What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

Cost harvesting

Cost harvesting is an attack that drives a victim's paid AI service beyond its normal operating capacity so that the owner pays more, using floods of cheap queries, a few expensive ones, or instructions that make an AI agent waste tool calls. MITRE ATLAS catalogues cost harvesting as technique AML.T0034, under the Impact tactic.

Last reviewed

Key points

  • Cost harvesting is an attack on a victim's bill. The attacker drives a paid AI service past its normal capacity so that its owner pays more. MITRE ATLAS catalogues it as AML.T0034.
  • There are three routes. Send many cheap queries, send a few expensive ones, or plant instructions that make an AI agent waste tool calls or loop.
  • Autoscaling makes it worse. The service adds capacity to keep up, and the owner pays for that too. Saturated queues can also lock out legitimate users.
  • ATLAS's defences are rate limits, access controls, and budgets on each request and agent run.
  • ATLAS links no case study to cost harvesting yet. OWASP's nearest term is Denial of Wallet, which fits the flood route best.

Cost harvesting is an attack on the bill. MITRE ATLAS files it as AML.T0034: adversaries “deliberately drive a victim’s AI services beyond normal operating capacity with the intent of increasing the cost of services.” The aim is the victim’s financial harm. ATLAS separates it from resource hijacking, where the attacker uses the victim’s compute for their own purposes.

How it works

ATLAS lists three routes.

  • Excessive queries. Many normal, cheap requests, automated to exploit “pay-per-use billing models”.
  • Resource-intensive queries. A few requests that each cost a lot. Against generative models: long inputs, requests for extremely long outputs, or prompts that need complex reasoning. Against vision and language models: sponge examples, inputs crafted to maximise energy use and delay. ATLAS notes these “may be more difficult to detect and block or limit” than a flood.
  • Agentic resource consumption. A prompt injection, or poisoned data the agent reads through its tools, tells an AI agent to do wasteful work, such as “Summarize the following text 1000 times.” It can also push the agent into delegating tasks to itself in a loop.

Why it matters

ATLAS calls cost harvesting “especially relevant for cloud-hosted, pay-per-use AI/ML platforms”, such as LLM APIs. It warns that autoscaling can amplify it: the service adds capacity to keep up, and that capacity is billed too. Pushed far enough, the pressure saturates queues and causes “outright service unavailability for legitimate users”. When outage is the aim, ATLAS files the attack separately, as denial of AI service.

ATLAS maps query rate limits and access controls against cost harvesting, though it notes rate limits “may not protect against attacks that require few requests”. It also maps budgets on each request and workflow. For agents, those cap how many steps and tool calls an agent takes, how long it runs and what it spends downstream. AI red teaming sends cost-amplifying requests on purpose and checks that the budgets, alerts and termination controls hold.

In practice

ATLAS has no worked example yet. As of its September 2026 release, no ATLAS case study maps to AML.T0034 or its three sub-techniques, so the routes above come from the technique descriptions, not from recorded attacks.

Where definitions disagree

OWASP cites AML.T0034 but does not use the name in its own text. Its 2025 LLM10 Unbounded Consumption lists Denial of Wallet: “a high volume of operations” that exploits “the cost-per-use model of cloud-based AI services”. That is closest to ATLAS’s first route. OWASP lists expensive queries as a separate example, and files the whole group with denial of service and model theft. ATLAS groups by the attacker’s goal, the bill, whatever the route.

Questions and answers

What is cost harvesting in AI security?

Cost harvesting is an attack that drives a victim's paid AI service beyond its normal operating capacity so that the owner pays more. MITRE ATLAS catalogues it as AML.T0034. The attacker sends many cheap queries, a few expensive ones, or instructions that make an AI agent waste tool calls.

How is cost harvesting different from denial of AI service?

Mainly the goal. ATLAS files resource pressure aimed at availability as denial of AI service, AML.T0029, and pressure aimed at the victim's bill as cost harvesting, AML.T0034. Floods and expensive inputs appear in both. Coercing an AI agent into wasteful tool calls appears only under cost harvesting. ATLAS notes that cost harvesting can also cause outright service unavailability for legitimate users.

Is cost harvesting the same as denial of wallet?

Not quite. OWASP's LLM10:2025 Unbounded Consumption describes Denial of Wallet as a high volume of operations that exploits the cost-per-use model of cloud AI services. That is closest to the first of cost harvesting's three routes. ATLAS's cost harvesting also covers a few expensive queries and agents coerced into wasteful tool calls.

Sources

  1. MITRE ATLAS, AML.T0034 Cost Harvesting (collection 2026.09)MITRE
  2. LLM10:2025 Unbounded Consumption, OWASP Top 10 for LLM ApplicationsOWASP