evals.report
BenchmarksLabsCompareRun guides

Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection)

A large-scale public red-teaming competition run on the Gray Swan Arena platform that measures how often adversarial attackers can break frontier AI agents (via jailbreaks and indirect prompt injection across tool-use, coding, and computer-use settings), reported as an attack success rate where lower is better.

AgentsAttack Success Rate (ASR)Lower is better

What this benchmark measures

A large-scale public red-teaming competition run on the Gray Swan Arena platform that measures how often adversarial attackers can break frontier AI agents (via jailbreaks and indirect prompt injection across tool-use, coding, and computer-use settings), reported as an attack success rate where lower is better.

Rows on this page are sourced from public benchmark artifacts, leaderboard exports, or source-linked model reports. Each row keeps benchmark version, source model name, and available run details attached to the score.

The metric shown here is Attack Success Rate (ASR). It should be interpreted within Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection), not compared as part of a site-wide ranking.

No composite ranking
evals.report never combines benchmarks. Attack Success Rate (ASR) on Gray Swan Arena (Agent Red-Teaming / Indirect Prompt Injection) is its own number — don’t average it with other metrics.