The Cloud Security Alliance (CSA) has released a new document that defines key terms related to Large Language Model (LLM) risks and threats.
CSA says that ‘establishing a common language reduces confusion, helps connect related concepts, and facilitates more precise dialogue across diverse groups’. The common language set out in the document ‘will ultimately assist the advancement of artificial intelligence (AI) risk evaluation, AI control measures, and responsible AI governance’.
The Large Language Model (LLM) Threats Taxonomy:
- Defines the assets that are essential for implementing and managing LLM/AI systems
- Defines the phases of the LLM lifecycle
- Defines potential LLM risks
- Defines the impact categories of LLM risks.
The document includes an initial list of LLM Service Threat Categories which ‘encompasses a range of potential risks and vulnerabilities that need careful consideration and mitigation strategies’. These are:
- Model manipulation
- Data poisoning
- Sensitive data disclosure
- Model theft
- Model Failure/malfunctioning
- Insecure supply chain
- Insecure apps/plugins
- Denial of Service (DoS)
- Loss of governance/compliance.






