Slide 9 of 27
Part 2 · TypesSlide 9
PART 2
Types
Slides 9–13 · 4 patterns, each a real incident
Slide 9 · Part 2 Overview
OWASP names three categories. We're covering four.
Each gets its own real, confirmed incident.
🪪
PII Leakage
Personal data exposed during interaction with the LLM.
🧬
Proprietary Algorithm Exposure
Model internals or training data extracted via inversion attacks.
🏢
Sensitive Business Data Disclosure
Confidential company information surfaces in a generated response.
📚
Training Data Memorization
The model regurgitates verbatim text it was trained on.

The fourth — memorization — isn't one of OWASP's three officially named “Common Examples of Vulnerability,” but it's explicitly one of their own cited reference incidents. Worth its own slide.

← BackNext → PII Leakage