LLM Security

LLM Security

My notes on attacking and defending LLM applications, following the OWASP Top 10 for LLM Applications 2025. It starts with how an LLM actually works, then the threat model, then each vulnerability class with a local lab you can break and patch.

Everything here is for learning, CTFs, authorized red teaming, and defending your own systems. Payloads are only meant for the local labs or systems you have written permission to test.

Chapter 1: Foundations

Part 00 · Intro to LLM Security

Part 01 · LLM Foundations

More parts (the OWASP Top 10 one by one, plus newer attack techniques) are on the way.