セキュリティと信頼 Jul 31, 2026 at 22:208ブックマークに追加

IPIベンチマークにおいて、Opus 5はOpus 4.8の攻撃者成功率をほぼ3分の1に削減しています。最も優れた非Claudeモデルでも16.5%にとどまっています。Schneierは正しい指摘をしています。プロンプトインジェクションを完全に封じるのではなく、統計的にコストのかかるものにするのです。
Anthropicが公開したIPI(Indirect Prompt Injection)ベンチマークでは、Opus 5は攻撃成功率を15回試行で2.0%(Opus 4.8は5.5%)、1回試行で0.2%(Opus 4.8は0.5%)と発表しています。同じファミリー内の比較では、Sonnet 5が5.9%(k=15)、Mythos 5が2.6%です。このベンチマークでClaude以外のモデルで最も優秀だったMuse Sparkでも16.5%にとどまっており、Opus 5の8倍以上の数値です。Bruce Schneierは2026年7月31日のブログでこれらの数値を取り上げ、自身の見解を述べています。すなわち、一般的なケースでのプロンプトインジェクション防止は不可能だが、特定の領域では明確な進歩が見られるというものです。
数値以上に重要なのは、2つのポイントです。1つ目は、Claude以外のモデルのベースラインである16.5%という数値が、この攻撃ベクトルの差が現実的なものであることを示しています。エンタープライズ環境でエージェントがサードパーティのコンテンツ(メール、ドキュメント、ウェブ)にさらされる場合、成功率を16%から2%に抑えることは、運用コストの面で大きな違いをもたらします。2つ目は、Schneierの見解「特定のケースにおける進歩であって、解決ではない」という指摘です。これは正しい姿勢です。プロンプトインジェクションを完全に排除するのではなく、統計的にコストをかけさせることが重要です。
完全なIPIプロトコル(データセット、攻撃者、カテゴリ)と第三者による再現可能な評価です。これらがなければ、2%という数値は製品マーケティングの域を出ず、SOC(セキュリティオペレーション)の現実には反映されません。
本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。
2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?
That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?
Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.
How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.
That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?
The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.
Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?
Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.
So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.
Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.
But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?
Claude Fable 5 : de l'annonce à la mise en production