OWASP / www-project-top-10-for-large-language-model-applications

OWASP Foundation Web Respository
Other
453 stars 119 forks source link

Add CloudBorne and CloudJacking Attacks to LLM-05 Supply Chain - CVE-2023-4969 #264

Open GangGreenTemperTatum opened 5 months ago

GangGreenTemperTatum commented 5 months ago

Remember, an issue is not the place to ask questions. You can use our Slack channel for that, or you may want to start a discussion on the Discussion Board.

When reporting an issue, please be sure to include the following:

Steps to Reproduce


NA

What happens?


NA

What were you expecting to happen?


Within the current LLM entry, I think supply-chain needs to cover cloudborne and cloudjacking attacks, IE GPU and cloud providers in further detail which the entry currently does not cover and is applicable to all companies and AI developers who depend on cloud resources. I added an article of interest below which I feel would back up this entry' resources section.

Any logs, error output, etc?


NA

Any other comments?


LeftoverLocals: Listening to LLM responses through leaked GPU local memory

What versions of hardware and software are you using?


NA