<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Google Cloud Vertex AI - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/google-cloud-vertex-ai/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:32:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/google-cloud-vertex-ai/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>GCP Vertex AI High Volume Request Pattern Detection</title><link>https://feed.craftedsignal.io/briefs/2026-10-gcp-vertex-ai-high-volume/</link><pubDate>Wed, 07 Oct 2026 16:32:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gcp-vertex-ai-high-volume/</guid><description>High volumes of GenerateContent requests from a single IP against Vertex AI models indicate potential model extraction, automated scraping, or LLMjacking attacks.</description><content:encoded><![CDATA[<p>Security teams should monitor for anomalous request volumes against Google Cloud Vertex AI models, specifically targeting the <code>PredictionService.GenerateContent</code> and <code>PredictionService.StreamGenerateContent</code> methods. Observed patterns of high request volume from a single <code>source.ip</code> within a short timeframe may signify model theft, systematic automated scraping, or LLMjacking, where an attacker leverages compromised credentials to exhaust prediction quotas or exfiltrate model knowledge. This behavior is documented by the MITRE ATLAS framework as Exfiltration via AI Inference API (AML.T0024) and Denial of AI Service (AML.T0029). Defenders should correlate these high-frequency events with associated service account activity, prompt content, and token volume to differentiate between legitimate batch processing and unauthorized interaction.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains unauthorized access to a Google Cloud principal or service account with permission to query Vertex AI models.</li>
<li>Attacker enumerates accessible model resources within the target GCP project.</li>
<li>Attacker initiates high-frequency <code>GenerateContent</code> or <code>StreamGenerateContent</code> calls targeting a specific model resource.</li>
<li>Attacker iterates through systematically crafted prompts to probe model responses and extract output patterns.</li>
<li>Attacker continues high-volume requests to maximize data exfiltration or deliberately exhausts the organization's prediction quota (LLMjacking).</li>
<li>Attacker potentially modifies model configuration via <code>SetPublisherModelConfig</code> to obscure future monitoring activity.</li>
<li>Attacker achieves final objective of either model weight reconstruction (theft) or resource denial through quota exhaustion.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation can lead to intellectual property theft through model extraction, unauthorized costs associated with LLMjacking, or service unavailability for legitimate users of the AI platform. These activities impact data confidentiality, billing integrity, and operational availability for organizations relying on GCP AI services.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Enable GCP Vertex AI <code>auditlogs</code> for <code>aiplatform.googleapis.com</code> to ensure visibility into prediction requests.</li>
<li>Establish a baseline for normal request volume per model and project to tune thresholds for the detection logic.</li>
<li>Review billing and quota usage for Vertex AI models for sudden, unexplained spikes.</li>
<li>If unauthorized activity is identified, rotate credentials for the calling principal and restrict the source IP via VPC Service Controls.</li>
<li>Pivot to prompt logs to inspect for repetitive probing behavior or large context data dumps indicative of systematic scraping.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>cloud</category><category>genai</category><category>model-theft</category><category>llmjacking</category></item></channel></rss>