OWASP AI Exchange

OWASP AI Exchange

计算机和网络安全

Global exchange of AI security expertise, for standards alignment, collaboration, and feeding into the AI Act standards.

关于我们

The OWASP AI Exchange is as a collaborative working document at owaspai.org to advance the development of global AI security standards and regulations. It provides a comprehensive overview of AI threats, vulnerabilities, and controls to foster alignment among different standardization initiatives. This includes the EU AI act, ISO/IEC 27090 (AI security), the OWASP ML top 10, OWASP LLM top 10, and OpenCRE - which we want to use to provide the AI Exchange content through the security chatbot OpenCRE-Chat Our mission is to be the authoritative source for consensus, foster alignment, and drive collaboration among initiatives - NOT to set a standard. By doing so, it provides a safe, open, and independent place to find and share insights for everyone.

网站
https://owaspai.org/
所属行业
计算机和网络安全
规模
2-10 人
类型
非营利机构

OWASP AI Exchange员工

动态

  • 查看OWASP AI Exchange的公司主页,图片

    2,440 位关注者

    Our very own Susanna spreading the AI security word.

    查看Threat Modeling Connect的公司主页,图片

    2,124 位关注者

    How does the role of data in AI systems change the attack surface? How do you apply that knowledge to understand and approach AI threats? We had an insightful session at our monthly Global Meetup yesterday led by ???? Disesdi Susanna Cox, a true AI security pioneer who offered her insights and shared three approaches to understanding AI-specific threats: ?? NIST AI 100-2e2023 (CIA model, applied to AI) ?? OWASP AI Exchange (Dev/Deployment phases, MLSecOps) ?? Boolean path threat model + OODA Loop (Game theoretic, boolean, OODA). She also suggested three steps to understanding the AIML system attack surfaces: 1?? Know your data flows 2?? Know your data provenance 3?? Know your data governance Missed the session? Catch the full recap and recording (link in comments)?? ?? Huge thanks to our amazing facilitator team Audrey Long Claire Allen-Addy CMktr Robin Abraham Ninan Dimitri Redant Fraser 'zeroXten' Scott?for making this session extremely collaborative with the peer group discussions they led! ?

    • 该图片无替代文字
  • 查看OWASP AI Exchange的公司主页,图片

    2,440 位关注者

    Watch the recording of our very own Eng. Behnaz Karimi giving a nice overview of the AI Exchange at the OWASP Germany day 2024. Well done Behnaz! #ai #aisecurity

    查看Eng. Behnaz Karimi的档案,图片

    Co-Lead OWASP AI Exchange/Senior Cyber Security Analyst- Master AI Security Engineer at Accenture | Ransomware | SIEM/SOAR/SOC | Mentor at ISACA

    Yesterday, I had the pleasure of speaking at OWASP Germany about the OWASP AI Exchange and the pivotal role of AI security in today’s world. We covered: ? How the OWASP AI Exchange is driving guidance, standards, and resources to tackle emerging AI security challenges ? The roadmap toward building a secure, responsible future in AI ? The OWASP AI Exchange framework, which addresses evolving security challenges in AI systems ? An overview of the OWASP AI Exchange's mission to foster collaboration and align AI security standards across industries ? Controls and countermeasures from the OWASP AI Exchange to mitigate risks throughout the AI lifecycle ? How organizations can leverage the AI Exchange to improve governance, implement best practices, and ensure the confidentiality, integrity, and availability of AI systems A big thank you to our amazing expert group at OWASP AI Exchange for their incredible work. Special thanks to Rob van der Veer, Chris Ancharski and Aruneesh Salhotra for their leadership and unwavering support. It’s inspiring to be part of such a dedicated team! Thank you to OWASP Germany for having me, and to Dirk Wetter for your engagement. And huge thanks to everyone who joined. Let’s keep pushing the boundaries together for a safer AI landscape. https://lnkd.in/eZnNKuSr ?#OWASP #AI #Cybersecurity #AIExchange #OWASPAI

    • 该图片无替代文字
    • 该图片无替代文字
    • 该图片无替代文字
    • 该图片无替代文字
    • 该图片无替代文字
  • 查看OWASP AI Exchange的公司主页,图片

    2,440 位关注者

    The OWASP AI Exchange team regularly posts highlights from the material at owaspai.org. This week it's the References section, that today received a massive extension with training material, CTF resources, and AI security talks - kudos to author Zia Rashid. Have a look at https://lnkd.in/eeVSbXjW You may want to bookmark it. In fact, that is an important goal for us: be a primary bookmark for AI security practitioners out there. #ai #aisecurity

    • 该图片无替代文字
  • OWASP AI Exchange转发了

    查看Rob van der Veer的档案,图片

    Pioneer and veteran in AI, security, and software engineering | Senior principal expert at SIG | AI Act security standard co-editor | Advisor to ISO/IEC, OWASP, ENISA | Results: ISO/IEC 5338, owaspai.org and opencre.org

    Isn't it amazing and surreal, to finally meet people in person after years of working together online? The OWASP? Foundation is reporting live from Torino Italy, from its seat at the international standardization table - working closely with CEN and CENELEC groups and the European Commission to shape harmonized standards for the AI Act. Our focus? Building a robust AI Security Standard and solving some of the field's toughest challenges: - How can we confidently protect against data poisoning? - What does future-proof testing for evasion attacks look like? - How do we define countermeasures clearly, so there's no ambiguity for vendors and assessors? - And how do we balance clear guidance with the flexibility needed to support innovation? This is probably the biggest puzzle of my career. A heartfelt thanks to my peers at CEN/CENELEC—I’m constantly learning from you. To the incredible experts at the OWASP AI Exchange, thank you for your invaluable contributions. And to my team at Software Improvement Group, I’m grateful for the opportunity to share our research and insights to make a real difference. Let’s work together to make AI a force for good, and not the ideal target for malicious actors - which it currently is. In the picture, at the left hand, Annegrit Seyerlein-Klug Convenor, At the close right, Wei Wei, Editor, and me on the left, second row, co-editor, at the table with other representatives of WG5 and the European Commission. #ai #aisecurity #aiact

    • 该图片无替代文字
  • OWASP AI Exchange转发了

    查看OWASP? Foundation的公司主页,图片

    268,318 位关注者

    How can this possibly be free? Join some of the best with Rob van der Veer, Mackenzie Jackson, Tiago Teles, Philippe De Ryck, Olle E Johansson, Spandan Chandra, Irfaan Santoe, Robin van Loon, and Jim Manico later this month at OWASP BeNeLux Days Register now: https://lnkd.in/er67-kRf

    查看Rob van der Veer的档案,图片

    Pioneer and veteran in AI, security, and software engineering | Senior principal expert at SIG | AI Act security standard co-editor | Advisor to ISO/IEC, OWASP, ENISA | Results: ISO/IEC 5338, owaspai.org and opencre.org

    Security professionals, let's meet again at the OWASP BeNeLux Days in Utrecht, exactly a month from now: https://lnkd.in/er67-kRf I'm honored to close the event with the talk 'AI - the new beginning? A lighthearted talk about our end of days' and Software Improvement Group is sponsoring with a booth. My colleagues and I will be happy to discuss software quality and security with you and demo our Sigrid platform - enabling you to solve the tool soup, the broader software quality problem, and how to create alignment in the entire organization. Register for this free event, with great exhibitors and talks by Mackenzie Jackson, Tiago Teles, Philippe De Ryck, Olle E Johansson, Spandan Chandra, Irfaan Santoe, Robin van Loon, and Jim Manico! Also, check out the training sessions on the 29th. We are looking forward to seeing you on November 28th! OWASP? Foundation #ai #appsec #security

    • 该图片无替代文字
  • OWASP AI Exchange转发了

    查看Rob van der Veer的档案,图片

    Pioneer and veteran in AI, security, and software engineering | Senior principal expert at SIG | AI Act security standard co-editor | Advisor to ISO/IEC, OWASP, ENISA | Results: ISO/IEC 5338, owaspai.org and opencre.org

    How can we control AI security with timely, clear, comprehensive, and fair rules? I explored this question during my opening keynote at the annual?ETSI?Security Conference in Sophia Antipolis, France, representing Software Improvement Group. In his welcome message, Director General Jan Ellsberger emphasized the importance of preventing fragmented efforts - a sentiment we all share. Yet, the world hasn't found a way to unify standards effectively for practitioners. OpenCRE is part of the solution, connecting different standards, but the broader landscape remains fragmented. To address this, I’m committed to bringing experts together to tackle the urgent challenge of AI security. If we don’t, AI—due to its ubiquity— becomes the ideal attack vector for malicious actors. Securing AI is a new area for many, which makes our task even more critical. So, a call to action for all standard makers: work closely with your peers, and if that’s a challenge, at least let your experts engage in the OWASP AI Exchange to collaborate on shared research questions. See my slides: https://lnkd.in/e_y7ytvZ In the keynote, I discuss the fragmented standard landscapes, the development of the EU AI Act security standard, and a brief course on AI security, including data poisoning and indirect prompt injection. Event site: https://lnkd.in/edXrRRfb Let’s collaborate and make a difference, fellow experts. #ai #aisecurity #ETSISEC2024

    • 该图片无替代文字
  • OWASP AI Exchange转发了

    查看Eng. Behnaz Karimi的档案,图片

    Co-Lead OWASP AI Exchange/Senior Cyber Security Analyst- Master AI Security Engineer at Accenture | Ransomware | SIEM/SOAR/SOC | Mentor at ISACA

    ?? I am pleased to announce that I will be speaking at the OWASP Chapter Germany on "Overview of OWASP AI Exchange: A Comprehensive Guide to AI Security." In this session, I will provide an in-depth overview of the OWASP AI Exchange and its mission. I’ll delve into key aspects of AI security, offering insights and practical guidance for navigating the challenges we face today. ?? Event Details: German OWASP Day : Leipzig on November 12-13, 2024! I look forward to an engaging discussion and the opportunity to connect with fellow professionals dedicated to enhancing AI security. https://god.owasp.de/2024/ OWASP AI Exchange OWASP Germany #AIsecurity #OWASP #Cybersecurity #MLSecOps #AI

    German OWASP Day 2024

    German OWASP Day 2024

    god.owasp.de

  • 查看OWASP AI Exchange的公司主页,图片

    2,440 位关注者

    If you're in the neighborhood, come see the session on security and GenAI by our very own Niklas Bunzel. #ai #genai #aisecurity

    查看OWASP Germany的公司主页,图片

    702 位关注者

    We're thrilled to announce the second and last round of speakers/talks for the German OWASP Day in Leipzig on November 13th: * Ing. Behnaz Karimi will give us an overview of the OWASP AI Exchange project * Niklas Bunzel and Raphael Antonius Frick will explore the security challenges and opportunities posed by GenAI * Clemens Hübner will amend that showing how GenAI can help identifying threats * Hanno B?ck will tell not-so-good stories about private keys * Florian Hantke and Sebastian Roth will show how to scan for Vulnerabilities Without Getting Into Trouble * ??? Diana C. will explore strategies for creating and implementing Security Champion programs in organisations * Malte Wessels will display results of his research on SSRF Full program will be announced RSN on the web site. This is first hand information, as one week ago! Registration is open. Reserve your spot! https://god.owasp.de/

  • OWASP AI Exchange转发了

    查看Rob van der Veer的档案,图片

    Pioneer and veteran in AI, security, and software engineering | Senior principal expert at SIG | AI Act security standard co-editor | Advisor to ISO/IEC, OWASP, ENISA | Results: ISO/IEC 5338, owaspai.org and opencre.org

    I feel incredibly grateful for the opportunity to help design our future with AI, in a whirlwind of a time! ?? Monday: Keynote on AI security for Siemens Industrial Software. ?? Tuesday: Two podcasts with Caitlin Begg on AI adoption. ?? Wednesday: Incredible launch party of ’Luna and the Magic AI Paintbrush’ with co-author, publisher, and superwoman Bessie Schenk. ?? Thursday: Book signing at the World Summit AI and a talk on our future with AI. ?? Friday: Lead a workshop day on AI strategy with a client. And that’s just the start. Next week, I’m looking forward to: ?? Monday: Opening the ETSI security conference in Cannes, advocating broad collaboration on AI security standards. ?? Tuesday: Launching the Software Improvement Group AI Readiness Guide! ?? Wednesday: Article on the partnership I set between CEN and CENELEC - OWASP? Foundation, and how it positions the OWASP AI Exchange. ?? Thursday: Panellist at the European Cyber Security Organisation (ECSO) high-level event in Brussels. ?? Friday: Security event with Brenno de Winter who has another brilliant idea. Thank you to everyone who has listened, participated, and engaged with my work. Your input and feedback make this journey worthwhile. I’m just a guy trying to make sense of it all. As I shared in my summit talk, we all wonder: What is our future with AI? The best answer is, “We don’t know” because it keeps us both curious and cautious. In the end, WE decide: - We decide if we’ll use AI to attend and summarize our meetings. - We decide if we’ll drive in cars that almost do everything right. - We decide how we collaborate with AI while maintaining our skills. -We decide if we’ll put AI in weapons, knowing the risks of data poisoning and evasion attacks. We should explore and make mistakes. But we must also be willing to step back, reflect, and help others do the same. Thank you for joining me on this journey. I should also mention Luc Brandts, Wouter Knigge, Olivia Gambelin, Petri Myllym?ki, Yiannis Kanellopoulos, Peter Boersma, Birgit Geiberger, Paul El Khoury, Arman Iranfar, Huub Janssen, Florence Mottay, Pavel Cholakov, Meindert Kamphuis, and Franjo Bartels. #ai #responsibleai #aisecurity

    • 该图片无替代文字
    • 该图片无替代文字
    • 该图片无替代文字
    • 该图片无替代文字
    • 该图片无替代文字

相似主页