Skip to content

Denial of Service and Cost Attacks on AI

How attackers exhaust AI resources or run up bills, and how to protect budgets and availability.

Editorial team 1 min read

AI inference is expensive. Attackers — or buggy clients — can exploit that.

Attack Types

  • Volume attacks: flooding an AI endpoint with requests.
  • Expensive inputs: very long prompts or files that consume many tokens.
  • Output amplification: prompts designed to produce extremely long responses.
  • Agent loops: tricking agents into repeating actions indefinitely.
  • Resource-heavy tools: triggering costly searches or computations.
  • Account abuse: free tiers or stolen API keys used to consume resources.

Defences

  • Authentication and per-user rate limits.
  • Limits on input size, output length and conversation length.
  • Step, time and cost budgets for agents.
  • Spending caps and alerts with model providers.
  • Caching for repeated requests.
  • Anomaly detection on usage patterns.
  • Protection of API keys, which are valuable to attackers.

Business Design

Pricing and free tiers should account for abuse. Require verification for higher usage levels.

Monitor

Track cost per user and per feature, and investigate sudden increases quickly.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025