A scoring API caps each key at 1,000 calls a day - why doesn't that stop model extraction?
answer
- ask what the limit is attached to
- count identities, not requests
- the adversary is patient, not loud
- what does one new account cost?
- a limit that divides is not a bound
basics
~20 sThe cap is attached to a key, and keys are cheap. Someone who can open self-serve accounts buys any total volume they want; the cap only fixes how many identities they need. The binding price is identity, not the per-key count.
solid answer
~40 sA per-key cap divides an extraction campaign; it does not bound it. A party fitting a functional copy of a paid relevance-scoring model can open many self-serve accounts, keep every one of them inside its daily allowance, and spread the same total query volume over weeks. Nothing crosses a threshold and no single identity looks remarkable. Their sum has no per-minute term in it at all: it is the number of replies they need for the fidelity they want, times the price per call, plus the price of each identity they have to stand up. The cap only sets the divisor between those last two terms. Treat a quota as a price you charge the adversary, never as a boundary; and note that your smallest paying customers hit it before any adversary does.
go deeper
Be ready to say what the limit is attached to. A cap counted per key bounds one key; the adversary chooses how many keys to hold, so recall that identity cost, not the per-key number, is the term that matters.
Explain the adversary's arithmetic out loud: replies needed times price per call, plus the price of each identity. Show where the cap enters - as a divisor setting how many identities are needed - and point out that no per-minute term appears at all.
Expect to be asked what you would watch instead, and to say plainly that a quiet threshold is evidence about the threshold, not about the model. Account for who else pays: the smallest legitimate customers meet the cap before any adversary does.
Own the framing that this is a priced surface, not a protected one. Be ready to argue what raising the price of an identity would cost the self-serve funnel, and to state which fidelity of copy the business is content to have loose in the world.
## The setting A relevance-scoring service sells predictions by the call: a buyer describes an impression opportunity, and the service returns a predicted click-through score that feeds directly into what the buyer bids. Access is metered by API key, and each key is allowed 1,000 calls a day. An adversary wants a functional copy - a model of their own whose outputs track the service's closely enough that they can bid without paying per call. The reflex answer, and the one this question exists to break, is: *we cap requests per key, so a full extraction would take years.* ## What a per-key cap actually asserts A quota is a property of a credential, not of a person. It answers exactly one question - how much may this key consume today - and says nothing about how many keys exist behind one intent. To turn a per-key number into a statement about an adversary you need a second fact that the quota does not supply: that the adversary can hold only one key. On a self-serve product that fact is false by design. Keys are issued to anyone who completes signup, and signup costs whatever your onboarding charges, which is often an email address and a payment instrument that can be recycled. ## The arithmetic the adversary runs Write the bill out and the shape of the problem becomes obvious. It has three terms: - the number of replies needed for the fidelity of copy they want; - the price per call, which you publish; - the price of standing up one identity, times the number of identities. The per-key allowance enters only in the last term, and only as a divisor: replies needed, divided by the allowance and by however many days they are willing to spend, gives the identity count. There is no per-minute quantity anywhere in the sum. That is the whole point. A control that appears in the adversary's cost model as a divisor is a price; a control that appears as an infinity is a boundary; this one is a price. ## Why nothing ever trips Extraction is patient. A campaign spread across a pool of self-serve accounts over weeks produces, per identity, a small unremarkable customer: inside quota, inside any burst limit, paying its invoice. In aggregate it is the entire campaign. Traffic that never exceeds a count is exactly what a threshold-shaped defence is designed to accept, and the adversary can read your published limits before they start, which is what makes designing around them cheap. This leads to a direction-of-claim point worth stating precisely in an interview: a quiet counter is evidence about the counter. It reports that nobody exceeded the number you chose to watch. It does not bound how many replies left the building, and it says nothing whatsoever about whether a copy now exists. ## Three consequences **Tightening the cap multiplies identities, not time.** Dropping from 1,000 to 100 calls a day does not make the campaign ten times longer; it makes it need ten times as many accounts. Whether that hurts is a question about your onboarding, not about your rate limiter. **The honest side pays first.** Legitimate high-volume buyers are the callers whose ordinary day brushes a per-key ceiling. The same control a funded adversary treats as bookkeeping is the one that generates support tickets from customers. **The unspreadable cost is the interesting one.** Any cost the adversary can divide across more keys is amortised away. The only terms they cannot spread are the ones attached to an identity rather than to a call - what it takes to bring a new account into existence, and whether the accounts can be linked back into one actor afterwards. That is an observation about where cost sits, not a prescription: raising identity friction is paid for by the self-serve funnel, which makes it a product decision rather than a security setting. ## What this is not It is not an argument that limits are pointless. A quota prices out the unfunded and the careless, bounds accidental scraping, keeps one buggy client from consuming a shard, and leaves a billing record that later makes joining identities possible at all. Those are real. They are simply not the claim *extraction would take years*, and a review that records the quota as extraction risk mitigated has written down a price as if it were a barrier. ## How to say it Ask what the limit is attached to; count how many of those things the adversary needs; price one of them. If the answer is the price of an email address, you have said everything the interviewer wanted to hear.
- Lower the cap from 1,000 to 100 calls a day - what actually changes?The campaign needs ten times as many identities for the same total volume, so the adversary's bill rises by ten identity prices, which may be pocket change. Meanwhile every legitimate caller whose ordinary day exceeds 100 now fails, so the tightening lands hardest on the side that is paying you. The extraction sum still contains no per-minute term.
- The traffic logs show no spike at all. Does that mean nobody is extracting?No - it means nobody exceeded a count. A campaign built around published quotas produces precisely the traffic shape you already call normal: flat, spread across identities, spread across weeks. The absence of a spike is evidence that your thresholds were readable, not evidence about who now holds a copy of the scoring function.
- Where does the per-key cap appear in the adversary's cost model?Only as a divisor: replies needed, divided by the per-key allowance and the days they will spend, gives the number of identities to fund. It never appears as a wall. That is why the interesting number is what one identity costs to create, and how much of that cost your onboarding actually imposes.
A per-till spending limit does not cap what you can carry out of a supermarket; it caps what you can carry through one queue. If joining a queue is free, the limit only tells you how many trolleys to push.
saying these in an interview costs you the question
- Says a per-key rate limit makes extraction take years
- Treats a quota as a boundary rather than a price
- Assumes one adversary means one key
- Expects an extraction campaign to arrive as a burst
- Forgets that honest high-volume callers hit the cap first