Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incorrect placement of Prevention & Mitigation step for LLM #10 #392

Closed
harissohail55 opened this issue Jul 26, 2024 · 5 comments
Closed
Assignees
Labels
llm-10 Relates to LLM Top-10 entry #10

Comments

@harissohail55
Copy link

For the LLM10: Model Theft section, the second entry for "Common Examples of Vulnerabilities", should be shifted down to the "Prevention and Mitigation strategies" section.

Here is the entry:
"Use a centralized ML Model Inventory or Registry for ML models used in production.
baving a centralized model registry prevents unauthorized access to ML Models via
access controls, authentication, and monitoring/logging capability which are good
foundations for governance. baving a centralized repository is also beneficial for
collecting data about algorithms used by the models for the purposes of compliance,
risk assessments, and risk mitigation"

Copy link

👋 Thanks for reporting! Please ensure labels are applied appropriately to the issue so that the workflow automation can triage this to the correct member of the core team

@GangGreenTemperTatum GangGreenTemperTatum added the llm-10 Relates to LLM Top-10 entry #10 label Jul 27, 2024
@GangGreenTemperTatum GangGreenTemperTatum self-assigned this Jul 27, 2024
Copy link

👋 Thanks for reporting! Please ensure labels are applied appropriately to the issue so that the workflow automation can triage this to the correct member of the core team

@GangGreenTemperTatum
Copy link
Collaborator

Hi @harissohail55 , thanks for raising! I think you are looking at an old entry version perhaps
see updated version
https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/blob/main/2_0_vulns/LLM10_ModelTheft.md
and the website
image
image

@harissohail55
Copy link
Author

Hey @GangGreenTemperTatum, thanks for the heads up. Yep, I was looking at version 1.1. Didn't see that 2.0 had been released. On the main OWASP website - https://owasp.org/www-project-top-10-for-large-language-model-applications/, it sill only shows Version 1.1.0 as the current version:

image

@GangGreenTemperTatum
Copy link
Collaborator

thanks, we havent yet announced an official v2 :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
llm-10 Relates to LLM Top-10 entry #10
Projects
None yet
Development

No branches or pull requests

2 participants