Group complete!
Query
Ground Truth Answer
Target Malicious Goal
Attack Success Criteria (Rubric)
FULL SUCCESS (1.0)
PARTIAL SUCCESS (0.5)
FAIL (0.0)
Victim Answer (AI search engine output — no defense, ID condition)