Seguridad y Confianza Jul 31, 2026 at 22:208Añadir a favoritos

En el benchmark IPI, Opus 5 reduce casi tres veces la tasa de éxito de ataques de Opus 4.8. El mejor no-Claude evaluado sigue siendo del 16,5 %. Schneier recuerda la línea correcta: no se cierra la inyección de prompt, se la hace estadísticamente costosa.
En el benchmark IPI (Inyección Indirecta de Prompts) publicado por Anthropic, Opus 5 reclama una tasa de éxito de ataque del 2,0 % en 15 intentos (frente al 5,5 % de Opus 4.8), y del 0,2 % en un solo intento (frente al 0,5 %). Comparación en la misma familia en laboratorio: Sonnet 5 con un 5,9 % (k=15), Mythos 5 con un 2,6 %. El mejor modelo no-Claude evaluado en este benchmark, Muse Spark, se sitúa en un 16,5 % —más de ocho veces la tasa de Opus 5. Bruce Schneier retoma estas cifras en su blog el 31 de julio de 2026 y recuerda su postura: impedir la inyección de prompts sigue siendo imposible en el caso general, pero el campo avanza notablemente en casos específicos.
Dos puntos importan más allá de la cifra del editor. Uno: la línea base no-Claude, del 16,5 %, indica que la diferencia en este vector es real, no homeopática —para un despliegue empresarial que expone un agente a contenidos de terceros (correos, documentos, web), pasar del 16 % al 2 % cambia el coste operativo del exploit. Dos: la lectura de Schneier —«progresos en casos específicos, no resolución»— es la postura correcta. No se cierra la inyección de prompts, se la hace estadísticamente costosa.
El protocolo IPI completo (conjunto de datos, adversarios, categorías) y evaluaciones de terceros reproducibles. Sin ellas, el 2 % vive en el marketing del producto, no en el SOC.
Artículo producido por inteligencia artificial, revisado bajo control editorial humano.
Inicia sesión para unirte a la conversación.
2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?
That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?
Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.
How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.
That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?
The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.
Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?
Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.
So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.
Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.
But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?
Claude Fable 5 : de l'annonce à la mise en production