I Scanned Gemma 4 Against OWASP Top 10 — Here's the Report Card
- Time
- 2026-08-09 10:00 ~ 10:30
- Speaker
- 徐方繹 Fngi Shiu
- Room
- RB102
- Co-write
Abstract
When Google released Gemma 4, it came with a model card and safety benchmarks — tested by Google themselves. But what happens when you rescan it from an attacker's perspective using OWASP LLM Top 10 criteria? This talk shares the full process and results of our red team scan on Gemma 4 26B, run on an NVIDIA DGX Spark GB10 and Mac mini M4 (MLX). We used the OpenClaw attack chain to test each OWASP LLM Top 10 risk category, including Prompt Injection (LLM01: 5 out of 7 tests passed), Visual Prompt Injection (2 out of 3 confirmed vulnerabilities), and real test data across other categories. This is not a theoretical analysis — it's a report card with concrete pass/fail results. We'll walk through the attack techniques used in each test, how Gemma 4 actually responded, and which weaknesses can be mitigated with NemoClaw Guardrail. The goal isn't to say Gemma 4 is insecure. It's to show every developer using open-source models that the risks not listed on the model card are yours to test. We'll open-source our testing scripts so you can run the same vulnerability scan on any open-source LLM.
Speaker
徐方繹 Fngi Shiu
Fngi 專注於 AI 安全治理與 LLM 紅隊測試。曾任多家台灣機構 CISO,同時擔任 GDG Taipei Organizer 及台灣金融研訓院 AI 安全講師。擁有超過十年資安與全端工程經驗。