Security
How LLM applications and agents become vulnerable, and why protection is built with architecture rather than a prompt: trust boundaries, direct and indirect injections, data leaks, excessive agent permissions, attacks on the budget.
Loading…
01The whole topic
Take the whole "Security" topic
Every question of the topic — one per fact, from easy to hard. An honest check of the whole topic rather than of a single section.
02
Topic sections
#QUIZQUESTIONSDIFFICULTYSTATUS
7.1OWASP Top 10 for LLMRisks from the OWASP list for LLMs, How prompt injection differs from SQL injection, The consequences of a successful injection
7.2Direct injections and jailbreaksTechniques of direct injection, Rate limits against injections, Input filtering
7.3Indirect injectionsA hidden instruction on a web page, Direct and indirect injection, An injection in a résumé
7.4Trust boundaries and least privilegeWhat a trust boundary is, A public API or your own model, A pessimistic trust boundary
7.5Data leaksWhere the model learns too much, Personal data in training, How to keep personal data out of training data
7.6Excessive agent permissionsThree kinds of excessive agency, A medical database and the model's permissions, Automatic portfolio rebalancing
7.7Attacks on the budgetDoS, DoW and model cloning, A cheap request, an expensive answer, Protection from DoS and DoW
7.8The supply chainThe supply chain of an LLM application, Incidents on Hugging Face, Data poisoning