Contributing to the OWASP Top 10 for LLM
Steve Wilson
Gen AI and Cybersecurity - Leader and Author - Exabeam, OWASP, O’Reilly
The OWASP Top 10 for Large Language Model (LLM) Security project is a community-driven effort to identify and tackle the biggest security challenges in LLM applications. I get asked all the time by people who want to contribute how they can start. Your input is invaluable whether you’re a seasoned pro or just getting started. Here’s how you can get involved:
Check Out the Roadmap
To get a sense of where the project is headed, look at our roadmap. It outlines all the key milestones and goals for the upcoming version.
Knowing what’s coming up helps you see where you can make the most impact. Whether it’s giving feedback on proposed changes or suggesting new ideas, your contributions are crucial.
Participate in Surveys
One of the easiest ways to contribute is to respond to our surveys. We want to hear from you! Your insights help shape the project and ensure that we’re focusing on the most critical issues.
Recently we did a survey where we re-ranked the existing Top 10 vulns and then asked people for areas that needed further investigation.
Here are some of the areas identified by the survey for future research.
Suggest New Vulnerabilities
Have you spotted a new type of attack or weakness in LLM applications? We want to hear about it! Proposing new vulnerabilities is a fantastic way to contribute. Your real-world examples and suggestions for mitigating these issues help keep the OWASP Top 10 relevant and up-to-date.
Submitting a new vulnerability is easy! Just check out the instructions here. You can develop something new or rewrite an existing vuln with a new spin. It's up to you! This is a generative phase. You can get your ideas out. We'll prune and combine ideas later.
We've already had a ton of submissions, so get yours in now!
领英推荐
Get Involved!!!
Full details here: https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Contributing
Contribute to Additional Projects
In addition to the core OWASP Top 10 list, there are several other exciting projects you can get involved with. These projects offer more ways to contribute and make a difference in the field of LLM security.
CISO Checklist Project
The CISO Checklist Project aims to create a comprehensive checklist for evaluating the security of LLM applications. This checklist will serve as a valuable resource for Chief Information Security Officers (CISOs), helping them ensure their applications meet the highest security standards.
Data Gathering Project
The Data Gathering Project focuses on collecting real-world data on LLM security vulnerabilities. This data is crucial for understanding the prevalence and impact of different security issues, and it helps inform the OWASP Top 10 list and other initiatives.
By participating in these additional projects, you can help expand our understanding of LLM security and develop practical tools and resources for the community. Every bit of effort counts, and together we can make a significant impact.
Thanks, Steve. I will look into the information and contribute with my knowledge.
Cybersecurity Professionals | Certified Red Team Operator (CRTO) | CEH Practical | CSCU | AZ-900 | SC-900
5 个月Interesting ??
Empowering tech leaders with robust cybersecurity | Specializing in GenAI/LLM testing & Offensive Security | Senior Consultant with multi-industry pentest experience
5 个月Thanks Steve Wilson for putting out this article, always had this question in mind.
Capable, Collaborative, Professional, Cyber Security Leader | Vulnerability Management | Cyber Risk Assessment | Cyber Security | Operations Management | Threat Intelligence Analysis
5 个月Interesting!
CISSP, C|EH, CSSLP, Principal Software Engineer Raytheon, Adjunct Professor UMBC
5 个月Thanks for sharing