CRAICLJun 16

A Red-Team Study of Anthropic Fable 5 & Opus 4.8 Models

arXiv:2606.181934.6
Predicted impact top 71% in CR · last 90 daysOriginality Synthesis-oriented
AI Analysis

For AI safety researchers and deployers, this work demonstrates that even the most hardened frontier LLMs are vulnerable to automated red-teaming, undermining aggregate robustness claims.

The study evaluates adversarial robustness of Anthropic's Fable 5 and Opus 4.8 models against automated jailbreak attacks, finding that while both resist most attacks, adaptive iterative attacks break Opus 4.8 on 11.5% of intents and Fable 5 on 6.1%, with thousands of confirmed harmful completions, indicating frontier models remain reliably breakable under sustained automated pressure.

We evaluate the adversarial robustness of two frontier large language models (LLMs) developed by Anthropic, Fable 5 and Opus 4.8, against four families of automated jailbreak attack across 7 826 harmful intents spanning a ten-category harm taxonomy. Using the HackAgent red-teaming framework, hundreds of thousands of adversarial attempts were generated and every apparent success was independently re-adjudicated by a panel of three judge models (majority vote). Both models resist the majority of attacks, but the residual surface is larger than aggregate framing suggests: it is dominated by adaptive iterative attacks, while static obfuscation is near-fully neutralised. The strongest adaptive search (tree-of-attacks) breaks Opus 4.8 on 11.5% of intents overall, whereas Fable 5 stays in the single digits (6.1% worst-case). Aggregate rates therefore should not be read as reassurance. Even in these hardened configurations, the two models produced 1 620 (Opus 4.8) and 702 (Fable 5) panel-confirmed harmful completions spanning every harm category, located automatically, cheaply, and within the first one or two refinement steps by an attacker model with no human expert in the loop. The reasonable conclusion is that even the best, most-tested frontier models remain reliably breakable under sustained automated pressure.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes