By Amy Chang, Nicholas Conley
Publication Date: 2026-09-24 15:59:00
With research and development support from Ravikumar Balakrishnan, Ankit Garg, and Sanket Mendapara
When we launched the Cisco LLM Security Leaderboard earlier this year, the goal was simple: give organizations clear, tested data on how models hold up against attacks, so they know the risks before they deploy one. That matters because AI models are increasingly built into products such as agents that read email, browse the web, and take actions on a person’s behalf. A model that can be manipulated could be turned against the person using it. That risk also varies by deployment: a model wired into a browsing agent is exposed on different inputs (or modalities such as text, images, and audio) than one only answering questions in a chat window, so where a specific model is weak matters as much as where it’s strong.
The leaderboard tests for that a few different ways: prompt injection, where a malicious instruction is hidden in content the model processes, like a webpage or…

