OWASP Top 10 for LLM Applications 2025
Data and Model Integrity

OWASP Top 10 for LLM Applications 2025 OWASPLLM-5: Data and Model Poisoning (LLM04)

Address OWASP LLM04:2025 Data and Model Poisoning. Data Poisoning occurs when training + fine-tuning + retrieval data is intentionally + unintentionally contaminated to bias + degrade + or backdoor the resulting model. Model Poisoning occurs when the model itself is tampered with via direct modification + supply chain compromise + or insider action. Mitigations include (a) vet training + fine-tuning data sources for integrity + provenance + content + (b) implement anomaly detection + sanitisation for training data + (c) implement model integrity verification including signing + reproducibility + (d) protect model artefacts in storage + deployment via access control + integrity verification + (e) implement adversarial testing including poisoning + backdoor detection + (f) maintain monitoring + detection for model behaviour drift + (g) implement model versioning + rollback capability.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.