Inference Resource Exhaustion Attack
推論資源耗盡攻擊
Operation & Monitoring
Risk Description
When an attacker occupies computing resources continuously using a small number of extremely complex requests; due to unmitigated control gaps, the organization's traffic protection uses request count as its threshold and is never triggered, yet the service can no longer respond normally due to resource exhaustion, triggering compliance exposure and operational reputational costs.
Framework Mappings
OWASP Top 10 for LLMLLM10
MITRE ATLASAML.T0029
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2
Risk Treatment & Implementation Guidance
Meter by compute quota rather than request counts alone, governing by request complexity; Detect and degrade or reject extreme-complexity request patterns; Alert on resource utilization, intervening on anomalous occupation