AppWorld Singapore 2025: AI and AppSec Insights with OWASP Singapore

F5 DevCentral CommunityAbout 3 min readJun 18, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

  • OWASP (Open Web Application Security Project)
  • AppSec (Application Security)
  • GenAI (Generative AI)
  • LLM (Large Language Model)
  • Supply Chain Security
  • API Security
  • OWASP Top Ten
  • Injection
  • Broken Access Control

OWASP and GenAI Security Landscape in Singapore

  • OWASP's Role in GenAI: Onn Chee acknowledges Aubrey's work within OWASP in the GenAI space, noting that Singaporean authorities are referencing OWASP artifacts related to GenAI. This highlights OWASP's growing influence and relevance in the rapidly evolving field of AI security.
  • Developer Gap: Despite the increasing attention on GenAI, a significant gap exists in developers' ability to write secure LLM or AI applications. This is a key challenge that OWASP can address through education and empowerment.
  • Marriage of Security Aspects: AI applications are not isolated entities; they rely on libraries and cloud-hosted APIs. Therefore, securing them requires a combination of LLM security, API security, traditional application security (like the OWASP Top Ten), and supply chain security.
  • OWASP Top Ten Applicability: Traditional vulnerabilities like injection and broken access control, as defined in the OWASP Top Ten, remain relevant in the LLM world. This underscores the need to apply established security principles to new technologies.

Education and Industry Collaboration

  • University Curriculum Gap: Universities and colleges in Singapore are not yet making AppSec a core, mandatory module for software engineering students. This leaves a crucial gap in the education of the next generation of developers.
  • OWASP's Educational Role: Industry groups like OWASP play a vital role in educating and enabling developers, especially in the absence of comprehensive AppSec education in academic institutions.
  • F5's Support for OWASP: F5 is recognized as an ardent supporter of the OWASP Singapore chapter, highlighting the importance of industry collaboration in advancing application security.

Specific Security Concerns

  • LLM Security: Protecting the LLM itself is a key concern, including aspects like model protection and network security.
  • Supply Chain Security: Ensuring the security of the models and libraries used in AI applications is crucial, as vulnerabilities in these components can compromise the entire application.
  • API Security: AI applications often rely on APIs, making API security a critical aspect of overall security.
  • Traditional Vulnerabilities: Classic vulnerabilities like injection and broken access control still apply in the LLM world and must be addressed.

Notable Quotes:

  • Onn Chee: "How can the developer write secure LLM apps? Or AI apps. And I think that's the chasm and that's the gap that I hope that OWASP can also play as a strong partner to educate, empower and enable developers to write secure AI apps."
  • Onn Chee: "I would see a confluence of various aspects like LLM security, API security, your traditional application security, your classical Top Ten, for example, with injection and broken access control. I think that still applies in the LLM world."

Synthesis/Conclusion:

The conversation highlights the evolving AppSec landscape in Singapore, particularly with the rise of GenAI. While OWASP is playing a crucial role in providing guidance and resources, a significant gap remains in developers' ability to build secure AI applications. This gap is exacerbated by the lack of comprehensive AppSec education in universities. Addressing these challenges requires a multi-faceted approach that combines LLM-specific security measures with traditional application security principles, supply chain security, and API security. Industry collaboration, as exemplified by F5's support for OWASP, is essential for advancing AppSec and empowering developers to build secure AI applications.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.