当前位置:首页 > 报告详情

OWASP:LLM AI安全与治理清单(英文版)(29页).pdf

上传人: AG 编号:606149 2024-01-01 29页 3.28MB

1、LLM AI Security&Governance ChecklistFrom the OWASP Top 10for LLM Applications TeamRevision HistoryRevisionDateAuthor(s)Description0.12023-11-01Sandy Dunninitial draft0.52023-12-06SandyDunn,OWASPLLMApps Teampublic draftVersion:0.5Published:December 6,2023The information provided in this document does

2、 not,and is not intended to,constitute legal advice.All information is for general informational purposes only.This document contains links to other third-party websites.Such links are only for convenienceand OWASP does not recommend or endorse the contents of the third-party sites.1Overview.41.1Res

3、ponsible and Trustworthy Artificial Intelligence.61.2Who is This For?.71.3Why a Checklist?.82Large Language Model Challenges.92.1LLM Threat Categories.102.2Artificial Intelligence Security and Privacy Training.102.3IncorporateLLMSecurityandgovernancewithExisting,EstablishedPracticesandControls102.4F

4、undamental Security Principles.112.5Risk.112.6Vulnerability and Mitigation Taxonomy.113Determining LLM Strategy.123.1Deployment Strategy.134Check List.144.1Adversarial Risk.144.2AI Asset Inventory.144.3AI Security and Privacy Training.144.4Establish Business Cases.154.5Governance.154.6Legal.164.7Reg

5、ulatory.174.8Using or Implementing Large Language Model Solutions.185Resources.19ATeam.29OverviewEvery internet user and business should prepare for the impact of a surge in powerful generativeartificial intelligence(GenAI)applications.GenAI holds enormous promise and opportunities fordiscovery,effi

6、ciency,and driving corporate growth across many industries and disciplines.However,as with any strong new technology,it introduces new challenges to security and privacy.Artificial Intelligence,Machine Learning,Large Language Models,and Diffusion Models have beenin development and the focus of acade

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要内容为OWASP针对大型语言模型(LLM)应用的安全与治理清单,旨在帮助组织快速了解LLM的风险与益处,并制定全面的安全策略。清单包括: 1. LLM应用概述,包括AI、机器学习、LLM和扩散模型的定义,以及LLM与AI的关系。 2. LLM面临的挑战,如非确定性、语义搜索、幻觉等,以及如何通过限制和实用性之间的权衡来提高可靠性和减少攻击面。 3. 确定LLM策略,包括部署策略、风险评估、安全原则、漏洞分类和治理等。 4. 清单,包括对抗风险、AI资产清单、安全与隐私培训、业务案例、治理、法律、监管和LLM解决方案的使用或实施等。 5. 资源,包括OWASP、MITRE和其他组织的资源,以及AI漏洞库和采购指南。 本文强调LLM应用增加了组织的攻击面,并提出了新的挑战,需要特殊的战术和防御措施。同时,LLM也带来了与已知问题相似的问题,因此,将LLM网络安全与组织的现有网络安全控制、流程和程序相结合,可以减少组织对威胁的脆弱性。
如何评估LLM应用的风险? 如何确保LLM应用的合规性? 如何提高LLM应用的安全性?
客服
商务合作
小程序
服务号
折叠