S0132RS3-T15-S0132-Z · Full risk code

Inference Resource Exhaustion Attack

推論資源耗盡攻擊

Operation & Monitoring
Risk Description

When an attacker occupies computing resources continuously using a small number of extremely complex requests; due to unmitigated control gaps, the organization's traffic protection uses request count as its threshold and is never triggered, yet the service can no longer respond normally due to resource exhaustion, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM10
MITRE ATLASAML.T0029
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Meter by compute quota rather than request counts alone, governing by request complexity; Detect and degrade or reject extreme-complexity request patterns; Alert on resource utilization, intervening on anomalous occupation