Report by Cisco
Proprietary Problems: How Frontier Closed Models Collapse Under Iterative Pressure
Key Findings
Multi-turn attack success rate (ASR) ranges from 7.89% to 88.30% across the 15 closed/proprietary flagship models in the cohort.
Single-turn attack success rate (ASR) ranges from 2.19% to 64.91% across the 15 closed/proprietary flagship models in the cohort.
Gemini 3 Pro shifts from 18.10% single-turn ASR to 73.35% multi-turn ASR, a 4x increase.
Cross-regime deltas (multi-turn ASR minus single-turn ASR) range from −34.74 percentage points to +55.25 percentage points across the cohort.
Eight of 15 models have an absolute cross-regime gap greater than 15 percentage points.
Nova 2 Lite shows 34.05% single-turn ASR but 7.89% multi-turn ASR.
Enabling reasoning on Grok 4.1 Fast reduces multi-turn ASR from 88.30% to 43.47%.
Within each multi-turn attack strategy family, the spread between the most- and least-exposed models ranges from 79.51 to 89.25 percentage points.
Multi-turn attack success rates run 2x to 10x higher than single-turn baselines across eight open-weight LLMs in an earlier evaluation.
Imposter AI is more than 14 percentage points higher than the tenth-ranked procedure by weighted ASR.
Anthropic Claude-family single-turn ASR ranges from 2.19% to 3.64%, and multi-turn ASR ranges from 11.16% to 16.20%.
Grok 4.1 Fast in its non-reasoning configuration records a multi-turn ASR of 88.30%.
In an earlier open-weight evaluation, multi-turn ASR reached 92.78% against Mistral Large-2.
GPT-5.4 moves from 2.74% single-turn ASR to 24.68% multi-turn ASR, a 9x increase.
Imposter AI procedures produce a 37.50% weighted single-turn ASR, Soft Paraphrase produces 29.21%, and System Prompts produce 27.69%.