AI model endpoint (LLM API): what it is and how it is attacked
Where an application sends a question, along with documents, images or data, to an AI model and gets an answer back.
Also known as
- LLM API
- inference endpoint
- model service
- AI service
Typing any of them into the editor finds this object.
Why it matters on a security diagram
It handles untrusted input by design, and whatever consumes its answer usually trusts it. Where the model has been given tools or credentials of its own, its permissions are the blast radius.
How it gets attacked, and what reduces it
How it gets attacked
- Instructions hidden in content the model later reads
- Model output used to trigger actions without a check
What reduces it
- Treat model output as untrusted input to whatever consumes it
- Never let an answer trigger an action without a check in between
- Give the model narrower access than the person asking, not wider
Where it sits
- Group
- Cloud and subscribed services · Things that only exist because somebody else runs the platform underneath them.
- Whose side, by default
- Ours · Belongs to the organisation the diagram is about.
- Catalogue identifier
- model-endpoint
Reviewed . CC BY 4.0.
Go deeper
Prompt injection pattern library · Free tool
Others in cloud and subscribed services
- Cloud platformAWS · Azure · GCP · Google Cloud · public cloud · hyperscaler · IaaSA supplier's computing platform, rented by the hour, where a setting made on a website creates or removes a whole system.
- Cloud accountsubscription · project · AWS account · Azure subscription · Google Cloud project · cloud environmentOne named compartment of a cloud platform, with its own bill and its own list of who may change what.
- Cloud account groupmanagement group · AWS Organizations · GCP folder · landing zone · account structureThe parent that owns all of an organisation's cloud accounts and can set rules over every one of them.
- Cloud control panelcontrol plane · management console · cloud portal · cloud API · management planeThe website and commands used to configure the cloud itself, as opposed to the systems running inside it.
- Supplier-run applicationSaaS · software as a service · cloud application · business applicationAn application a supplier runs entirely, which the organisation subscribes to and puts its data into.
- Connected appOAuth application · app registration · enterprise application · app consent · add-inAn outside program that somebody has allowed to reach company data on their behalf.
- Managed databaseRDS · Azure SQL · Cloud SQL · database as a service · DBaaSA database the cloud provider runs, where the data and the settings are yours but the machine is never touched.
- On-demand functionserverless · Lambda · Azure Functions · Cloud Run · FaaSA small piece of code that runs only when something asks for it, with no server to look after.
- Container platformKubernetes · K8s · cluster · EKS · AKS · GKE · OpenShiftThe system that decides where each packaged application runs, and starts it again when it stops.
- Container image storecontainer registry · image registry · ECR · ACR · artefact storeThe library of packaged applications that machines fetch from whenever they start something.
- Infrastructure blueprintinfrastructure as code · IaC · Terraform · state file · CloudFormation · BicepThe written description of what the cloud should contain, together with the record of what was actually built.
The cloud and subscribed services group lists all 12 of them side by side.
AI model endpoint on your own diagram
Open the editor, press N, and type LLM API. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.
Open the diagram maker