmark measured by Attack Success Rate (ASR).

What does Attack Success Rate (ASR) mean on Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection)?

Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) reports Attack Success Rate (ASR) (%); lower is better. Scores are shown only within Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) and are never averaged with other benchmarks.

What is the top reported Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) score?

Claude Opus 4.5 has the top reported score on Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection): 0.5% (Attack Success Rate (ASR)).

Why do Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) scores differ across runs?

Harness, scaffold, reasoning effort, and prompt setup change results, so two runs of the same model can differ. evals.report keeps each score with its run context so the differences stay visible.

Does evals.report rank models across benchmarks?

No. Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) scores are shown within their own metric; evals.report never combines benchmarks into a composite ranking or a single "best model".