Open cardosec

Case 3BF752 · AI security · L3 Applied

API Bill Spikes 40x Overnight

Practise as: Incident drill

Live alertA single customer API key made 2.1M calls to your fine-tuned model in 9 hours, with systematically varied prompts and logprobs enabled on every request.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Throttle or suspend the key; confirm with the account owner whether usage is legitimate or the key was leaked.
  2. Pattern suggests model extraction (distillation) or unbounded consumption; compare against normal usage baselines.
  3. Check for key leakage: public GitHub commits, client-side apps embedding the key, source IP diversity.
  4. Controls: per-key rate limits and spend caps, restrict logprobs to trusted tiers, anomaly alerts on query entropy.
  5. Involve legal: ToS violation for training competing models; preserve logs as evidence.

If the interviewer pushes back

  • How would you set rate limits that stop extraction without breaking your largest legitimate customers?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.