OWASP LLM Top 10
The OWASP LLM Top 10 is the authoritative ranking of the most critical vulnerabilities in language models. It guides red teams, developers, and auditors in prioritizing security work.
See the workflow →The Four Phases
An attack follows a repeatable, documented process.
- Threat modeling
- Impact assessment
- Prioritization
- Remediation
Core Concepts
The foundations of understanding these vulnerabilities and controls.
The Ten Critical Risks
OWASP ranks ten vulnerability categories by prevalence and severity. Each maps to real attack techniques: prompt injection, insecure output, training data poisoning, model denial of service, and more. Understanding the ranking helps focus security investment.
- LLM01: Prompt Injection — breaking model instructions
- LLM02: Insecure Output Handling — code execution via LLM output
- LLM03: Training Data Poisoning — manipulating model behavior
- LLM04: Model Denial of Service — resource exhaustion attacks
Mapping Risks to Remediation
Each risk requires specific detection and prevention strategies. Prompt injection needs input validation; poisoning needs data provenance; DoS needs rate limiting. The Top 10 provides the roadmap.
- Detection: identify which risks affect your application
- Testing: red team each risk category systematically
- Controls: implement guardrails, monitoring, and incident response
- Governance: track remediation and compliance over time
The Implementation Workflow
Each phase is methodical and repeatable. No phase is skipped; each has clear objectives.
Understand each risk category
Read the OWASP LLM Top 10 entries. Map them to your architecture.
Assess exposure in your systems
Which risks apply to your use case? Model? Deployment?
Prioritize fixes by business impact
Does injection affect customer data? Does DoS impact availability?
Implement controls and retest
Deploy mitigations, verify effectiveness, update your risk register.
Related Pages
Deep dives into related attack and defense topics.
LLM Red Teaming
Systematic testing of all ten risks via red team campaigns.
Prompt Injection Attacks
Deep dive into OWASP 01 and detection strategies.
Model Extraction & Privacy Attacks
Covering extraction and privacy risks (LLM09).
MITRE ATLAS Framework
Linking OWASP risks to adversarial tactics and techniques.