LLMVault 是一个故意存在漏洞的 CTF 风格训练平台,覆盖 OWASP 大型语言模型应用 Top 10(2025),提供 25 个跨三个难度级别的动手实验。

Stars

253

7 天增长

暂无数据

Fork 数

62

开放 Issue

1

开源协议

MIT

最近更新

2026-07-18

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它是首个专门针对 OWASP LLM Top 10 的结构化、完全离线的训练靶场,每个攻击都配有对应的防御教程,并通过渐进解锁机制引导学习。

适合谁使用

  • 需要实战 LLM 漏洞训练的安全专业人员
  • 希望了解常见 LLM 安全缺陷的 AI/ML 开发者
  • 扩展至 AI 系统的红队和渗透测试人员
  • 网络安全或 AI 安全课程的学生和教育工作者

典型使用场景

  • 动手练习 OWASP LLM Top 10 攻击技术
  • 通过内置防御教程进行防御训练
  • 课堂教学或工作坊用 LLM 安全教学
  • 自学以获取 AI 安全认证或提升技能

项目优势

  • 覆盖全部 10 个 OWASP LLM 类别,每类有多个实验
  • 渐进式层级系统(核心 → 高级 → 专家)顺序解锁
  • 每个实验解决后显示防御讲解,强化学习效果
  • 完全离线且支持 Docker,无需 API 密钥或外部服务

使用前须知

  • 专家级内容已加密,需从作者处手动获取密钥,限制完全自主使用
  • 脆弱助手为脚本化/确定性行为,非真实 LLM 交互
  • 除本地记分板外,无内置多用户或课堂管理功能

README 快速开始

LLMVault

The Ultimate Hands-On OWASP LLM Top 10 Training Platform

🎬 Demo

Learn • Exploit • Defend

A deliberately-vulnerable, CTF-style training range for the OWASP Top 10 for LLM Applications (2025) — WebGoat / KubeGoat, but for AI. 25 labs across three tiers: ten core one-per-category labs; ten advanced, multi-turn labs (jailbreaking, data poisoning, agent exploitation, model extraction); and five expert labs modelling real-world attack classes. Each tier unlocks the next.

Every lab pairs the attack with a defense (in the private solutions guide): learn the fix by practising the break.

⚠️ Everything here is intentionally insecure. Authorised, self-hosted security education only. Don't expose it to the internet or reuse its code in production.

📸 Screenshots

Labs (three tiers)A lab in actionCompletion card

🧩 Core Tier — OWASP LLM Top 10

OWASP (2025)LabTechnique
LLM01 Prompt InjectionThe Obedient Assistantdirect instruction override
LLM02 Sensitive Info DisclosureRedaction Theateroutput-filter bypass via encoding
LLM03 Supply ChainTrust the Manifest?typosquatted / unsigned dependency
LLM04 Data & Model PoisoningThe Sleeper Phrasepoisoned-data backdoor trigger
LLM05 Improper Output HandlingRendered Without Questionunsanitised output → injection
LLM06 Excessive AgencyKeys to the Kingdomover-permissioned tool, no authz
LLM07 System Prompt LeakageLoose Lipssecret leaked from system prompt
LLM08 Vector & EmbeddingRetrieval Without BordersRAG retrieval ignores ACLs
LLM09 MisinformationThe Yes-Mansycophancy / false authority
LLM10 Unbounded ConsumptionDenial of Walletrunaway generation + leaky error

🔥 Advanced Tier — Multi-Turn Challenges (unlocks after completing all 10 Core challenges)

These are conversational: no single message wins — they require building state across turns (roleplay escalation, iterative poisoning, tool chaining, oracle querying).

OWASPLabAdvanced technique
LLM01Roleplay Unchainedmulti-turn jailbreak via persona escalation
LLM02Death by a Thousand Hintsfragment reconstruction from a partial-disclosure oracle
LLM0

项目描述

An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

S40911120
精选
S40911120 GitHub avatar

recensa

Recensa is a self-hosted web viewer that indexes Claude Code session transcripts into a local SQLite database, enabling full-text search, replay, and audit of all past agent conversations without uploading data anywhere.

AI 与机器学习大语言模型
67
makecindy
精选
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI 与机器学习大语言模型
958
uzairansaruzi
精选
uzairansaruzi GitHub avatar

hermex

Hermex is a native SwiftUI iPhone app that lets you control a self-hosted Hermes AI agent directly from your phone, with no subscriptions, tracking, or third-party relay.

AI 与机器学习大语言模型
941