Application & API Security

OWASP ML Top 10

OWASP Machine Learning Security Top 10

Community Global OWASP Since 2023

A risk list for classical machine learning systems: input manipulation, data poisoning, model inversion, membership inference, model theft, and transfer learning attacks.

Still the better reference for a trained-in-house model that is not a language model. Treat it as a checklist rather than a standard: the document has been in draft for years.

At a glance

Category
Application & API Security
Jurisdiction
Global
Governance
OWASP
Status
Draft; superseded in practice by the GenAI project for LLM work
First released
2023

Links

Related frameworks

Other entries under Application & API Security.

See OWASP ML Top 10 in context

Open the interactive Data Landscape for Regulation to compare OWASP ML Top 10 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.