| Benchmark | Metric | Baseline | This Paper | Δ |
|---|---|---|---|---|
| Attack performance comparison showing Virus effectiveness against baselines. | ||||
| Llama Guard 2 Moderation | Leakage Ratio | 0.348 | 1.00 | +0.652 |
| Victim Model Safety | Harmful Score | Not reported in the paper | Not reported in the paper | +16.00 |
| Victim Model Safety | Harmful Score | Not reported in the paper | Not reported in the paper | +16.30 |
| Optimization Analysis | Gradient Cosine Similarity | 0.826 | 0.981 | +0.155 |