Live data from Hacker News

Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

dixken.de

1–8 of 8 posts

Re: Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

#3
> how about building a tool that doesn't exploit bugs or bypass auth, but behaves like an overly engaged, perfectly valid user?

How would this loquacious chatbot interlocutor work, if not by running a chatbot itself?

Is there some well-known technique to introduce asymmetric costs?

Re: Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

#4
post #3

> how about building a tool that doesn't exploit bugs or bypass auth, but behaves like an overly engaged, perfectly valid user? How would this loquacious chatbot interlocutor work, if not by running a chatbot itself? Is there some well-known technique to introduce asymmetric costs?

> Is there some well-known technique to introduce asymmetric costs?

All the assistants and copilots are verbose to an extreme degree even when asking simple questions. Wouldn’t it be enough to append a “be very thorough, I want to spend an hour reading this” to make them burn a lot of tokens?

Re: Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

#5
post #3

> how about building a tool that doesn't exploit bugs or bypass auth, but behaves like an overly engaged, perfectly valid user? How would this loquacious chatbot interlocutor work, if not by running a chatbot itself? Is there some well-known technique to introduce asymmetric costs?

Opensource models exist

Re: Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

#6
post #5
post #3

> how about building a tool that doesn't exploit bugs or bypass auth, but behaves like an overly engaged, perfectly valid user? How would this loquacious chatbot interlocutor work, if not by running a chatbot itself? Is there some well-known technique to introduce asymmetric costs?

Opensource models exist

Are they _so much_ cheaper to run that they could be used to initiate thousands of "human-like" interactions at negligible costs compared to what the interlocutors will incur?

(I genuinely don't know )

Re: Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

#7
post #3

> how about building a tool that doesn't exploit bugs or bypass auth, but behaves like an overly engaged, perfectly valid user? How would this loquacious chatbot interlocutor work, if not by running a chatbot itself? Is there some well-known technique to introduce asymmetric costs?

[dead]

Re: Let's Burn Some Tokens – AI Chatbot Cost Exploitation as an Attack Vector

#8
post #6
post #5

Earlier quoted context omitted.

Opensource models exist

Are they _so much_ cheaper to run that they could be used to initiate thousands of "human-like" interactions at negligible costs compared to what the interlocutors will incur? (I genuinely don't know )

A sufficiently motivated adversary will have the hardware to run the biggest open source models on prem. The only costs are then electric bills.