Securing the LLM Stack: The OWASP Top 10 for Large Language Model Applications
July 29 @ 12:00 pm - 1:00 pm CDT
If you have ever used the OWASP Top 10 for Web Application Security to guide a design review, threat model, or secure-coding standard, you already understand the value of a community-vetted, vendor-neutral risk baseline. This session introduces its counterpart for the era of generative AI.
Large language models are no longer isolated research artifacts — they are production components embedded in enterprise systems as copilots, retrieval-augmented search engines, and autonomous agents that call APIs, write code, and act on live data. Their arrival introduces a class of security failures that classical application security was not designed to catch: instruction injection through untrusted data, sensitive information surfacing from training corpora, supply-chain risks in opaque model weights, excessive agency in tool-enabled agents, and denial-of-wallet attacks on metered inference endpoints.
The OWASP GenAI Security Project — built by more than 600 contributors across 18 countries — has codified these failures into the 2025 Top 10 for LLM Applications. This 45-minute engineer-focused briefing walks the complete list: what each risk is, how it is exploited in real systems, how to defend against it, and where it maps in a production LLM architecture. Concrete examples ground each risk, a cross-category failure-chain case study shows how a single poisoned document can traverse six risk categories simultaneously, and a secure-by-design control blueprint translates the list into actionable design, build, deploy, and run guidance.
Speaker(s): Mike Bishop
Virtual: https://events.vtools.ieee.org/m/565506