Exposed model endpoints are now being used, not only catalogued
11 of 108 AI-aware addresses, 311 generation requests (honeypot); 2 of 39 (network sensor)
Read the finding
An earlier version of this page reported that everything reaching these AI ports was taking inventory and none of it was using the model. That held for the first day of collection and no longer does. Over eleven days the emulated endpoints received 311 chat or generation requests from 11 addresses, out of 108 that spoke a model API at all. The network sensor saw the same shift on a smaller scale: two of 39 AI-aware addresses moved on from listing models to requesting chat, generation or a model pull. Listing is still the common case, and most callers never go further, but the population now contains callers that spend inference capacity rather than count it. The operational distinction stands: a listing request is reconnaissance, and a generation request against an unauthenticated endpoint is someone using your hardware. The difference is that both are now observed here.
- Evidence
- First-party capture of POST requests to chat, generate and chat-completions paths, own monitoring traffic excluded. Network-sensor figure from the vendor field model_use_paths_requested. No model is ever run; every response is a fixed inert string.
- Assumptions
- That the own-traffic filter is complete. It combines known operator addresses with the monitoring user agents and cannot see an unlisted operator address, though none of the eleven callers matches either.
- Independence
- Two collectors on one host, one first-party and one vendor-processed. Not independent of each other in vantage point.