Slide 18 of 27
Part 4 · PreventionSlide 18
PART 4
Prevention
Slides 18–25 · 6 mitigation categories
Slide 18 · Prevention Overview
Six mitigation categories — one per slide.
OWASP defines the categories. We show what each means in practice and which incidents each stops.
🛡️
M1 — Validate Before Embedding
Strip hidden content, detect adversarial formatting, filter injected instructions before any document enters the vector store.
🔐
M2 — Permission-Aware Vector Stores
Enforce access controls at retrieval time — not just at document upload time.
🎯
M3 — Retrieval Controls Beyond Similarity
Add provenance checks and confidence thresholds so cosine similarity alone cannot be gamed.
🔒
M4 — Encrypt Vectors at Rest
Prevent embedding inversion attacks if the vector store is compromised or exfiltrated.
📊
M5 — Monitor for Poisoning Patterns
Log retrieval activity with provenance. Alert on anomalies — sudden ranking shifts, new documents scoring unusually high for high-value queries.
⏱️
M6 — Limit Embedding Persistence
Apply TTLs and cascade deletion from source to embedding, so poisoned vectors don’t outlast their source documents.
← BackNext → M1: Validate ingestion