Foundations
of GenAI Security & OWASP LLM Top 10
1.
Introduction to GenAI & Security Basics
- What is Generative AI (GenAI)?
- How GenAI apps differ from
traditional applications
- Key components: LLMs, prompts,
embeddings, vector DBs
- Why GenAI security matters
2.
Introduction to OWASP GenAI / LLM Top 10
- Purpose of OWASP GenAI Security
Project
- How GenAI risks map to traditional
security risks
- Overview of all 10 categories with
simple real-life examples
3. Deep Dive
into OWASP LLM Top 10 (Part 1)
- Prompt Injection
- Insecure Output Handling
- Training Data Poisoning
- Model Theft / Extraction
- Supply Chain Vulnerabilities
4. Deep Dive
into OWASP LLM Top 10 (Part 2)
- Data Leakage
- Unauthorized Code Execution
- Hallucinations & Overreliance
- Excessive Agency
- Insecure Plugin / Tool Integration
5. Hands-On
Demo
- Simple prompt injection examples
- Manipulating instructions
- How insecure outputs lead to risk
Threat
Modeling, Secure Development & Mitigation
6. Threat
Modeling for GenAI
- Understanding data flow in
LLM-based systems
- Finding attack points
- STRIDE basics applied to GenAI
- Misuse / abuse scenarios
7. GenAI
Architecture & Common Risks
- API calls & model gateways
- Risks in hosted vs self-hosted
models
- RAG (Retrieval-Augmented
Generation) risks explained simply
- Risks in plugins, tools & AI
agents
8. Secure
Development Practices
A. Secure
Prompt Engineering
- Designing safe prompts
- Guardrails & boundaries
- How to reduce prompt injection
- Output validation basics
B. Data
Security & Privacy
- Safe data ingestion
- Masking & minimization
- Handling sensitive data
C. Supply
Chain Security
- Risks in pretrained models
- Risks in libraries &
open-source packages
- Model integrity checks
9. Defensive
Controls & Testing
- Input/output validation
- AI safety tools (guardrail models,
AI firewalls)
- API security basics (rate limits,
authentication)
- Testing for:
- Hallucinations
- Unsafe outputs
- Prompt injection
10.
Governance, Compliance & Best Practices
- Responsible AI basics
- Key regulatory frameworks (simple
explanation)
- Documentation & audit readiness
11. Final
Lab + Q&A
- Small hands-on scenario
- Review of OWASP LLM Top 10
- Best practices checklist