Skip to content

附錄 A:OWASP Agentic AI Security Mapping Matrix

Appendix A - OWASP Agentic AI Security Mapping Matrix

ASI Top 10、LLM Top 10、Agentic AI Threats & Mitigations 與 AIVSS Core Risks 的交叉對照。

ASI ID/項目 OWASP LLM Top 10(2025) Agentic AI Threats & Mitigations AIVSS Core Risk Alignment
ASI 01 – Agent 目標劫持 LLM01:2025 Prompt Injection · LLM06:2025 Excessive Agency T6 Goal Manipulation · T7 Misaligned & Deceptive Behaviors Agent Goal & Instruction Manipulation
ASI 02 – 工具誤用與利用 LLM06:2025 Excessive Agency T2 Tool Misuse · T4 Resource Overload · T16 Insecure Inter-Agent Protocol Abuse Agentic AI Tool Misuse
ASI 03 – 身分與權限濫用 LLM01:2025 Prompt Injection · LLM06:2025 Excessive Agency · LLM02:2025 Sensitive Info Disclosure T3 Privilege Compromise Agent Access Control Violation
ASI 04 – Agentic 供應鏈漏洞 LLM03:2025 Supply Chain Vulnerabilities T17 Supply Chain Compromise · T2 Tool Misuse · T11 Unexpected RCE · T12 Agent Comm Poisoning · T13 Rogue Agent · T16 Insecure Inter-Agent Protocol Abuse Agent Supply Chain & Dependency Attacks
ASI 05 – 非預期程式碼執行(RCE) LLM01:2025 Prompt Injection · LLM05 Improper Output Handling T11 Unexpected RCE & Code Attacks Insecure Agent Critical Systems Interaction
ASI 06 – 記憶與上下文污染 LLM01:2025 Prompt Injection · LLM04:2025 Data & Model Poisoning · LLM08:2025 Vector & Embedding Weaknesses T1 Memory Poisoning · T4 Memory Overload · T6 Broken Goals · T12 Shared Memory Poisoning Memory Use & Contextual Awareness
ASI 07 – 不安全的 Agent 間通訊 LLM02:2025 Sensitive Information Disclosure · LLM06:2025 Excessive Agency T12 Agent Communication Poisoning · T16 Insecure Inter-Agent Protocol Abuse Agent Memory & Context Manipulation
ASI 08 – 級聯失效 LLM01:2025 Prompt Injection · LLM04 Data & Model Poisoning · LLM06:2025 Excessive Agency T5 Cascading Hallucination Attacks · T8 Repudiation & Untraceability Agent Cascading Failures
ASI 09 – 人類與 Agent 信任利用 LLM01:2025 Prompt Injection · LLM05:2025 Improper Output Handling · LLM06:2025 Excessive Agency · LLM09 Misinformation T7 Misaligned & Deceptive Behaviors · T8 Repudiation & Untraceability · T10 Overwhelming Human in the Loop Agent Untraceability / Human Manipulation
ASI 10 – Rogue Agents LLM02:2025 Sensitive Information Disclosure, LLM09:2025 Misinformation T13 Rogue Agents in Multi-Agent Systems · T14 Human Attacks on Multi-Agent Systems · T15 Human Manipulation Behavioral Integrity(BI)· Operational Security(OS)· Compliance Violations(CV)

備註

  • LLM Top 10 alignment:涵蓋延伸至 Agentic 系統的根本 LLM 漏洞。
  • Agentic Threats & Mitigations(T1–T17):代表 ASI framework 所引用的細粒度攻擊路徑。
  • AIVSS Core Risks:對應用於優先排序與嚴重度排名的量化評分分類,例如 BI、OS、CV。
  • Crossover insight:ASI 項目經常混合多個 LLM 項目;例如 ASI01 結合 LLM01:2025(prompt)與 LLM06(autonomy),呈現 Agentic autonomy 如何放大 model-level risk。

原作:OWASP Top 10 For Agentic Applications 2026
專案:OWASP Gen AI Security Project - Agentic Security Initiative
授權:CC BY-SA 4.0
本翻譯為非官方繁體中文版本,並依 CC BY-SA 4.0 授權釋出。