https://www.betabit.nl/en/betatalks
Jelle and Gerben discuss security in AI applications, exploring the threats and vulnerabilities that can arise when developing such applications, including those leveraging AI models, machine learning models, or large language model (LLM) chatbots. To determine how to build secure AI apps, they examine OWASP's efforts to identify common risks through their top 10 lists. They discuss the focus and shortcomings of these lists and how the theory behind them relates to securing actual applications. Jelle and Gerben take a closer look at the Machine Learning top 10 and the Large Language Model top 10. Based on these risks, they debate whether the top 10s help developers or if they pose risks themselves. While both agree that the lists play a key role in raising awareness and initiating important discussions, they disagree on whether the top 10s are a net positive. Specifically, they discuss potential categorization problems and the possible misuse of the top 10s as checklists.
Links for more information:
Machine Learning top 10: https://owasp.org/www-project-machine...
Large Language Model top 10: https://owasp.org/www-project-top-10-...
Consider donating to OWASP: https://owasp.org/donate/
Timestamps
00:00 - Introduction: security threats specific to AI applications
00:55 - What is OWASP?
02:31 - Defense in depth
03:30 - Supply chain weakness in modern AI applications
05:08 - The draft OWASP top 10 for machine learning
07:36 - What hackers want: your model and your data
08:30 - Discussion: top 10 lists for specific apps versus considering risks more holistically
10:17 - Discussion: how to categorize the top 10 items and top 10 lists
11:04 - Why we should avoid using top 10s as checklists
11:59 - The OWASP top 10 for large language models
13:00 - Discussion: unique risks, like overreliance on LLMs
14:16 - Walking through the top 10 for LLMs
16:16 - Visualizing security risks in an LLM architecture
18:06 - Discussion: are OWASP top 10s specific to AI apps useful?
19:08 - Risk applicability across different security scenarios
20:03 - Overview and closing remarks
There is more to come!
https://www.betabit.nl/en