Skip to content
Threat Feed
medium advisory

Detection of Unauthorized Amazon Bedrock Parameter Manipulation

Adversaries are exploiting Amazon Bedrock APIs by submitting malformed inference parameters to trigger repeated validation exceptions, potentially for model evasion, cost harvesting, or testing defensive boundaries.

This threat involves the systematic exploitation of the Amazon Bedrock InvokeModel and InvokeModelWithResponseStream APIs by submitting intentional API calls with invalid inference parameters. By mapping parameters from one foundation model to another that does not support them, or by providing out-of-bounds values, an attacker induces ValidationException errors.

While these errors represent a failure of the request, a high frequency of such exceptions from a single user identity suggests malicious reconnaissance to map model architecture, attempts to bypass specific security guardrails or model limitations, or a denial-of-service attack intended to cause financial impact through excessive API usage. This activity is consistent with techniques documented in MITRE ATLAS for model evasion, cost harvesting, and flooding AI systems with chaff data. Defenders should focus on anomalous error rates associated with individual IAM principals accessing Bedrock services.

Impact

Successful exploitation of this vector can lead to unauthorized model access, the circumvention of established security policies, or significant financial loss due to billing spikes. The impact is primarily organizational, affecting cloud resource budgets and the security integrity of internal generative AI applications.

Recommendation

Prioritized actions for detection engineering and cloud security teams:

  • Deploy the provided detection logic to identify users exceeding 3 validation errors within a single minute in the AWS Bedrock environment.
  • Review IAM policies for accounts identified by the detector to ensure adherence to the principle of least privilege, specifically regarding Bedrock API permissions.
  • Establish alerting for anomalous cost spikes associated with Bedrock API consumption as a secondary indicator of cost harvesting attempts.
  • Audit existing logs for high volumes of ValidationException errors to identify if this behavior has occurred historically.

Immediate actions

Deploy rule to detect high-frequency Bedrock ValidationException events.

Detection Engineering 48h

Threat Hunt

Search historical logs for spikes in ValidationException for high-privileged accounts.

AML.T0034 medium high confidence hunt now

Data: Bedrock invocation logs

Detection coverage 1

Detect Multiple AWS Bedrock Validation Exceptions by Single User

high

Detects four or more ValidationException errors generated by a single user account in AWS Bedrock within a one-minute window, suggesting parameter fuzzing or malicious API manipulation.

sigma tactics: defense_evasion, impact sources: webserver

Detection queries are available on the platform. Get full rules →