How do you defend an LLM service against resource-exhaustion and denial-of-service attacks?
An attacker doesn't have to breach your LLM to hurt you, only make it do expensive work. A few crafted prompts can pin your GPUs and run up the bill. The defense is not a bigger rate limit.
Updated Sep 2026 · Grounded in real GenAI, LLM, and AI/ML engineering interview loops and written to a senior-engineer editorial bar.
An attacker doesn't have to breach your LLM to hurt you, only make it do expensive work. A few crafted prompts can pin your GPUs and run up the bill. The defense is not a bigger rate limit.
Lead with where the obvious approach breaks, because that is the judgment they are screening for — most candidates jump straight to the happy path and lose the room.
Then walk the failure back through the pipeline in order, naming the one metric the customer's exec sponsor actually cares about before you propose the fix.