Security & Trust 31/07/2026 à 22h208Ajouter aux favoris

Sur le benchmark IPI, Opus 5 divise par près de trois le taux de succès attaquant d'Opus 4.8. Le meilleur non-Claude évalué reste à 16,5 %. Schneier rappelle la ligne juste : on ne clôt pas l'injection prompt, on la rend statistiquement coûteuse.
Sur le benchmark IPI (Indirect Prompt Injection) publié par Anthropic, Opus 5 revendique un taux de succès attaquant de 2,0 % en 15 tentatives (contre 5,5 % pour Opus 4.8), et de 0,2 % en une seule tentative (contre 0,5 %). Comparaison labo dans la même famille : Sonnet 5 à 5,9 % (k=15), Mythos 5 à 2,6 %. Le meilleur modèle non-Claude évalué sur ce benchmark, Muse Spark, plafonne à 16,5 % - plus de huit fois le taux d'Opus 5. Bruce Schneier reprend ces chiffres sur son blog le 31 juillet 2026 et rappelle sa position : empêcher l'injection prompt reste impossible dans le cas général, mais le domaine progresse nettement sur les cas spécifiques.
Deux points comptent au-delà du chiffre éditeur. Un : la baseline non-Claude, 16,5 %, dit que l'écart sur ce vecteur est réel, pas homéopathique - pour un déploiement enterprise qui expose un agent à des contenus tiers (mails, docs, web), passer de 16 à 2 % change le coût opérationnel de l'exploit. Deux : la lecture de Schneier - « progrès sur cas spécifiques, pas résolution » - est la posture juste. On ne clôt pas l'injection prompt, on la rend statistiquement coûteuse.
Le protocole IPI complet (dataset, adversaires, catégories) et des évaluations tierces reproductibles. Sans elles, le 2 % vit dans le marketing produit, pas dans le SOC.
Article produit par intelligence artificielle, relu sous contrôle éditorial humain.
Connectez-vous pour rejoindre la discussion.
2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?
That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?
Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.
How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.
That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?
The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.
Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?
Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.
So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.
Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.
But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?
Claude Fable 5 : de l'annonce à la mise en production