OWASP LLM Top 10

The OWASP LLM Top 10 is the authoritative ranking of the most critical vulnerabilities in language models. It guides red teams, developers, and auditors in prioritizing security work.

See the workflow →

The Four Phases

An attack follows a repeatable, documented process.

  • Threat modeling
  • Impact assessment
  • Prioritization
  • Remediation

Core Concepts

The foundations of understanding these vulnerabilities and controls.

The Ten Critical Risks

OWASP ranks ten vulnerability categories by prevalence and severity. Each maps to real attack techniques: prompt injection, insecure output, training data poisoning, model denial of service, and more. Understanding the ranking helps focus security investment.

  • LLM01: Prompt Injection — breaking model instructions
  • LLM02: Insecure Output Handling — code execution via LLM output
  • LLM03: Training Data Poisoning — manipulating model behavior
  • LLM04: Model Denial of Service — resource exhaustion attacks

Mapping Risks to Remediation

Each risk requires specific detection and prevention strategies. Prompt injection needs input validation; poisoning needs data provenance; DoS needs rate limiting. The Top 10 provides the roadmap.

  • Detection: identify which risks affect your application
  • Testing: red team each risk category systematically
  • Controls: implement guardrails, monitoring, and incident response
  • Governance: track remediation and compliance over time

The Implementation Workflow

Each phase is methodical and repeatable. No phase is skipped; each has clear objectives.

Understand each risk category

Read the OWASP LLM Top 10 entries. Map them to your architecture.

Assess exposure in your systems

Which risks apply to your use case? Model? Deployment?

Prioritize fixes by business impact

Does injection affect customer data? Does DoS impact availability?

Implement controls and retest

Deploy mitigations, verify effectiveness, update your risk register.

Related Pages

Deep dives into related attack and defense topics.

LLM Red Teaming

Systematic testing of all ten risks via red team campaigns.

Prompt Injection Attacks

Deep dive into OWASP 01 and detection strategies.

Model Extraction & Privacy Attacks

Covering extraction and privacy risks (LLM09).

MITRE ATLAS Framework

Linking OWASP risks to adversarial tactics and techniques.