Coder Social home page Coder Social logo

rubenszimbres / www-project-top-10-for-large-language-model-applications Goto Github PK

View Code? Open in Web Editor NEW

This project forked from talesh/www-project-top-10-for-large-language-model-applications

1.0 1.0 0.0 276.91 MB

OWASP Foundation Web Respository

License: Other

Shell 4.53% Ruby 0.10% CSS 2.36% TeX 90.09% Makefile 2.01% HTML 0.91%

www-project-top-10-for-large-language-model-applications's Introduction

www-project-top-10-for-large-language-model-applications

OWASP Foundation Web Repository

OWASP Top 10 for Large Language Model Applications

OWASP Lab Status project License: CC BY-SA 4.0 llmtop10.com

Welcome to the official repository for the OWASP Top 10 for Large Language Model Applications!

Overview and Audience 🗣️

The OWASP Top 10 for Large Language Model Applications is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to Large Language Model (LLM) applications. There are other ongoing frameworks both inside and outside of OWASP that are not to be confused with this project and is currently scoped towards only LLM Application Security.

Our primary audience is developers, data scientists, and security experts tasked with designing and building applications and plugins leveraging LLM technologies. We aim to provide practical, actionable, and concise security guidance to help these professionals navigate the complex and evolving terrain of LLM application security.

Key Focus 📖

The primary aim of this project is to provide a comprehensible and adoptable guide to navigate the potential security risks in LLM applications. Our Top 10 list serves as a starting point for developers and security professionals who are new to this domain, and as a reference for those who are more experienced.

Mission Statement 🚀

Our mission is to make application security visible, so that people and organizations can make informed decisions about application security risks related to LLMs. While our list shares DNA with vulnerability types found in other OWASP Top 10 lists, we do not simply reiterate these vulnerabilities. Instead, we delve into these vulnerabilities’ unique implications when encountered in applications utilizing LLMs.

Our goal is to bridge the divide between general application security principles and the specific challenges posed by LLMs. The group’s goals include exploring how conventional vulnerabilities may pose different risks or be exploited in novel ways within LLMs and how developers must adapt traditional remediation strategies for applications utilizing LLMs.

Contribution 👋

The first version of this list was contributed by Steve Wilson of Contrast Security. We encourage the community to contribute and help improve the project. If you have any suggestions, feedback or want to help improve the list, feel free to open an issue or send a pull request.

We have a working group channel on the OWASP Slack, so please sign up and then join us on the #project-top10-llm channel.

Please hop over to our wiki page to collaborate on the project and stay up to date with the latest meetings and current roadmap.

License

This project is licensed under the terms of the Creative Commons Attribution-ShareAlike 4.0 International License.

www-project-top-10-for-large-language-model-applications's People

Contributors

virtualsteve-star avatar ganggreentempertatum avatar talesh avatar rot169 avatar kenhuangus avatar rossja avatar jsotiro avatar gtklondike avatar owaspfoundation avatar emmanuelgjr avatar bobsimonoff avatar setotet avatar leondz avatar yodahash avatar hblankenship avatar shikida avatar manjesh24 avatar willchilcutt avatar azai91 avatar hashishrajan avatar davidprowe avatar dhruwen avatar jondot avatar humdr0id avatar lior-ps avatar pasanchamikara avatar sn4kecharmer avatar rfc-st avatar rubenszimbres avatar v4fs avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.