[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-model-exfiltration::en":3,"gloss-cluster-model-exfiltration::en":23,"gloss-next-model-exfiltration::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"model-exfiltration","security","Model Exfiltration (Model Extraction)","Model exfiltration — also called model extraction or model stealing — is an attack that reconstructs a proprietary model, or a close-enough copy, by systematically querying it and learning from the outputs. An attacker with API access sends large volumes of carefully chosen prompts, records the responses (and any confidence scores or logits you expose), and trains a cheaper substitute model that mimics your behavior. Related attacks try to recover training data or the system prompt itself. For SaaS builders, the exposed asset is often not the base LLM — which you rent — but the fine-tuning, prompt engineering, and proprietary data that make your feature valuable. Practical note: rate-limit and monitor per-key query patterns, avoid returning raw logits or verbose confidence data you don't need to, watermark or fingerprint outputs where feasible, and keep genuinely sensitive logic server-side behind business rules rather than encoding it entirely in a promptable model.","Model exfiltration reconstructs a proprietary model, or a close-enough clone, by systematically querying it through the API and training on the responses.",null,[11,14,17,20],{"slug":12,"name":13},"api-key","API Key",{"slug":15,"name":16},"fine-tuning","Fine-Tuning",{"slug":18,"name":19},"prompt-injection","Prompt Injection",{"slug":21,"name":22},"red-teaming","Red-Teaming",[24,28,32,36,39,42,45,48,51,54,57,60],{"slug":25,"category":5,"name":26,"updated_at":27},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":29,"category":5,"name":30,"updated_at":31},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":33,"category":5,"name":34,"updated_at":35},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":37,"category":5,"name":38,"updated_at":35},"bridge-letter","Bridge Letter",{"slug":40,"category":5,"name":41,"updated_at":35},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":43,"category":5,"name":44,"updated_at":27},"byok","Bring Your Own Key (BYOK)",{"slug":46,"category":5,"name":47,"updated_at":35},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":49,"category":5,"name":50,"updated_at":31},"data-classification","Data Classification",{"slug":52,"category":5,"name":53,"updated_at":35},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":55,"category":5,"name":56,"updated_at":35},"data-minimization","Data Minimization",{"slug":58,"category":5,"name":59,"updated_at":35},"data-poisoning","Data Poisoning",{"slug":61,"category":5,"name":62,"updated_at":35},"data-processing-agreement","Data Processing Agreement (DPA)"]