Opus 5 reduce la tasa de inyección de indicaciones al 2 % en k=15 - Schneier valida la trayectoria

Seguimiento del caso : Claude Fable 5 : de l'annonce à la mise en production· Episodio 4/4

Seguridad y Confianza Jul 31, 2026 at 22:208Añadir a favoritos

Opus 5 reduce la tasa de inyección de indicaciones al 2 % en k=15 - Schneier valida la trayectoria
Ilustración : Léa Fontaine

En el benchmark IPI, Opus 5 reduce casi tres veces la tasa de éxito de ataques de Opus 4.8. El mejor no-Claude evaluado sigue siendo del 16,5 %. Schneier recuerda la línea correcta: no se cierra la inyección de prompt, se la hace estadísticamente costosa.

El hecho

En el benchmark IPI (Inyección Indirecta de Prompts) publicado por Anthropic, Opus 5 reclama una tasa de éxito de ataque del 2,0 % en 15 intentos (frente al 5,5 % de Opus 4.8), y del 0,2 % en un solo intento (frente al 0,5 %). Comparación en la misma familia en laboratorio: Sonnet 5 con un 5,9 % (k=15), Mythos 5 con un 2,6 %. El mejor modelo no-Claude evaluado en este benchmark, Muse Spark, se sitúa en un 16,5 % —más de ocho veces la tasa de Opus 5. Bruce Schneier retoma estas cifras en su blog el 31 de julio de 2026 y recuerda su postura: impedir la inyección de prompts sigue siendo imposible en el caso general, pero el campo avanza notablemente en casos específicos.

Nuestra lectura

Dos puntos importan más allá de la cifra del editor. Uno: la línea base no-Claude, del 16,5 %, indica que la diferencia en este vector es real, no homeopática —para un despliegue empresarial que expone un agente a contenidos de terceros (correos, documentos, web), pasar del 16 % al 2 % cambia el coste operativo del exploit. Dos: la lectura de Schneier —«progresos en casos específicos, no resolución»— es la postura correcta. No se cierra la inyección de prompts, se la hace estadísticamente costosa.

A vigilar

El protocolo IPI completo (conjunto de datos, adversarios, categorías) y evaluaciones de terceros reproducibles. Sin ellas, el 2 % vive en el marketing del producto, no en el SOC.

Resources

Artículo producido por inteligencia artificial, revisado bajo control editorial humano.

Nuestra redacción
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
¿Te ha resultado útil este artículo?

10 personas han valorado este artículo

Me gusta
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
Compartir:
Comentarios (8)

Inicia sesión para unirte a la conversación.

MusicFanatic 03 Aug 2026 · 07:55

2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?

ArtLover99 01 Aug 2026 · 04:58

That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?

Alex_London 01 Aug 2026 · 04:48

Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.

Dr. Emily 01 Aug 2026 · 04:46

How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.

FoodieFiona 2 01 Aug 2026 · 04:27

That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?

FoodieFiona 01 Aug 2026 · 07:18

The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.

LecteurDuDimanche 01 Aug 2026 · 07:33

Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?

Critique42 01 Aug 2026 · 04:22

Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.

EcoWarrior99 31 Jul 2026 · 18:21

So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.

ArtLoverLA 31 Jul 2026 · 20:47

Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.

HistoryBuff 31 Jul 2026 · 17:51

But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?

El hilo del caso

Claude Fable 5 : de l'annonce à la mise en production

  1. 1Anthropic hace que Claude Fable 5 sea permanente en planes premium a partir del 20 de julio19/07/2026
  2. 2Anthropic lanza Claude Opus 5: capacidad casi-Fable 5 a aproximadamente la mitad del precio25/07/2026
  3. 3Claude Opus 5 de Anthropic: el arco Fable 5 cierra a aproximadamente la mitad del precio26/07/2026
  4. 4Opus 5 reduce la tasa de inyección de indicaciones al 2 % en k=15 - Schneier valida la trayectoria31/07/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Secciones
Explorar
Información