Case 6F4411 · AI security · L3 Applied
OWASP LLM Top 10 Threat Modeling
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Use the list (2025 edition) as a threat-modeling checklist of app-level LLM risks, not a compliance standard to certify against.
- Plain chatbot: prompt injection, sensitive info disclosure, system prompt leakage, misinformation and cost abuse dominate.
- RAG adds poisoned or ACL-blind retrieval (vector/embedding weaknesses); agents add excessive agency, turning injection into action.
- Prompt injection cannot be fully patched: instructions and data share one channel, so assume it succeeds and contain the blast radius.
- Contain: least-privilege tools, human approval for consequential actions, and treat model output as untrusted input downstream.
If the interviewer pushes back
- Which two items would you prioritize for a customer-facing RAG chatbot with no tools, and why?
- Where does the list fall short for multi-step agents, and what would you add (e.g. MITRE ATLAS techniques)?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.