|
1 | 1 | Export of Github issues for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10). |
2 | 2 |
|
| 3 | +# [\#189 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189) `open`: [FEEDBACK]: Include a page with a brief descriptions of each of the vulnerabilities |
| 4 | +**Labels**: `issues/general`, `issues/triage` |
| 5 | + |
| 6 | + |
| 7 | +#### <img src="https://avatars.githubusercontent.com/u/64902909?u=756899683e78c4e336cc1e8a6b7584bc6b508200&v=4" width="50">[mik0w](https://github.com/mik0w) opened issue at [2023-11-23 12:08](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189): |
| 8 | + |
| 9 | +### Type |
| 10 | + |
| 11 | +Suggestions for Improvement |
| 12 | + |
| 13 | +### What would you like to report? |
| 14 | + |
| 15 | +For example in Top10 for LLM there's this page with a summary of each of the vulnerabilities, which I think would be pretty useful to have in Top10 for ML as well. |
| 16 | + |
| 17 | +Sometimes when you e.g. work on some slides for a presentation, you just want to get a short summary of each of the vulnerabilities. In my opinion including such a page in Top10 for ML would be an improvement: |
| 18 | + |
| 19 | + |
| 20 | + |
| 21 | +### Code of Conduct |
| 22 | + |
| 23 | +- [X] I agree to follow this project's Code of Conduct |
| 24 | + |
| 25 | + |
| 26 | + |
| 27 | + |
| 28 | +------------------------------------------------------------------------------- |
| 29 | + |
| 30 | +# [\#188 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188) `open`: [FEEDBACK]: Include MLOps vulnerabilties somewhere in the Supply Chain Security category |
| 31 | +**Labels**: `issues/general`, `issues/triage` |
| 32 | + |
| 33 | + |
| 34 | +#### <img src="https://avatars.githubusercontent.com/u/64902909?u=756899683e78c4e336cc1e8a6b7584bc6b508200&v=4" width="50">[mik0w](https://github.com/mik0w) opened issue at [2023-11-17 10:26](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188): |
| 35 | + |
| 36 | +### Type |
| 37 | + |
| 38 | +Suggestions for Improvement |
| 39 | + |
| 40 | +### What would you like to report? |
| 41 | + |
| 42 | +**Context** |
| 43 | +One of the parts of the supply chain in modern ML systems is MLOps software - like i.e. MLFlow, Prefect etc. Those systems are vulnerable to classic web based attacks and they seem to be "misconfured by default". I've described it here: https://hackstery.com/2023/10/13/no-one-is-prefect-is-your-mlops-infrastructure-leaking-secrets/ or here: https://github.com/logspace-ai/langflow/issues/1145 |
| 44 | + |
| 45 | +**Suggestion for improvement** |
| 46 | +I'd suggest including MLOps-related vulnerabilities in the ML06 (or maybe in some other categories as well? I am open for suggestions). |
| 47 | + |
| 48 | +### Code of Conduct |
| 49 | + |
| 50 | +- [X] I agree to follow this project's Code of Conduct |
| 51 | + |
| 52 | + |
| 53 | + |
| 54 | + |
| 55 | +------------------------------------------------------------------------------- |
| 56 | + |
| 57 | +# [\#187 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187) `open`: [FEEDBACK]: Sync attack names between LLMT10 and MLT10 where appropriate |
| 58 | +**Labels**: `issues/general`, `issues/triage` |
| 59 | + |
| 60 | + |
| 61 | +#### <img src="https://avatars.githubusercontent.com/u/795878?u=d704fd433504e531d707c517cdb6ff75bdf20372&v=4" width="50">[kapsolas](https://github.com/kapsolas) opened issue at [2023-11-16 22:16](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187): |
| 62 | + |
| 63 | +### Type |
| 64 | + |
| 65 | +Suggestions for Improvement |
| 66 | + |
| 67 | +### What would you like to report? |
| 68 | + |
| 69 | +I would like to make the suggestion that we consolidate the terms used in the LLM and ML top 10 documents. |
| 70 | + |
| 71 | +Many of the top 10 items in each are closely related or even the same. |
| 72 | +Where possible, the same term should be used (i.e. Model Theft vs Model Stealing, Data Poisoning Attack vs Training data Poisoning). |
| 73 | + |
| 74 | +Thanks! |
| 75 | + |
| 76 | +### Code of Conduct |
| 77 | + |
| 78 | +- [X] I agree to follow this project's Code of Conduct |
| 79 | + |
| 80 | + |
| 81 | + |
| 82 | + |
| 83 | +------------------------------------------------------------------------------- |
| 84 | + |
3 | 85 | # [\#182 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/182) `open`: fix: merge review from @harrietf |
4 | 86 | **Labels**: `issues/triage`, `review needed` |
5 | 87 |
|
|
0 commit comments