OWASP Top 10 for LLM Applications

Language-model-based applications introduce new vulnerabilities: prompt manipulation, data leakage, unauthorized actions, or poorly secured document sources. This training covers the main security risks of AI applications and the measures needed to reduce them.

Programme

Day 1 — Understanding the vulnerabilities

Morning (9:00 – 12:30)

Understanding LLM application vulnerabilities

  • Architecture of an LLM-powered application
  • How prompts work
  • Prompt Injection
  • Sensitive information leakage
  • Risks related to models and third-party components
  • Compromised data or document sources
  • Poor handling of AI-generated responses

Afternoon (14:00 – 17:30)

Demonstrations and practical cases

  • Highlighting vulnerabilities through realistic scenarios
  • Analysis of Prompt Injection attacks
  • Identifying data leakage points
  • Experience sharing and discussion of real cases

Day 2 — Securing AI applications

Morning (9:00 – 12:30)

Securing AI applications and agents

  • Securing AI agents
  • Least privilege principle
  • Protecting vector databases and RAG systems
  • Input and output controls
  • Access management
  • Request and cost limiting

Afternoon (14:00 – 17:30)

Threat modeling and remediation

  • Threat modeling of an AI application
  • Building a remediation plan

Skills acquired

  • By the end of the training, participants will be able to:
  • identify the main vulnerabilities of an LLM application
  • detect Prompt Injection risks
  • secure a RAG architecture
  • limit the privileges of an AI agent
  • define appropriate protection measures

General information

€4,500 excl. VAT

Objective

Identify and remediate the main vulnerabilities in LLM-based applications.

Target audience

Developers, architects, DevSecOps, AppSec, pentesters and CISOs.

Level

Intermediate / Advanced

Duration

2 days

Prerequisites

General knowledge of web development, APIs or application security.

This training is delivered in partnership with Académie Cyber, a certified organisation. It is Qualiopi-certified and CPF-eligible.

Qualiopi certification
Mon Compte Formation
Contact us

Other training courses offered by De Shagan Network

  • Cyber incident management and first response

    A cyberattack can have serious consequences. This course enables IT teams and SOC analysts to react quickly.

    Audience

    IT teams, SOC, system administrators

    Level

    Intermediate / Advanced

    Duration

    2 days

    Discover this course
  • Application security and DevSecOps

    A simple bug can be an entry point for a cyberattack. Ensure your developers apply OWASP Top 10 best practices.

    Audience

    Developers, DevOps, IT teams

    Level

    Intermediate / Advanced

    Duration

    2 days

    Discover this course
  • Cloud environment security (AWS, Azure, Google Cloud)

    Cloud solutions (AWS, Azure, Google Cloud...) open the door to many cyber risks. Protect your business from data leaks or API attacks.

    Audience

    IT teams, cloud architects, DevOps

    Level

    Intermediate

    Duration

    1 day

    Discover this course
  • Generative AI: cyber risks and best practices

    Learn how to use ChatGPT, Copilot and generative AI without putting your company data at risk. Identify risks, apply best practices and secure professional AI usage.

    Audience

    Employees, IT teams, managers, CISOs

    Level

    Beginner / Intermediate

    Duration

    2 days

    Discover this course