risk
AI endpoint abuse, scraping and model extraction
Adversaries scrape inference endpoints at scale to extract model behaviour or proprietary data, exhaust compute budgets through unbounded consumption, or harvest system prompts and technical details disclosed in outputs or documentation, degrading service and eroding competitive and security posture.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- ai_governance
- domain
- AI Governance
- Network & Communications Security
- taxonomy
- owasp-llm-top10-2025
- nist-ai-rmf-risk
- inherent_rating
- medium
Details
- risk_id
- ai-endpoint-abuse-model-extraction
- category
- ai_governance
- likelihood
- medium
- impact
- medium
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- owasp-llm-top10-2025
- nist-ai-rmf-risk
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-14 — Authorize public content and external information sharing mitigates AI endpoint abuse, scraping and model extraction
- strength
- related
- rationale
- Pre-publication review of technical details keeps system-prompt and architecture information from aiding extraction attempts.
- UC-AI-21 — Commission independent third-party AI evaluations on a quarterly cadence mitigates AI endpoint abuse, scraping and model extraction
- strength
- related
- rationale
- Adversarial-robustness testing includes extraction and over-disclosure probes against the endpoints.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse mitigates AI endpoint abuse, scraping and model extraction
- strength
- primary
- rationale
- Rate limiting, authentication, and monitoring of inference endpoints directly stop scraping, extraction, and unbounded-consumption abuse.