Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release episode artwork

EPISODE · Oct 31, 2023 · 51 MIN

Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release

from The Application Security Podcast · host Chris Romeo

The first OWASP Top 10 for Large Language Model Applications gave developers and security teams a shared threat model for a rapidly changing technology. Project leaders Steve Wilson and Gavin Klondike walk through the inaugural list and explain why familiar controls need to be reconsidered around probabilistic systems. They cover prompt injection, insecure output handling, training-data poisoning, denial of service, supply-chain vulnerabilities, sensitive information disclosure, insecure plugin design, excessive agency, overreliance, and model theft. Along the way, they distinguish application risks from attacks on the underlying model and show how plugins and autonomous actions can enlarge the blast radius. The episode closes with what the project learned from community feedback and how the list would evolve as real-world LLM deployments exposed new failure modes.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Wilson and Gavin Klondike:→ Steve Wilson on LinkedIn→ Gavin Klondike on LinkedIn→ OWASP GenAI Security ProjectMentioned in this episode:→ OWASP Top Ten for LLM Applications project homepage→ OWASP Top 10 For LLMs 2023 Slides V1 1→ ChatGPT→ LangChain→ Tay (Microsoft chatbot)→ DEF CONFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introducing the OWASP Top 10 for LLM Applications01:37 A threat model for large language models05:39 Risk 1 — Prompt injection09:00 Risk 2 — Insecure output handling11:35 Risk 3 — Training-data poisoning15:14 Risk 4 — Model denial of service19:11 Risk 5 — Supply-chain vulnerabilities28:16 Risk 6 — Sensitive information disclosure33:28 Risk 7 — Insecure plugin design38:27 Risk 8 — Excessive agency42:39 Risk 9 — Overreliance46:31 Risk 10 — Model theft49:56 Lessons for the next release

Episode metadata supplied by the publisher feed · Published Oct 31, 2023

Embed this episode

The first OWASP Top 10 for Large Language Model Applications gave developers and security teams a shared threat model for a rapidly changing technology. Project leaders Steve Wilson and Gavin Klondike walk through the inaugural list and explain why familiar controls need to be reconsidered around probabilistic systems. They cover prompt injection, insecure output handling, training-data poisoning, denial of service, supply-chain vulnerabilities, sensitive information disclosure, insecure plug...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release

0:00 51:43

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 51 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 31, 2023.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!