附錄 A:OWASP Agentic AI Security Mapping Matrix
Appendix A - OWASP Agentic AI Security Mapping Matrix
ASI Top 10、LLM Top 10、Agentic AI Threats & Mitigations 與 AIVSS Core Risks 的交叉對照。
| ASI ID/項目 | OWASP LLM Top 10(2025) | Agentic AI Threats & Mitigations | AIVSS Core Risk Alignment |
|---|---|---|---|
| ASI 01 – Agent 目標劫持 | LLM01:2025 Prompt Injection · LLM06:2025 Excessive Agency | T6 Goal Manipulation · T7 Misaligned & Deceptive Behaviors | Agent Goal & Instruction Manipulation |
| ASI 02 – 工具誤用與利用 | LLM06:2025 Excessive Agency | T2 Tool Misuse · T4 Resource Overload · T16 Insecure Inter-Agent Protocol Abuse | Agentic AI Tool Misuse |
| ASI 03 – 身分與權限濫用 | LLM01:2025 Prompt Injection · LLM06:2025 Excessive Agency · LLM02:2025 Sensitive Info Disclosure | T3 Privilege Compromise | Agent Access Control Violation |
| ASI 04 – Agentic 供應鏈漏洞 | LLM03:2025 Supply Chain Vulnerabilities | T17 Supply Chain Compromise · T2 Tool Misuse · T11 Unexpected RCE · T12 Agent Comm Poisoning · T13 Rogue Agent · T16 Insecure Inter-Agent Protocol Abuse | Agent Supply Chain & Dependency Attacks |
| ASI 05 – 非預期程式碼執行(RCE) | LLM01:2025 Prompt Injection · LLM05 Improper Output Handling | T11 Unexpected RCE & Code Attacks | Insecure Agent Critical Systems Interaction |
| ASI 06 – 記憶與上下文污染 | LLM01:2025 Prompt Injection · LLM04:2025 Data & Model Poisoning · LLM08:2025 Vector & Embedding Weaknesses | T1 Memory Poisoning · T4 Memory Overload · T6 Broken Goals · T12 Shared Memory Poisoning | Memory Use & Contextual Awareness |
| ASI 07 – 不安全的 Agent 間通訊 | LLM02:2025 Sensitive Information Disclosure · LLM06:2025 Excessive Agency | T12 Agent Communication Poisoning · T16 Insecure Inter-Agent Protocol Abuse | Agent Memory & Context Manipulation |
| ASI 08 – 級聯失效 | LLM01:2025 Prompt Injection · LLM04 Data & Model Poisoning · LLM06:2025 Excessive Agency | T5 Cascading Hallucination Attacks · T8 Repudiation & Untraceability | Agent Cascading Failures |
| ASI 09 – 人類與 Agent 信任利用 | LLM01:2025 Prompt Injection · LLM05:2025 Improper Output Handling · LLM06:2025 Excessive Agency · LLM09 Misinformation | T7 Misaligned & Deceptive Behaviors · T8 Repudiation & Untraceability · T10 Overwhelming Human in the Loop | Agent Untraceability / Human Manipulation |
| ASI 10 – Rogue Agents | LLM02:2025 Sensitive Information Disclosure, LLM09:2025 Misinformation | T13 Rogue Agents in Multi-Agent Systems · T14 Human Attacks on Multi-Agent Systems · T15 Human Manipulation | Behavioral Integrity(BI)· Operational Security(OS)· Compliance Violations(CV) |
備註
- LLM Top 10 alignment:涵蓋延伸至 Agentic 系統的根本 LLM 漏洞。
- Agentic Threats & Mitigations(T1–T17):代表 ASI framework 所引用的細粒度攻擊路徑。
- AIVSS Core Risks:對應用於優先排序與嚴重度排名的量化評分分類,例如 BI、OS、CV。
- Crossover insight:ASI 項目經常混合多個 LLM 項目;例如 ASI01 結合 LLM01:2025(prompt)與 LLM06(autonomy),呈現 Agentic autonomy 如何放大 model-level risk。
原作:OWASP Top 10 For Agentic Applications 2026
專案:OWASP Gen AI Security Project - Agentic Security Initiative
授權:CC BY-SA 4.0
本翻譯為非官方繁體中文版本,並依 CC BY-SA 4.0 授權釋出。