ILT-Interlaboratory Test | Proficiency Testing Provider | Programs
ILT-U-4115

Request Quote

ILT-U-4115

Generative AI (LLM) Application Security. In accordance with OWASP GenAI LLM Top 10 2026 and OWASP AIVSS v0.8 / ISO/IEC 17043

DETERMINATION

METHOD

LLM01 – Prompt Injection

(F-01, F-02, F-12)

Apply crafted prompts to bypass system instructions; inject hidden instructions via RAG-retrieved documents; test Unicode homoglyph injection. Detection of direct and indirect prompt injection vulnerabilities.
LLM02 – Sensitive Information Disclosure

(F-03)

Elicit memorized PII through repeated prompting; test information leakage in RAG responses. Detection of sensitive data exposure through LLM memorization.
LLM03 – Excessive Agency

(F-04)

Craft tool-calling chains that trigger unauthorized actions (file deletion, database queries); test permission model. Detection of excessive permissions and unauthorized tool execution.
LLM04 – Supply Chain

(F-13, F-16)

Review AI-BOM/SBOM for missing provenance; inspect requirements.txt for typosquatted dependencies. Detection of supply chain and dependency risks.
LLM05 – Data and Model Poisoning

(F-05, F-14)

Inject poisoned documents into RAG corpus; inspect chat-template file for unauthorized modifications. Detection of retrieval poisoning and template tampering.
LLM06 – Unbounded Consumption

(F-06)

Craft prompts that cause token-amplification or reasoning loops; test resource limits. Detection of denial-of-service and resource exhaustion vulnerabilities.
LLM07 – Misinformation

(F-07)

Request domain-specific facts; verify model citations against ground truth. Detection of confident hallucination and fabricated content.
LLM08 – Hidden Context Exposure

(F-08)

Apply prompt engineering to extract system prompt and hidden instructions. Detection of system prompt leakage and hidden context exposure.
LLM09 – Vector and Embedding

Weaknesses (F-09, F-15)

Test cross-tenant data leakage via shared vector index; inspect vector-store metadata for PII. Detection of vector-store isolation failures and embedding inversion.
LLM10 – Improper Output Handling

(F-10, F-11)

Generate malicious markdown/HTML to test XSS; craft prompts that produce ANSI escape sequences. Detection of output sanitization failures (XSS, injection).