Securing LLM Applications: OWASP Top 10 Threats and Defenses

Added:

Architecture Overview
LLM Top 10
Prompt Injection
Defense Mechanics
Data Disclosure
Excessive Agency

Architecture Overview

0:00
Playing Section
  • 1

    Introduces the talk's agenda and speaker background.

  • 2

    Explains how LLM applications are typically built.

  • 3

    Highlights the shift from simple RAG to agentic systems.

Basic understanding of Large Language Models (LLMs), including prompt engineering, system prompts, and how model weights generate text.
Familiarity with foundational cybersecurity principles, particularly traditional injection vulnerabilities like SQL Injection and Cross-Site Scripting (XSS).
An understanding of application architecture, specifically how LLMs connect to external systems, databases, and APIs via tools or agents.
Concepts of identity and access management (IAM), including the principle of least privilege and access control mechanisms.
Implementation of LLM guardrail frameworks (such as NeMo Guardrails or Llama Guard) to filter adversarial inputs and unsafe model outputs.
Advanced LLM Red Teaming techniques to proactively discover system vulnerabilities, logical bypasses, and indirect prompt injections.
Designing secure agentic workflows that restrict LLM autonomy, mitigating 'excessive agency' through human-in-the-loop (HITL) verification and sandbox environments.
Alignment with AI governance frameworks, threat modeling (e.g., STRIDE for AI), and emerging standards such as the NIST AI Risk Management Framework.
5.5K views152likes28:32@OWASPGLOBALOriginal Release: 2025-07-02

The OWASP Top 10 for LLMs identifies critical security vulnerabilities in large language model applications, with prompt injection (where attackers manipulate LLM behavior through crafted inputs) and excessive agency (where LLMs perform unintended actions beyond their intended scope) being among the most common and dangerous threats. Prompt injection can be mitigated through parameterization and sanitization of inputs, while excessive agency requires strict access controls, command whitelisting, and sandboxing to prevent unauthorized system interactions.