BEGIN:VCALENDAR
VERSION:2.0
PRODID:IEEE vTools.Events//EN
CALSCALE:GREGORIAN
BEGIN:VTIMEZONE
TZID:America/Chicago
BEGIN:DAYLIGHT
DTSTART:20260308T030000
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:CDT
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20261101T010000
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:CST
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20260730T195652Z
UID:7DEA836A-4F55-46FB-9E75-FDDF89862E92
DTSTART;TZID=America/Chicago:20260729T120000
DTEND;TZID=America/Chicago:20260729T130000
DESCRIPTION:If you have ever used the OWASP Top 10 for Web Application Secu
 rity to guide a design review\, threat model\, or secure-coding standard\,
  you already understand the value of a community-vetted\, vendor-neutral r
 isk baseline. This session introduces its counterpart for the era of gener
 ative AI.\n\nLarge language models are no longer isolated research artifac
 ts — they are production components embedded in enterprise systems as co
 pilots\, retrieval-augmented search engines\, and autonomous agents that c
 all APIs\, write code\, and act on live data. Their arrival introduces a c
 lass of security failures that classical application security was not desi
 gned to catch: instruction injection through untrusted data\, sensitive in
 formation surfacing from training corpora\, supply-chain risks in opaque m
 odel weights\, excessive agency in tool-enabled agents\, and denial-of-wal
 let attacks on metered inference endpoints.\n\nThe OWASP GenAI Security Pr
 oject — built by more than 600 contributors across 18 countries — has 
 codified these failures into the 2025 Top 10 for LLM Applications. This 45
 -minute engineer-focused briefing walks the complete list: what each risk 
 is\, how it is exploited in real systems\, how to defend against it\, and 
 where it maps in a production LLM architecture. Concrete examples ground e
 ach risk\, a cross-category failure-chain case study shows how a single po
 isoned document can traverse six risk categories simultaneously\, and a se
 cure-by-design control blueprint translates the list into actionable desig
 n\, build\, deploy\, and run guidance.\n\nSpeaker(s): Mike Bishop\n\nVirtu
 al: https://events.vtools.ieee.org/m/565506
LOCATION:Virtual: https://events.vtools.ieee.org/m/565506
ORGANIZER:bishopm@acm.org
SEQUENCE:15
SUMMARY:Securing the LLM Stack: The OWASP Top 10 for Large Language Model A
 pplications
URL;VALUE=URI:https://events.vtools.ieee.org/m/565506
X-ALT-DESC:Description: &lt;br /&gt;&lt;p class=&quot;font-claude-response-body break-wor
 ds whitespace-normal&quot;&gt;If you have ever used the OWASP Top 10 for Web Appli
 cation Security to guide a design review\, threat model\, or secure-coding
  standard\, you already understand the value of a community-vetted\, vendo
 r-neutral risk baseline. This session introduces its counterpart for the e
 ra of generative AI.&lt;/p&gt;\n&lt;p class=&quot;font-claude-response-body break-words 
 whitespace-normal&quot;&gt;Large language models are no longer isolated research a
 rtifacts &amp;mdash\; they are production components embedded in enterprise sy
 stems as copilots\, retrieval-augmented search engines\, and autonomous ag
 ents that call APIs\, write code\, and act on live data. Their arrival int
 roduces a class of security failures that classical application security w
 as not designed to catch: instruction injection through untrusted data\, s
 ensitive information surfacing from training corpora\, supply-chain risks 
 in opaque model weights\, excessive agency in tool-enabled agents\, and de
 nial-of-wallet attacks on metered inference endpoints.&lt;/p&gt;\n&lt;p class=&quot;font
 -claude-response-body break-words whitespace-normal&quot;&gt;The OWASP GenAI Secur
 ity Project &amp;mdash\; built by more than 600 contributors across 18 countri
 es &amp;mdash\; has codified these failures into the 2025 Top 10 for LLM Appli
 cations. This 45-minute engineer-focused briefing walks the complete list:
  what each risk is\, how it is exploited in real systems\, how to defend a
 gainst it\, and where it maps in a production LLM architecture. Concrete e
 xamples ground each risk\, a cross-category failure-chain case study shows
  how a single poisoned document can traverse six risk categories simultane
 ously\, and a secure-by-design control blueprint translates the list into 
 actionable design\, build\, deploy\, and run guidance.&lt;/p&gt;
END:VEVENT
END:VCALENDAR

