The AI/ML Security Working Group explores the security risks associated with Large Language Models (LLMs), Generative AI (GenAI), and other forms of artificial intelligence (AI) and machine learning (ML), and their impact on open source projects, maintainers, their security, communities, and adopters.
We envision a world where AI developers and practitioners can easily identify and use good practices to develop products using AI in a secure way. In this world, AI can produce code that is secure and AI usage in an application would not result in downgrading security guarantees.
AI / ML Security Resources
AI Security eBook
Securing Open Source in the Age of AI: A Practical Guide for Maintainers, Security Engineers, Researchers. Actionable advice for managing AI-generated contributions and using AI to improve security.
Agentic AI Tech Talk
Securing Agentic AI in Practice: From OpenSSF Guidance to Real-World Implementation. Open guidance and frameworks to help secure AI and machine learning systems,
MLSecOps Whitepaper
Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline Security. Built for practitioners, it draws on proven DevSecOps strategies and adapts them for AI/ML environments.