Application & API Security
OWASP ML Top 10
OWASP Machine Learning Security Top 10
A risk list for classical machine learning systems: input manipulation, data poisoning, model inversion, membership inference, model theft, and transfer learning attacks.
Still the better reference for a trained-in-house model that is not a language model. Treat it as a checklist rather than a standard: the document has been in draft for years.
At a glance
- Category
- Application & API Security
- Jurisdiction
- Global
- Governance
- OWASP
- Status
- Draft; superseded in practice by the GenAI project for LLM work
- First released
- 2023
Links
Related frameworks
Other entries under Application & API Security.
- OWASP LLM Top 10: OWASP Top 10 for LLM Applications
- OWASP API Top 10: OWASP API Security Top 10
- OWASP ASVS: Application Security Verification Standard
- OWASP SAMM: Software Assurance Maturity Model
See OWASP ML Top 10 in context
Open the interactive Data Landscape for Regulation to compare OWASP ML Top 10 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.