diff --git a/Document/content/2.1.1_Architectural_Mapping_of_OWASP_Threats.md b/Document/content/2.1.1_Architectural_Mapping_of_OWASP_Threats.md index b89184c..c09a43f 100644 --- a/Document/content/2.1.1_Architectural_Mapping_of_OWASP_Threats.md +++ b/Document/content/2.1.1_Architectural_Mapping_of_OWASP_Threats.md @@ -195,23 +195,23 @@ Given the above results, the following is a table with the 20 initial threats we | Threat ID (Threat Model Reference) | OWASP Threat Name | Short Name | Source | \[URL | Test Name | | ----- | ----- | ----- | ----- | ----- | ----- | -| T01-DPIJ | Prompt Injection | LLM01 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) | Testing for Prompt Injection (T-PJ) | -| T01-IDPIJ | Indirect Prompt Injection | LLM01 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) | Testing for Indirect Prompt Injection (T-IPJ) | +| T01-DPIJ | Prompt Injection | LLM01 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) | Testing for Prompt Injection (T-PJ) | +| T01-IDPIJ | Indirect Prompt Injection | LLM01 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) | Testing for Indirect Prompt Injection (T-IPJ) | | T01-AIE | Adversarial Input (Evasion) | Threat 2.1 | OWASP AI Exchange | [link](https://owaspai.org/docs/2_threats_through_use/#21-evasion) | Testing for Evasion Attacks (T-EA) | -| T01-RMP | Runtime Model Poisoning | LLM04 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/) | Testing for Runtime Model Poisoning (T-RMP) | -| T01-DMP | Model Poisoning | LLM04 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/) | Testing for Poisoned Training Sets (T-PTS) | -| T01-DPFT | Data Poisoning during Fine Tuning | LLM04 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/) | Testing for Fine Tuning Poisoning (T-FTP) | -| T01-SCMP | Supply Chain Model Poisoning | LLM03 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm032025-supply-chain/) | Testing for Supply Chain Tampering (T-SPT) | -| T01-SID | Sensitive Information Disclosure | LLM02 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/) | Testing for Sensitive Data Leak (T-SDL) | +| T01-RMP | Runtime Model Poisoning | LLM04 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/) | Testing for Runtime Model Poisoning (T-RMP) | +| T01-DMP | Model Poisoning | LLM04 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/) | Testing for Poisoned Training Sets (T-PTS) | +| T01-DPFT | Data Poisoning during Fine Tuning | LLM04 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/) | Testing for Fine Tuning Poisoning (T-FTP) | +| T01-SCMP | Supply Chain Model Poisoning | LLM03 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm032025-supply-chain/) | Testing for Supply Chain Tampering (T-SPT) | +| T01-SID | Sensitive Information Disclosure | LLM02 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/) | Testing for Sensitive Data Leak (T-SDL) | | T01-MIMI | Model Inversion & Membership Inference | Threat 2.3.2 | OWASP AI Exchange | [link](https://owaspai.org/docs/2_threats_through_use/#24-training-set-membership-inference) | Testing for Membership Inference (T-MI) | | T01-TDL | Training Data Leakage | Threat 3.2 | OWASP AI Exchange | [link](https://owaspai.org/docs/2_threats_through_use/#25-training-data-leakage) | Testing for Training Data Exposure (T-TDE) | | T01-MTU | Model Theft Through Use | Threat 2.4 | OWASP AI Exchange | [link](https://owaspai.org/docs/2_threats_through_use/#23-model-reversal) | Testing for Model Extraction (T-ME) | | T01-MTR | Direct Model Theft at Runtime | Threat 4.3 | OWASP AI Exchange | [link](https://owaspai.org/docs/2_threats_through_use/#22-model-exfiltration) | Testing for Runtime Exfiltration (T-REF) | | T01-MTDD | Model Theft during Development | Threat 3.2.2 | OWASP AI Exchange | [link](https://owaspai.org/docs/2_threats_through_use/#22-model-exfiltration) | Testing for Dev-Time Model Theft (T-DMT) | -| T01-DoSM | Denial of Model Services / Unbounded Consumption | LLM10 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/) | Testing for Resource Exhaustion (T-RE) | -| T01-LSID | Leak Sensitive Input Data | LLM02 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/) | Testing for Input Leakage (T-IL) | -| T01-IOH | Improper Output Handling | LLM05 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/) | Testing for Unsafe Outputs (T-UO) | -| T01-EA | Excessive Agency | LLM06 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/) | Testing for Agentic Behavior Limits (T-ABL) | -| T01-SPL | System Prompt Leakage | LLM07 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/) | Testing for System Prompt Leakage (T-SPL) | +| T01-DoSM | Denial of Model Services / Unbounded Consumption | LLM10 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/) | Testing for Resource Exhaustion (T-RE) | +| T01-LSID | Leak Sensitive Input Data | LLM02 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/) | Testing for Input Leakage (T-IL) | +| T01-IOH | Improper Output Handling | LLM05 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/) | Testing for Unsafe Outputs (T-UO) | +| T01-EA | Excessive Agency | LLM06 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/) | Testing for Agentic Behavior Limits (T-ABL) | +| T01-SPL | System Prompt Leakage | LLM07 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/) | Testing for System Prompt Leakage (T-SPL) | | T01-VEW | Vector & Embedding Weaknesses | LLM08 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/) | Testing for Embedding Manipulation (T-EMA) | -| T01-MIS | Misinformation | LLM09 | OWASP Top 10 2025 | [link](https://genai.owasp.org/llmrisk/llm092025-misinformation/) | Testing for Harmful Content Bias (T-HCB) | +| T01-MIS | Misinformation | LLM09 | OWASP Top 10 LLM 2025 | [link](https://genai.owasp.org/llmrisk/llm092025-misinformation/) | Testing for Harmful Content Bias (T-HCB) |