Explained: The OWASP Top 10 for Large Language Model Applications

Поділитися
Вставка
  • Опубліковано 2 чер 2024
  • OWASP Top 10 for Large Language Model Applications → ibm.biz/BdMzY4
    AI for cybersecurity → ibm.biz/BdMzYR
    Large Language Models (LLMs), like any new technology, are subject to the risk that "malicious actors" will abuse it for financial or other gain by attempting to circumvent built-in security measures. The well-known Open Worldwide Application Security Project or OWASP project has recently published their list of top 10 security risks for LLMs. In this video, IBM Distinguished Engineer Jeff Crume explains a subset of them and what you can do to protect you and your users.
    Get started for free on IBM Cloud → ibm.biz/buildonibmcloud
    Subscribe to see more videos like this in the future → ibm.biz/subscribe-now
    00:00 - What is the OWASP Top 10 for LLMs?
    01:25 - Prompt Injection (Direct)
    03:37 - Prompt Injection (Indirect)
    06:43 - Insecure Output Handling
    08:55 - Training Data
    11:46 - Over Reliance

КОМЕНТАРІ • 16

  • @carol-lo
    @carol-lo 9 місяців тому +1

    Great session as always

  • @ravi4044
    @ravi4044 9 місяців тому +2

    Great explanation 👏🏽

  • @tgau
    @tgau 7 місяців тому +1

    If I could, I'd give two 👍
    Easy to understand and precise.
    Thank you.

    • @jeffcrume
      @jeffcrume 7 місяців тому

      Thanks so much, @tgau!

  • @tombesore
    @tombesore 4 місяці тому +2

    Terrific content but I'd like to suggest a change in the title to "Top 3 plus Bonus!" What happened to the other 7?

    • @jeffcrume
      @jeffcrume 4 місяці тому +1

      Unfortunately, we have to keep it shorter for this format so I do the best I can with tight time constraints

  • @rsharma7197
    @rsharma7197 3 місяці тому +1

    Very good session on the 3 of the Top 10. Where can I listen to the remaining?

    • @jeffcrume
      @jeffcrume 3 місяці тому

      Thanks! I didn’t figure most viewers would want a video that long but you can read about the rest at the link in the description

  • @tyrojames9937
    @tyrojames9937 9 місяців тому +1

    INTERESTING!😁

  • @christopherpetersen342
    @christopherpetersen342 9 місяців тому +2

    Your example about training data isn't actually about "training" data, since the LLM is already trained and just pulling in poisoned data at run-time. Otherwise, very good stuff...

  • @Matinirx
    @Matinirx 9 місяців тому +1

    There's always somebody that's going to come in and gum up the works 🙃

    • @jeffcrume
      @jeffcrume 9 місяців тому +1

      It think it’s one of the immutable laws of the universe 😂

  • @pankaj16octdogra
    @pankaj16octdogra 9 місяців тому +3

    Wow, l like video series, this is new technology Netflix

    • @jeffcrume
      @jeffcrume 9 місяців тому

      I’m so glad you like it! And you can’t beat the price! 😂

  • @bastabey2652
    @bastabey2652 9 місяців тому +3

    "LLM is NOT a trusted user"... ouch

  • @bobanmilisavljevic7857
    @bobanmilisavljevic7857 9 місяців тому +1

    🔥