Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 15 additions & 16 deletions index.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,37 +7,36 @@ tags: example-tag
pitch: Aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs)
---

The OWASP Top 10 for Large Language Model Applications project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs). The project provides a list of the top 10 most critical vulnerabilities often seen in LLM applications, highlighting their potential impact, ease of exploitation, and prevalence in real-world applications. Examples of vulnerabilities include prompt injections, data leakage, inadequate sandboxing, and unauthorized code execution, among others. The goal is to raise awareness of these vulnerabilities, suggest remediation strategies, and ultimately improve the security posture of LLM applications. You can read our [group charter](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Charter) for more information
Note: This page is being updated please go to our primary public website for the latest assets [Project Website](https://genai.owasp.org)

Review the official 1.1 release ([Full Version](assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf) or [Short Slides](assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_1.pdf)) to understand work that has been done to date.
The OWASP Top 10 for Large Language Model Applications project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs). The project provides a list of the top 10 most critical vulnerabilities often seen in LLM applications, highlighting their potential impact, ease of exploitation, and prevalence in real-world applications. Examples of vulnerabilities include prompt injections, data leakage, inadequate sandboxing, and unauthorized code execution, among others. The goal is to raise awareness of these vulnerabilities, suggest remediation strategies, and ultimately improve the security posture of LLM applications.

# 📢 New Document Release: Security & Governance Checklist
You can read our [group charter](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Charter) for more information

We're excited to announce version 1.0 of our latest document: **Security & Governance Checklist**. This comprehensive guide is essential for a Chief Information Security Officer (CISO) managing the rollout of Gen AI technology in their organization.
Review the official 2023 1.1 release [Full Version](https://genai.owasp.org/resource/llm-top-10-for-llms-v1-1/)
or [Short Set of Slides](assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_1.pdf))to view the latest versions.

🔗 [Download the PDF here](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1.1.pdf) - also now [available in French](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_FR.pdf) and [Japanese](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_1_JP.pdf)
# 📢 Full list of Documents and Resources

You can view the full list of documents and resources for the project including the : **Security & Governance Checklist**. This comprehensive guide is essential for a Chief Information Security Officer (CISO) managing the rollout of Gen AI technology in their organization.

# 📢 New Website Launched: Check us out there as well
[View all the resources](https://genaai.owasp.org

We have launched a [new website](https://genai.owasp.org) to complement this one.
🔗 [Download the PDF here](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1.1.pdf) - also now [available in French](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_FR.pdf) and [Japanese](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_1_JP.pdf)

This initiative is community-driven and encourages participation and contributions from all interested parties.
# 📢 Join us on Slack

- We have a working group channel on the [OWASP Slack](https://owasp.org/slack/invite), so please sign up and then join us on the #project-top10-for-llm channel.
- The working group is collaborating on our [wiki](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki)
- Want to stay updated on periodic progress? [Subscribe to our newsletter](https://llmtop10.beehiiv.com/subscribe) or [Follow our project LinkedIn page](https://www.linkedin.com/company/owasp-top-10-for-large-language-model-applications/)

New to LLM Application security? Check out our [resources page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources) to learn more.



## Project Sponsorship

### Learn how to become an [OWASP LLM Project Sponsor/Donor](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Donors-and-Project-Sponsors).

We are just launching a new project sponsor program. The OWASP Top 10 for LLMs project is a community-driven effort open to anyone who wants to contribute. The project is a non-profit effort and sponsorship helps to ensure the project's sucess by providing the resources to maximize the value communnity contributions bring to the overall project by helping to cover operations and outreach/education costs. In exchange, the project offers a number of benefits to recognize the company contributions.

Sponsors
See our complete list of sponsors here.

## Supporters
## Sponsors
See our complete list of sponsors [here.](https://genai.owasp.org/supporters/)

Sponsor Logos Comming soon.
2 changes: 1 addition & 1 deletion info.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
### Top 10 for Large Language Model Applications Information
* [Lab Status Project](https://owasp.org/projects/)
* [Production Status Project](https://owasp.org/projects/)
<!--* [Version 2.0 - **In progress**](https://www.linkedin.com/pulse/announcing-owasp-top-10-large-language-model-v20-project-steve-wilson-an6jc?trk=public_post_feed-article-content)-->
* [Version 1.1.0 Translations](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/tree/main/assets/translations)
* [Version 1.1.0](assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf)
Expand Down
Binary file not shown.
1 change: 1 addition & 0 deletions initiatives/Data Gathering and Security/readme.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@

1 change: 1 addition & 0 deletions initiatives/RedTeaming/readme.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@

1 change: 1 addition & 0 deletions initiatives/SecureAIAdoption/readme.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@

1 change: 1 addition & 0 deletions initiatives/Threat Intelligence/readme.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@