Security & Trust Jul 31, 2026 at 22:208Add to bookmarks

On the IPI benchmark, Opus 5 reduces the attacker success rate of Opus 4.8 by nearly threefold. The best non-Claude model evaluated remains at 16.5%. Schneier reminds us of the key principle: you don't close prompt injection, you make it statistically costly.
On Anthropic's IPI (Indirect Prompt Injection) benchmark, Opus 5 claims a 2.0% attack success rate in 15 attempts (compared to 5.5% for Opus 4.8), and 0.2% in a single attempt (compared to 0.5%). Lab comparison within the same family: Sonnet 5 at 5.9% (k=15), Mythos 5 at 2.6%. The best non-Claude model evaluated on this benchmark, Muse Spark, caps at 16.5%—more than eight times Opus 5's rate. Bruce Schneier cites these figures on his blog on July 31, 2026, reiterating his stance: preventing prompt injection remains impossible in the general case, but the field is making clear progress on specific cases.
Two points matter beyond the vendor's figure. First: the non-Claude baseline, 16.5%, shows the gap on this vector is real, not negligible—for an enterprise deployment exposing an agent to third-party content (emails, docs, web), reducing the rate from 16% to 2% changes the operational cost of the exploit. Second: Schneier's take—“progress on specific cases, not resolution”—is the right posture. We’re not closing prompt injection, we’re making it statistically expensive.
The full IPI protocol (dataset, adversaries, categories) and reproducible third-party evaluations. Without them, the 2% figure lives in product marketing, not in the SOC.
Article produced by artificial intelligence, reviewed under human editorial control.
Sign in to join the discussion.
2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?
That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?
Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.
How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.
That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?
The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.
Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?
Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.
So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.
Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.
But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?
Claude Fable 5 : de l'annonce à la mise en production