Description:
- Without proper guardrails, generative AI models might generate code that causes harm or unintentionally affects other systems (e.g., via SQLi) or the end user (e.g., via XSS).
Impact:
- Varied based on the nature of the harmful code generated.
Applies to which types of AI models? Generative AI specifically
- Which AI security requirements function against this threat? [?]
-
- Control function: Corrective
- Control function: Detective
- Control function: Directive
- Control function: Preventative
- Control function: Variance reduction
- Discussed in which authoritative sources? [?]
-
- OWASP AI Exchange
2024, © The OWASP Foundation- Where:
- OWASP Top 10 for LLM Applications
Oct. 2023, © The OWASP Foundation- Where:
- LLM02: Insecure output handling
- LLM02: Insecure output handling
- Where:
- OWASP AI Exchange
- Discussed in which commercial sources? [?]
-
- AI Risk Atlas
2024, © IBM Corporation
- AI Risk Atlas