Frameworks

The standards, mapped to real evidence

OWASP and MITRE tell you what the risks are; this atlas shows each one actually happening — documented incidents, playable attack simulations, and the controls that would have stopped them. Pick an ID you're working with to see its evidence base.

OWASP Top 10 for LLM Applications (2025)

official site ↗

The most-cited list of what goes wrong in LLM applications. Each entry below links the official risk to the real incidents, playable scenarios and controls in this atlas.

The adversarial-ML knowledge base of attacker techniques, modelled after ATT&CK. Each technique below is illustrated with documented incidents and hands-on simulations.

NIST AI Risk Management Framework

official site ↗

The US framework for governing, mapping, measuring and managing AI risk. Each subcategory below shows the concrete technical risks it covers and the evidence base behind them.

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗