🛠️ Lab 2 — Risk Teach-Backs and Incident Classification (50 pts)
Goal: Build working fluency with all ten 2025 OWASP LLM risk categories by teaching one to your peers and then applying all ten to classify real-world-style incidents — including the tricky overlaps. Steps:
- Form or join a team (per your instructor's grouping). Each team is assigned exactly one of the ten 2025 risks (LLM01–LLM10).
- Go to the free OWASP GenAI Security Project resource hub at genai.owasp.org/llm-top-10/ and open your team's specific per-risk page (e.g., the LLM05 page linked in Resources below for Improper Output Handling).
- As a team, read your risk's full entry: description, common examples, prevention/mitigation strategies, and any example attack scenarios given.
- Prepare a 5-minute teach-back covering: (a) what the risk is in plain language, (b) one concrete example of how it manifests, (c) the top 2–3 mitigations OWASP recommends, and (d) one open question your team still has.
- Add a mini demo idea: a one-paragraph sketch of a small, safe demonstration of this risk that could be built later in the course (no need to build it now — just describe it clearly enough that a classmate could pick it up).
- Deliver your teach-back to the class (in person, on video, or recorded — per your instructor's format).
- Individually, complete the classification exercise: your instructor will distribute roughly 15 short breach/incident write-ups (drawn from the OWASP per-entry examples and public incident summaries). For each one, assign the correct LLM01–LLM10 category and write 2–3 sentences justifying your choice.
- Pay special attention to the tricky overlaps flagged in this week's lecture — for example, an incident where a leaked system prompt (LLM07) also happens to expose customer data (LLM02). Justify which category is the primary classification and explain your reasoning for the borderline call.
- Optional stretch: cross-reference the free DeepTeam framework's OWASP-mapped attack modules (trydeepteam.com) to see how each risk maps to an automated red-teaming test, and note in your write-up which module(s) correspond to your team's risk.
- Compile your teach-back notes/slides and your individual classification answers into a single submission.
Deliverables: One team teach-back artifact (slides, notes, or recording link) plus your individual completed classification exercise (15 incidents, each labeled LLM01–LLM10 with justification), submitted as a combined online upload or via text entry.