Cyver core supports the OWASP TOP 10 for Large Language Model (LLM) Applications v1.0 Checklist. This is a critical, new standard designed to address the emerging security risks specific to applications that integrate or are built upon LLMs.
General Information on the OWASP TOP 10 for LLMs
The frenzy of interest in LLMs and their rapid adoption following the mass-market release of pretrained chatbots in late 2022 created a significant security gap. Businesses, eager to harness LLM potential, often integrated them at breakneck speed, outpacing the establishment of comprehensive security protocols. This OWASP list was created to provide a unified resource, helping developers and security professionals understand and mitigate the unique vulnerabilities introduced by LLM integration.
OWASP TOP 10 for LLMs v1.0
- LLM01 – Prompt Injection
- LLM02 – Insecure Output Handling
- LLM03 – Training Data Poisoning
- LLM04 – Model Denial of Service
- LLM05 – Supply Chain Vulnerabilities
- LLM06 – Sensitive Information Disclosure
- LLM07 – Insecure Plugin Design
- LLM08 – Excessive Agency
- LLM09 – Overreliance
- LLM10 – Model Theft
Download
You can directly download the latest OWASP TOP 10 for LLMs Checklist from our GitHub repository: