The surge in popularity of Large Language Models (LLMs) since the widespread introduction of pre-trained chatbots in late 2022 has been astonishing. Companies are swiftly incorporating them into their systems and customer-facing services — but the pace of adoption has outstripped the development of robust security measures.
There was a clear gap in consolidated resources addressing the security issues specific to LLMs. OWASP's Top 10 for LLM Applications fills that gap, cataloguing the most critical risks so developers can integrate the technology more securely.
The OWASP Top 10 for LLMs
- LLM01 — Prompt Injection: malicious input that directly or indirectly manipulates the model to alter its behaviour, bypass controls, or reveal sensitive information.
- LLM02 — Sensitive Information Disclosure: the model or its application unintentionally reveals personal data, proprietary code or confidential details.
- LLM03 — Supply Chain Vulnerabilities: weaknesses in development, training or deployment components, including insecure third-party models and datasets.
- LLM04 — Data and Model Poisoning: corruption of pre-training, fine-tuning or embedding data, leading to biased or exploitable behaviour.
- LLM05 — Improper Output Handling: insufficient validation of model output, enabling XSS, server-side injection or remote code execution downstream.
- LLM06 — Excessive Agency: granting the model too much autonomy over external systems without sufficient oversight.
- LLM07 — System Prompt Leakage: disclosure of hidden system-level instructions that can expose operational details or aid further attacks.
- LLM08 — Vector and Embedding Weaknesses: manipulation of vector representations, potentially allowing data exfiltration or denial of service.
- LLM09 — Misinformation: generation of incorrect or misleading information ("hallucinations") that undermines reliability and trust.
- LLM10 — Unbounded Consumption: insufficient limits on resource usage, leading to denial of service or financial exploitation.
Understanding these risks is the first step towards deploying LLM features safely. Our LLM assessment service tests your applications against this framework and provides clear, prioritised remediation guidance.
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.