当前位置:首页 >英文主页 >中英对照 > 报告详情

OWASP:2025年大语言模型(LLM)应用十大安全风险洞察报告(英文版)(45页).pdf

上传人: 小*** 编号:1257974 2026-05-29 45页 10.22MB

下载:

1、OWASP PDF v4.2.0a 20241114-202703OWASP Top 10 forLLM Applications 2025Version 2025November 18,2024LICENSE AND USAGEThis document is licensed under Creative Commons,CC BY-SA 4.0.You are free to:Share copy and redistribute the material in any medium or format for any purpose,even commercially.Adapt re

2、mix,transform,and build upon the material for any purpose,even commercially.The licensor cannot revoke these freedoms as long as you follow the license terms.Under the following terms:Attribution You must give appropriate credit,provide a link to the license,and indicate if changes were made.You may

3、 do so in any reasonable manner,but not in any way that suggests the licensor endorses you or your use.ShareAlike If you remix,transform,or build upon the material,you must distribute your contributions under the same license as the original.No additional restrictions You may not apply legal terms o

4、r technological measures that legally restrict others from doing anything the license permits.Link to full license text:https:/creativecommons.org/licenses/by-sa/4.0/legalcodeThe information provided in this document does not,and is not intended to constitutelegal advice.All information is for gener

5、al informational purposes only.This document contains links to other third-party websites.Such links are only forconvenience and OWASP does not recommend or endorse the contents of the third-partysites.REVISION HISTORY 2023-08-01 Version 1.0 Release 2023-10-16 Version 1.1 Release 2024-11-18 Version

6、2025 ReleaseTable of ContentsLetter from the Project Leads .1Whats New in the 2025 Top 10 .1Moving Forward .2LLM01:2025 Prompt Injection .3Description .3Types of Prompt Injection Vulnerabilities.3Prevention and Mitigation Strategies .4Example Attack Scenarios.5Reference Links .6Related Frameworks an

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
1. **OWASP Top 10 for LLM Applications 2025**:发布于2024年11月18日,基于CC BY-SA 4.0许可,旨在解决LLM应用特有的安全风险。 2. **十大风险**:包括提示注入(LLM01)、敏感信息泄露(LLM02)、供应链风险(LLM03)、数据与模型投毒(LLM04)、输出处理不当(LLM05)、过度代理(LLM06)、系统提示泄露(LLM07)、向量与嵌入弱点(LLM08)、虚假信息(LLM09)、无界消耗(LLM10)。 3. **关键更新**:新增“无界消耗”(扩展拒绝服务风险)、“向量与嵌入弱点”(针对RAG安全)、“系统提示泄露”(应对现实攻击),并扩展“过度代理”以适应代理架构的自主性增强。 4. **防护策略**:强调最小权限、输入/输出过滤、人类审批、对抗测试等,结合MITRE ATLAS等框架提供实践指导。
注入攻击如何防御? 如何防止信息泄露? 供应链风险有哪些?
客服
商务合作
小程序
服务号
折叠