Ethics and safety·September 24, 2026, 18:03

Cisco's security leaderboard now tests AI on text, image and audio

AI-generated and checked against the sources listed below.

Cisco has expanded its security leaderboard for AI models so it now also tests how easily models can be tricked via images and audio, not just text. It is meant to help companies choose safer models for AI agents.

AI-generated image

Cisco has updated its "LLM Security Leaderboard," a public overview showing how well different AI language models can withstand attempts to manipulate them. Until now, the tests have only looked at text, but now images and audio have been added.

The expansion means the leaderboard now covers 136 models in total, 102 of them new since June 2026. Among the new ones are 55 image models and 14 audio models from major providers such as Amazon, Anthropic, Google, Meta, Mistral, OpenAI and xAI.

The background is that many AI models today not only respond to text but can also see images and hear audio, for example when they are used in AI agents that read emails, browse the web or carry out tasks on their own. Here, a security hole in one modality can become an entry point for attacks. A malicious instruction can, for example, be hidden in an image or audio file that the model is tricked into following; this is called prompt injection. There are also so-called jailbreaks, where you try to persuade the model to ignore its own safety rules.

The tests show large differences between the models. On image tests, Google's Gemini 3.1 Pro Preview performed best and withstood attacks in 93.9 percent of cases, while Mistral's Magistral Small managed only 23 percent. On audio tests, Gemini 3.1 Pro was again at the top with 90 percent, while Mistral's Voxtral Small withstood attacks in only 9 percent of attempts.

Cisco stresses that each provider builds its models differently and that this affects how well the different parts (text, image and audio) are secured against misuse. A model can thus be good at withstanding text attacks but vulnerable to attacks via images or audio.

For ordinary users and companies, this means that choosing an AI model is not just about how smart or fast it is, but also about how secure it is against manipulation attempts, especially if the model is to be used in systems that can act on your behalf.

Sources

More on this topic

Get the week's AI news in your inbox

Choose your level, topics and length. One email a week, unsubscribe at any time.

Subscribe to Promptly Newsletter
PromptlyNewsletterRSSLog in

The news on aijour is AI-generated and checked against the cited sources.