Blog
Build notes from the edge of AI usage.
Experiments, failures, and practical questions about investigating abnormal AI usage without reading prompts or responses.
I built an LLM API abuse detector. The benchmark kept lying to me.
I tried to tell credential misuse from legitimate traffic using metadata alone. The useful result was not a high score; it was a list of ways the experiment could fool me.
The ruble markup on AI tokens
Why the price of an AI token in Russia can include more than model inference—and what that hides about request provenance.