Amazon GuardDuty Introduces AI Protection for AWS AI Workloads
Amazon GuardDuty now offers AI Protection, extending threat detection to AWS AI services like Amazon Bedrock and Amazon SageMaker, enabling automatic detection of AI-specific threats such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts.
Amazon GuardDuty now offers AI Protection, extending threat detection to AWS AI services including Amazon Bedrock and Amazon SageMaker. As organizations rapidly adopt AI, security teams often lack visibility into threats specifically targeting AI workloads, such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts. GuardDuty AI Protection continuously monitors these workloads, allowing security teams to detect and respond to AI-specific threats without manual configuration or custom tooling. GuardDuty AI Protection analyzes CloudTrail management and data events from AWS AI services to identify suspicious activity, including unusual invocation patterns, cost harvesting attacks where threat actors force AI resources to consume excessive GPU time and tokens, and prompt injection attempts through integration with Amazon Bedrock Guardrails. Threat findings flow directly into AWS Security Hub, providing teams with a single view of AI assets and threats for prioritized response. GuardDuty AI Protection can be enabled in a few steps via the GuardDuty or Security Hub console and can be centrally enabled for all accounts in an organization using AWS Organizations. GuardDuty AI Protection is available to GuardDuty customers with a 30-day free trial. For pricing details, visit the Amazon GuardDuty pricing page. To learn more, see the Amazon GuardDuty User Guide and the Amazon GuardDuty product page. For the full list of supported Regions, see the AWS Regional Services List.