Opus 5 は、k=15 でプロンプト注入率を 2% に低下させる – Schneier が軌道を検証

継続中のトピック : Claude Fable 5 : de l'annonce à la mise en production· パート 4/4

セキュリティと信頼 Jul 31, 2026 at 22:208ブックマークに追加

Opus 5 は、k=15 でプロンプト注入率を 2% に低下させる – Schneier が軌道を検証
イラスト : Léa Fontaine

IPIベンチマークにおいて、Opus 5はOpus 4.8の攻撃者成功率をほぼ3分の1に削減しています。最も優れた非Claudeモデルでも16.5%にとどまっています。Schneierは正しい指摘をしています。プロンプトインジェクションを完全に封じるのではなく、統計的にコストのかかるものにするのです。

事実

Anthropicが公開したIPI(Indirect Prompt Injection)ベンチマークでは、Opus 5は攻撃成功率を15回試行で2.0%(Opus 4.8は5.5%)、1回試行で0.2%(Opus 4.8は0.5%)と発表しています。同じファミリー内の比較では、Sonnet 5が5.9%(k=15)、Mythos 5が2.6%です。このベンチマークでClaude以外のモデルで最も優秀だったMuse Sparkでも16.5%にとどまっており、Opus 5の8倍以上の数値です。Bruce Schneierは2026年7月31日のブログでこれらの数値を取り上げ、自身の見解を述べています。すなわち、一般的なケースでのプロンプトインジェクション防止は不可能だが、特定の領域では明確な進歩が見られるというものです。

当社の考察

数値以上に重要なのは、2つのポイントです。1つ目は、Claude以外のモデルのベースラインである16.5%という数値が、この攻撃ベクトルの差が現実的なものであることを示しています。エンタープライズ環境でエージェントがサードパーティのコンテンツ(メール、ドキュメント、ウェブ)にさらされる場合、成功率を16%から2%に抑えることは、運用コストの面で大きな違いをもたらします。2つ目は、Schneierの見解「特定のケースにおける進歩であって、解決ではない」という指摘です。これは正しい姿勢です。プロンプトインジェクションを完全に排除するのではなく、統計的にコストをかけさせることが重要です。

要注目

完全なIPIプロトコル(データセット、攻撃者、カテゴリ)と第三者による再現可能な評価です。これらがなければ、2%という数値は製品マーケティングの域を出ず、SOC(セキュリティオペレーション)の現実には反映されません。

リソース

本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。

編集部について
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
この記事は役に立ちましたか?

10 人がこの記事を評価しました

いいね
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
シェア:
コメント (8)

ログインして議論に参加しましょう。

MusicFanatic 03 Aug 2026 · 07:55

2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?

ArtLover99 01 Aug 2026 · 04:58

That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?

Alex_London 01 Aug 2026 · 04:48

Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.

Dr. Emily 01 Aug 2026 · 04:46

How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.

FoodieFiona 2 01 Aug 2026 · 04:27

That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?

FoodieFiona 01 Aug 2026 · 07:18

The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.

LecteurDuDimanche 01 Aug 2026 · 07:33

Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?

Critique42 01 Aug 2026 · 04:22

Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.

EcoWarrior99 31 Jul 2026 · 18:21

So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.

ArtLoverLA 31 Jul 2026 · 20:47

Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.

HistoryBuff 31 Jul 2026 · 17:51

But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?

トピックの経過

Claude Fable 5 : de l'annonce à la mise en production

  1. 1Anthropicは、2024年7月20日からプレミアムプランでClaude Fable 5を永続的に利用可能にします。19/07/2026
  2. 2Anthropic、Claude Opus 5を発表:Fable 5に近い能力を半額以下で提供25/07/2026
  3. 3AnthropicはClaude Opus 5をリリース:Fable 5アークがおよそ半額で終了26/07/2026
  4. 4Opus 5 は、k=15 でプロンプト注入率を 2% に低下させる – Schneier が軌道を検証31/07/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
テーマ
探索
インフォメーション