Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Steve Wilson

Rating No ratings yet

Large language models (LLMs) are not just shaping the trajectory of AI, they're also unveiling a new era of security challenges. This practical book takes you straight to the heart of these threats. Author Steve Wilson, chief product officer at Exabeam, focuses exclusively on LLMs, eschewing generalized AI security to delve into the unique characteristics and vulnerabilities inherent in these models. Complete with collective wisdom gained from the creation of the OWASP Top 10 for LLMs list—a feat accomplished by more than 400 industry experts—this guide delivers real-world guidance and practical strategies to help developers and security teams grapple with the realities of LLM applications. Whether you're architecting a new application or adding AI features to an existing one, this book is your go-to resource for mastering the security landscape of the next frontier in AI. You'll learn Why LLMs present unique security challenges How to navigate the many risk conditions associated with using LLM technology The threat landscape pertaining to LLMs and the critical trust boundaries that must be maintained How to identify the top risks and vulnerabilities associated with LLMs Methods for deploying defenses to protect against attacks on top vulnerabilities Ways to actively manage critical trust boundaries on your systems to ensure secure execution and risk minimization

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# The Developer's Playbook for Large Language Model Security ## 【One-Line Pitch】 A practical, field-tested guide to securing LLM-based applications, written by the creator of the OWASP Top 10 for LLMs, covering everything from architecture fundamentals to hands-on defense strategies. Essential reading for developers, security engineers, and technical leaders building or planning AI-powered features. ## 【Book Arc】 - **Opening (~0%–6%)**: Introduces why LLMs create fundamentally new security challenges compared to traditional web applications, and lays out the book's three-part structure: foundations, vulnerabilities, and defense strategies. - **Early (~6%–16%)**: Walks through the origin story of the OWASP Top 10 for LLMs—how a machine-generated draft evolved into a global industry standard with input from 400+ experts—and establishes the core mindset of trust boundaries. - **Early (~16%–28%)**: Uses the Microsoft Tay disaster as a cautionary case study, showing how even well-intentioned, stress-tested AI systems can spiral out of control when adversarial users exploit learning-from-interaction features. - **Middle (~28%–44%)**: Explains LLM architecture fundamentals—neural networks, transformers, chatbots, copilots—and introduces the critical trust boundaries unique to LLM systems: user prompts, uploaded content, training data, databases, and plugins. - **Middle (~44%–53%)**: Dives deep into data trust boundaries, contrasting internally curated training data with "in-the-wild" public data, and explains how each presents distinct security risks including data poisoning, bias, and sensitive information leakage. - **Late (~53%–end)**: Moves into practical defense: rate limiting, input filtering, adversarial training, guardrails (open source vs. commercial), CI/CD security, supply chain management, and the RAISE framework for ongoing security assessment. ## 【Key Takeaways】 - **LLMs are not traditional software** (Early): Unlike web apps with predefined algorithms, LLMs generate dynamic responses from massive neural networks, creating a fundamentally different and still-nascent security landscape that demands new mental models. - **Trust boundaries are the core security concept** (Middle): Every data flow into and out of an LLM—user prompts, training data, databases, plugins—represents a boundary that must be explicitly managed, with different risk profiles for internal vs. external data sources. - **Training data is both power and vulnerability** (Middle): Internally curated data offers reliability but risks exposing sensitive information; public data provides scale but introduces poisoning, bias, and toxicity risks. The Tay incident shows the catastrophic cost of treating user input as trusted training data. - **The OWASP Top 10 for LLMs emerged from practical need** (Early): The list, born from a ChatGPT-generated draft and refined by 400+ experts, filled a massive gap in organized LLM security knowledge and quickly became a foundational reference adopted by government agencies. - **Adversarial users will exploit learning systems** (Early): Microsoft stress-tested Tay extensively, yet coordinated attacks from online communities overwhelmed the system within hours—demonstrating that traditional testing approaches are insufficient for interactive AI. - **Defense requires layered, LLM-specific controls** (Late): Rate limiting, rule-based filtering, special-purpose LLM filters, prompt structure, and adversarial training each address different attack vectors, and no single control is sufficient on its own. - **Guardrails are an emerging best practice** (Late): Both open source and commercial guardrail solutions exist, and the most effective approach typically combines packaged solutions with custom controls tailored to your specific application context. ## 【Reading Tips】 - **Skim the OWASP origin story** (Early): The history of how the Top 10 list was created is interesting context, but the actionable content is in the architecture and trust boundary chapters that follow. - **Deep-read the trust boundary chapters** (Middle, ~38%–53%): This is the conceptual heart of the book. Understanding the different data flow boundaries—user interactions, training data, databases, plugins—is essential before moving to defense strategies. - **Pay special attention to the Tay case study** (Early, ~25%–28%): This isn't just a cautionary tale; it's a concrete example of how multiple trust boundary failures compound. Use it to test your understanding of the boundary concept. - **Use the defense chapters as a reference** (Late): The mitigation techniques—rate limiting, filtering, adversarial training, guardrails—are best absorbed as a toolkit to consult when designing specific features rather than read straight through. - **Look for the RAISE framework** (Late, ~16% of book): This appears to be a structured checklist for ongoing security assessment; if you're a practitioner, this may be worth extracting and adapting for your own processes. ## 【Coverage Limits】 The excerpts primarily cover the book's conceptual foundations (chapters 1–3) and partial middle content on trust boundaries and data security. Detailed coverage of specific vulnerabilities (prompt injection, excessive agency) and the full defense strategy chapters (7–12) is not fully represented in the available material. ##
Page 4
ook for Large Language Model Security, readers embark on an entertaining and exciting journey to the LLM security frontier. Steve Wilson provides a compass t...
View in text
Page 14
of RAM. But I still managed to cram a complete clone of the Tron Lightcycles game onto that machine, complete with a simple but effective AI to drive one of...
View in text
Excerpt 3
a of whether my Top 10 list looked novel and worth pursuing. Jeff encouraged me to petition the OWASP board for approval to spin it up as a new project. A fe...
View in text
Excerpt 4
pon which LLMs build their understanding and capa‐ bilities. Whether used for initial training or subsequent fine-tuning, the nature and source of this data...
View in text
Excerpt 5
ce between the user and the LLM. Indirect injections can be harder to spot as they can be embedded in external sources and may not be immediately visible to...
View in text
Excerpt 6
our model might disclose this information to a third party. Here are some risks you’ll want to consider as you craft the dataset for training your model: Dir...
View in text
Excerpt 7
en‐ tiality of the data they manage. Reducing database risk Here are some ideas for best practices and mitigation strategies for reducing the risks of sensit...
View in text
Excerpt 8
de, which may include the same hallucination. Examples | 67 awareness, improves accuracy, and provides a mechanism for sourcing the generated content, thus c...
View in text
Tags
AI categories
Artificial IntelligenceCybersecurityBackend
ISBN: 109816220X
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 200
File Format: PDF
File Size: 4.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…