Безопасность и доверие Jul 31, 2026 at 22:208В закладки

На бенчмарке IPI Opus 5 почти в три раза снижает процент успешных атак по сравнению с Opus 4.8. Лучший результат среди не-Claude моделей остаётся на уровне 16,5 %. Шнайер напоминает верную мысль: закрыть инъекцию промпта нельзя, но можно сделать её статистически затратной.
На бенчмарке IPI (Indirect Prompt Injection), опубликованном Anthropic, Opus 5 заявляет о 2,0 % успешных атак за 15 попыток (против 5,5 % у Opus 4.8) и 0,2 % за одну попытку (против 0,5 %). Сравнение в том же семействе: Sonnet 5 — 5,9 % (k=15), Mythos 5 — 2,6 %. Лучшая модель вне семейства Claude на этом бенчмарке, Muse Spark, достигает 16,5 % — более чем в восемь раз выше, чем у Opus 5. Брюс Шнайер приводит эти цифры в своём блоге 31 июля 2026 года и напоминает свою позицию: предотвратить prompt injection в общем случае невозможно, но в специфических сценариях прогресс очевиден.
Есть два момента, выходящие за рамки маркетинговых цифр. Во-первых, показатель вне семейства Claude — 16,5 % — говорит о том, что разрыв в этом векторе реален, а не символичен. Для корпоративного развёртывания, где агент взаимодействует с внешними источниками (письма, документы, веб), переход с 16 % до 2 % меняет операционную стоимость эксплуатации. Во-вторых, позиция Шнайера — «прогресс в специфических случаях, а не полное решение» — это единственно верная точка зрения. Проблему prompt injection не закрывают, но делают её статистически затратной.
Полный протокол IPI (набор данных, противники, категории) и независимые воспроизводимые оценки. Без них цифра 2 % останется частью маркетинга, а не частью SOC.
Статья создана искусственным интеллектом и проверена под редакционным контролем человека.
Войдите, чтобы участвовать в обсуждении.
2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?
That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?
Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.
How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.
That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?
The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.
Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?
Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.
So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.
Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.
But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?
Claude Fable 5 : de l'annonce à la mise en production