Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEEDBACK]: Is the "OWASP Machine Learning Security Top Ten" machine generated? #213

Open
1 task done
xw48 opened this issue Oct 22, 2024 · 2 comments
Open
1 task done
Assignees
Labels
issues/general General issues issues/triage Issues that need further analysis

Comments

@xw48
Copy link

xw48 commented Oct 22, 2024

Type

Documentation Issue Report

What would you like to report?

I would like to report the following issue/feedback

I am not an ML person but feels that the OWASP Machine Learning Security Top Ten is generated by LLMs and there is a lot of errors in it. For example, the description of member inference attack, and the use of the terms such as "a malicious attacker" (Is there a benign attacker then?).

Code of Conduct

  • I agree to follow this project's Code of Conduct
@xw48 xw48 added issues/general General issues issues/triage Issues that need further analysis labels Oct 22, 2024
@mik0w
Copy link
Collaborator

mik0w commented Oct 22, 2024

Yup, it is.

The project is currently in Work In Progress status, initial version was released as generated by some kind of LLM, we are working on delivering "actionable" release which is human-generated, e.g. this vulnerability was fully rewritten by me some time ago:

https://github.com/OWASP/www-project-machine-learning-security-top-10/blob/develop/docs/ML06_2023-AI_Supply_Chain_Attacks.md

Thank your for raising this issue, we are aware of this fact and we plan to update top10 in the near future

@sagarbhure
Copy link
Collaborator

To my knowledge, the top 10 was originally created before the release of GPT and hasn't been influenced by LLM-generated content. However, it might have incorporated some LLM elements since then. By the way, we're also developing a GitHub bot to detect LLM-generated content in our pull requests. I have a similar tool for my personal projects, so I might just integrate it here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
issues/general General issues issues/triage Issues that need further analysis
Projects
None yet
Development

No branches or pull requests

4 participants