PD³F框架可动态防御大模型资源耗尽攻击,提升服务容量5倍。
$PD^3F$: A Pluggable and Dynamic DoS-Defense Framework Against Resource Consumption Attacks Targeting Large Language Models
- 输入侧用资源指数动态调度请求,输出侧早停恶意生成。
- 实测在对抗负载下用户访问能力提升500%。
- 适合部署大模型的系统安全团队快速集成使用。
大型语言模型(LLMs)因高计算需求易受资源消耗攻击,可能导致服务器性能下降甚至崩溃,已有针对LLM的拒绝服务(DoS)攻击案例。然而现有工作缺乏有效缓解策略,使真实部署面临未解安全风险。为此,我们提出可插拔、动态的DoS防御框架PD³F,采用双阶段防御机制:输入侧引入资源指数,指导动态请求轮询调度,降低高并发场景下的恶意攻击资源开销;输出侧设计自适应末端抑制机制,提前终止过度恶意生成。六种模型实验表明,PD³F显著缓解资源消耗攻击,在对抗负载下用户访问容量最高提升500%。该工作推动了大模型在资源敏感场景下的韧性与自适应部署。
原文摘要 · Abstract (English)
Large Language Models (LLMs), due to substantial computational requirements, are vulnerable to resource consumption attacks, which can severely degrade server performance or even cause crashes, as demonstrated by denial-of-service (DoS) attacks designed for LLMs. However, existing works lack mitigation strategies against such threats, resulting in unresolved security risks for real-world LLM deployments. To this end, we propose the Pluggable and Dynamic DoS-Defense Framework ($PD^3F$), which employs a two-stage approach to defend against resource consumption attacks from both the input and output sides. On the input side, we propose the Resource Index to guide Dynamic Request Polling Scheduling, thereby reducing resource usage induced by malicious attacks under high-concurrency scenarios. On the output side, we introduce the Adaptive End-Based Suppression mechanism, which terminates excessive malicious generation early. Experiments across six models demonstrate that $PD^3F$ significantly mitigates resource consumption attacks, improving users' access capacity by up to 500% during adversarial load. $PD^3F$ represents a step toward the resilient and resource-aware deployment of LLMs against resource consumption attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。