Most Popular Detection 2026 – LLM Model Extraction / Distillation Abuse Pattern

This rule monitors cloud application events for high-frequency, automated API calls directed at AI/ML inference endpoints. A high volume of queries (over 1000) accessing a diverse range of objects (over 50) within a short window (60 minutes) by a single identity or IP address is flagged. Such behavior is characteristic of model extraction or distillation attacks, where an adversary probes an AI model to replicate its capabilities or internal parameters.