{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"ai_governance","domain":["AI Governance","Network & Communications Security"],"inherent_rating":"medium","taxonomy":["owasp-llm-top10-2025","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-endpoint-abuse-model-extraction","description":"Adversaries scrape inference endpoints at scale to extract model behaviour or proprietary data, exhaust compute budgets through unbounded consumption, or harvest system prompts and technical details disclosed in outputs or documentation, degrading service and eroding competitive and security posture.","details":{"category":"ai_governance","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-endpoint-abuse-model-extraction","taxonomies":["owasp-llm-top10-2025","nist-ai-rmf-risk"],"treatment":"mitigate"},"id":"risk:ai-endpoint-abuse-model-extraction","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-endpoint-abuse-model-extraction","sourceIds":["aiuc-1","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI endpoint abuse, scraping and model extraction","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57c1e16cec640d299115c1992f9706bc20fec65222ac19a4997b8e8a7c78fab3","properties":{"rationale":"Pre-publication review of technical details keeps system-prompt and architecture information from aiding extraction attempts.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.json","targetId":"risk:ai-endpoint-abuse-model-extraction","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a1a2dc56bb78b8ff0521c05adc3647c37d95cdf99641219b074b7ae7175865d","properties":{"rationale":"Adversarial-robustness testing includes extraction and over-disclosure probes against the endpoints.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.json","targetId":"risk:ai-endpoint-abuse-model-extraction","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a340fde6d9d4f7a36559a15043c17bac883b57bf6dd7bb715a1212a87782ced2","properties":{"rationale":"Rate limiting, authentication, and monitoring of inference endpoints directly stop scraping, extraction, and unbounded-consumption abuse.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.json","targetId":"risk:ai-endpoint-abuse-model-extraction","type":"mitigates"}],"schemaVersion":1}
