Skip to content

Commit

Permalink
45 feat contributions investigate use of all contributors specificati…
Browse files Browse the repository at this point in the history
…on (#60)

* docs: add @sagarbhure as a contributor

* docs: add @shsingh as a contributor

* docs: update @shsingh as a contributor

* docs: update @sagarbhure as a contributor

* docs: update @sagarbhure as a contributor

* docs: update @shsingh as a contributor

* docs: add @robvanderveer as a contributor

* docs: add @msnishanth9001 as a contributor

* docs: add @kingthorin as a contributor

* docs: add @hblankenship as a contributor

* docs: add @RiccardoBiosas as a contributor

* docs: add @aryanxk02 as a contributor

* docs: add @mik0w as a contributor

* fix: modify leaders.md

* fix: delete tab_contributors.md

* fix: modify all-contributorsrc

---------

Signed-off-by: Shain Singh <shain.singh@owasp.org>
  • Loading branch information
shsingh authored Aug 13, 2023
1 parent 06f7eed commit 4e0ab01
Show file tree
Hide file tree
Showing 6 changed files with 71 additions and 60 deletions.
2 changes: 1 addition & 1 deletion .all-contributorsrc
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"repoHost": "https://github.com",
"files": [
"CONTRIBUTORS.md",
"tab_contributors.md"
"README.md"
],
"imageSize": 100,
"commit": true,
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTORS.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
## Contributors ✨
# Contributors ✨

Thanks goes to these wonderful people
([emoji key](https://allcontributors.org/docs/en/emoji-key)):
Expand Down
73 changes: 56 additions & 17 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,32 +3,71 @@
[![OWASP Incubator](https://img.shields.io/badge/owasp-incubator-blue.svg)](https://owasp.org/projects/)
[![License: CC BY-SA 4.0](https://img.shields.io/badge/License-CC%20BY--SA%204.0-lightgrey.svg)](https://creativecommons.org/licenses/by-sa/4.0/)

Welcome to the repository for the OWASP Machine Learning Security Top 10 project!
Welcome to the repository for the OWASP Machine Learning Security Top 10
project!

## Overview

The primary aim of of the OWASP Machine Learning Security Top 10 project
is to deliver a standard awareness document for developers and application
security practitioners.

More infomration on the project scope and target audience is available in
our [project working group charter](https://github.com/OWASP/www-project-machine-learning-security-top-10/wiki/Charter).
The primary aim of the OWASP Machine Learning Security Top 10 project is to
deliver an overview of the top 10 security issues of machine learning systems.
More information on the project scope and target audience is available in our
[project working group charter](https://github.com/OWASP/www-project-machine-learning-security-top-10/wiki/Charter).

## Contribution

The initial version of the Machine Learning Security Top 10 list was contributed by [Sagar Bhure](mailto:sagar.bhure@owasp.org)
and [Shain Singh](mailto:shain.singh@owasp.org). The project encourages community contribution and aims
to produce a high quality deliverable reviewed by industry peers.
The initial version of the Machine Learning Security Top 10 list was contributed
by [Sagar Bhure](mailto:sagar.bhure@owasp.org) and
[Shain Singh](mailto:shain.singh@owasp.org). The project encourages community
contribution and aims to produce a high quality deliverable reviewed by industry
peers.

All contributors will need to adhere to the project's
[code of conduct](./CODE_OF_CONDUCT.md). Please
[use the following form](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/new?assignees=shsingh&labels=issues%2Fgeneral%2Cissues%2Ftriage&projects=&template=feedback-report.yaml&title=%5BFEEDBACK%5D%3A+)
for any feedback, suggestions, issues or questions.

## Getting Started

The project has a
[wiki](https://github.com/OWASP/www-project-machine-learning-security-top-10/wiki)
which provides information to get help you started on how to contribute.

## Contributors ✨

This project follows the
[all-contributors](https://github.com/all-contributors/all-contributors)
specification. Contributions of any kind welcome!

Thanks goes to these wonderful people
([emoji key](https://allcontributors.org/docs/en/emoji-key)):

All contributors will need to adhere to the project's [code of conduct](./CODE_OF_CONDUCT.md).
Please [use the following form](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/new?assignees=shsingh&labels=issues%2Fgeneral%2Cissues%2Ftriage&projects=&template=feedback-report.yaml&title=%5BFEEDBACK%5D%3A+)
for any suggestions, feedback, issues or questions.
<!-- ALL-CONTRIBUTORS-LIST:START - Do not remove or modify this section -->
<!-- prettier-ignore-start -->
<!-- markdownlint-disable -->
<table>
<tbody>
<tr>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/sagarbhure"><img src="https://avatars.githubusercontent.com/u/25385987?v=4?s=100" width="100px;" alt="Sagar Bhure"/><br /><sub><b>Sagar Bhure</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=sagarbhure" title="Code">💻</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=sagarbhure" title="Documentation">📖</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/pulls?q=is%3Apr+reviewed-by%3Asagarbhure" title="Reviewed Pull Requests">👀</a> <a href="#question-sagarbhure" title="Answering Questions">💬</a> <a href="#content-sagarbhure" title="Content">🖋</a> <a href="#research-sagarbhure" title="Research">🔬</a> <a href="#promotion-sagarbhure" title="Promotion">📣</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://shain.io/"><img src="https://avatars.githubusercontent.com/u/412800?v=4?s=100" width="100px;" alt="Shain Singh"/><br /><sub><b>Shain Singh</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=shsingh" title="Code">💻</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=shsingh" title="Documentation">📖</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/pulls?q=is%3Apr+reviewed-by%3Ashsingh" title="Reviewed Pull Requests">👀</a> <a href="#question-shsingh" title="Answering Questions">💬</a> <a href="#content-shsingh" title="Content">🖋</a> <a href="#promotion-shsingh" title="Promotion">📣</a> <a href="#projectManagement-shsingh" title="Project Management">📆</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/robvanderveer"><img src="https://avatars.githubusercontent.com/u/796794?v=4?s=100" width="100px;" alt="Rob van der Veer"/><br /><sub><b>Rob van der Veer</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/pulls?q=is%3Apr+reviewed-by%3Arobvanderveer" title="Reviewed Pull Requests">👀</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=robvanderveer" title="Code">💻</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=robvanderveer" title="Documentation">📖</a> <a href="#question-robvanderveer" title="Answering Questions">💬</a> <a href="#promotion-robvanderveer" title="Promotion">📣</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/msnishanth9001"><img src="https://avatars.githubusercontent.com/u/49409979?v=4?s=100" width="100px;" alt="M S Nishanth"/><br /><sub><b>M S Nishanth</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=msnishanth9001" title="Code">💻</a> <a href="#question-msnishanth9001" title="Answering Questions">💬</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/kingthorin"><img src="https://avatars.githubusercontent.com/u/7570458?v=4?s=100" width="100px;" alt="Rick M"/><br /><sub><b>Rick M</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=kingthorin" title="Code">💻</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://owasp.org/"><img src="https://avatars.githubusercontent.com/u/36673698?v=4?s=100" width="100px;" alt="Harold Blankenship"/><br /><sub><b>Harold Blankenship</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=hblankenship" title="Code">💻</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/RiccardoBiosas"><img src="https://avatars.githubusercontent.com/u/65150720?v=4?s=100" width="100px;" alt="RiccardoBiosas"/><br /><sub><b>RiccardoBiosas</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=RiccardoBiosas" title="Code">💻</a></td>
</tr>
<tr>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/aryanxk02"><img src="https://avatars.githubusercontent.com/u/59761275?v=4?s=100" width="100px;" alt="Aryan Kenchappagol"/><br /><sub><b>Aryan Kenchappagol</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=aryanxk02" title="Documentation">📖</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/mik0w"><img src="https://avatars.githubusercontent.com/u/64902909?v=4?s=100" width="100px;" alt="Mikołaj Kowalczyk"/><br /><sub><b>Mikołaj Kowalczyk</b></sub></a><br /><a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=mik0w" title="Code">💻</a> <a href="https://github.com/OWASP/www-project-machine-learning-security-top-10/commits?author=mik0w" title="Documentation">📖</a> <a href="#question-mik0w" title="Answering Questions">💬</a> <a href="#promotion-mik0w" title="Promotion">📣</a></td>
</tr>
</tbody>
</table>

## Get Started
<!-- markdownlint-restore -->
<!-- prettier-ignore-end -->

The project has a [wiki](https://github.com/OWASP/www-project-machine-learning-security-top-10/wiki)
which provides information to get you started on how to contribute.
<!-- ALL-CONTRIBUTORS-LIST:END -->

## License

This project is licensed under the terms of the [Creative Commons Attribution-ShareAlike 4.0 International License](./LICENSE)
This project is licensed under the terms of the
[Creative Commons Attribution-ShareAlike 4.0 International License](./LICENSE)
5 changes: 4 additions & 1 deletion index.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,10 @@ pitch:

- Provide feedback and report potential bugs
- Suggest enhancements to the project
- Fix a [Bug](https://github.com/owasp/www-project-machine-learning-security-top-10/issues?q=is%3Aopen+is%3Aissue+label%3Abug) or implement an [Enhancement](https://github.com/owasp/www-project-machine-learning-security-top-10/issues?q=is%3Aopen+is%3Aissue+label%3Aenhancement)
- Fix a
[Bug](https://github.com/owasp/www-project-machine-learning-security-top-10/issues?q=is%3Aopen+is%3Aissue+label%3Abug)
or implement an
[Enhancement](https://github.com/owasp/www-project-machine-learning-security-top-10/issues?q=is%3Aopen+is%3Aissue+label%3Aenhancement)

## Top 10 Machine Learning Security Risks

Expand Down
38 changes: 0 additions & 38 deletions tab_contributors.md

This file was deleted.

11 changes: 9 additions & 2 deletions tab_related.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,33 +9,40 @@ tags: related-tag
# Related

**Top 10 lists related to ML and AI:**

Top10 lists similar to famous OWASP Top10 for Web Applications list, but for AI:

- [MLSecOps Top10](https://ethical.institute/security.html)
- [OWASP Top10 for Large Language Models](https://owasp.org/www-project-top-10-for-large-language-model-applications/)

**Vulnerability databases:**
Catalogued vulnerabilities and risks that were present in real-world AI and ML systems:

Catalogued vulnerabilities and risks that were present in real-world AI and ML
systems:

- [AI Vulnerability Database (AVID)](https://avidml.org/)
- [MITRE ATLAS](https://atlas.mitre.org/)
- [AI Risk Database](https://airisk.io/)

**AI/ML security guidelines:**

Various guidelines on ML and AI Security and Safety

- [OWASP AI Security and Privacy Guide](https://owasp.org/www-project-ai-security-and-privacy-guide/)
- [ETSI "Securing Artificial Intelligence](https://www.etsi.org/technologies/securing-artificial-intelligence)
- [Biden&Harris Administraton - Ensuring Safe, Secure and Trustworthy AI](https://www.whitehouse.gov/wp-content/uploads/2023/07/Ensuring-Safe-Secure-and-Trustworthy-AI.pdf)

**Playbooks**

Interactive playbooks useful in threat modelling and securing AI.

- [NIST AI Risk Management Framework Playbook](https://pages.nist.gov/AIRMF/)
- [Department of Energy AI Risk Management Playbook](https://www.energy.gov/ai/doe-ai-risk-management-playbook-airmp)

**Other**
All the other resources related to ML Security - threat modelling resources, risk assessments framework, "Awesome Lists" etc.

All the other resources related to ML Security - threat modelling resources,
risk assessments framework, "Awesome Lists" etc.

- [Google on Red Teaming AI](https://services.google.com/fh/files/blogs/google_ai_red_team_digital_final.pdf)
- [Berryville ML Institute Resources for Threat Modelling ML]([https://berryvilleiml.com/interactive/)
Expand Down

0 comments on commit 4e0ab01

Please sign in to comment.