🔒 Lesson 9.3: Securing and Optimizing Your Chatbot

🔒 Lesson 9.3: Securing and Optimizing Your Chatbot

Module 9: Tools, Plugins, and Deployment Course: Build Your Own AI Chat System (Like ChatGPT or DeepSeek) Using Free Open-Source Tools


🎯 Lesson Objective:

By the end of this lesson, learners will know how to protect their AI chatbot from abuse, ensure smooth performance, and optimize for reliability, especially when deployed to public or team environments.


🔐 Why Security & Optimization Matter

When your chatbot is:

  • Publicly accessible
  • Dealing with private files or data
  • Used by clients or teammates

…it becomes a potential target for spam, misuse, or crashes. You must secure and optimize it just like any serious web application.


🧱 Key Areas of Security & Optimization

Area What to Do Why It Matters
Authentication Add login or access codes Limit usage to intended users
Rate Limiting Prevent too many requests per user Avoid overload or abuse
Input Sanitization Clean user inputs Prevent prompts from breaking the bot
Logging & Monitoring Track usage, errors, inputs Troubleshoot and improve
Memory Management Limit tokens or chunks Prevent crashes from long queries
Caching Responses Save common answers Speed up repeated questions

🔐 1. Add Basic Authentication

Streamlit Example:

import streamlit as st

password = st.text_input("Enter password", type="password")
if password != "openai123":
    st.stop()

Gradio Example:

import gradio as gr

def auth(username, password):
    return username == "admin" and password == "pass"

gr.ChatInterface(fn=chat_function).launch(auth=auth)

📉 2. Add Rate Limits

Manually (simple version):

import time

user_time = {}

def check_rate(user_id):
    now = time.time()
    if user_id in user_time and now - user_time[user_id] < 5:
        return False  # too fast
    user_time[user_id] = now
    return True

For production apps: use Redis or FastAPI-limiter.


🧼 3. Sanitize User Input

Before sending the user prompt to the LLM:

  • Remove dangerous characters
  • Limit length
  • Strip code or HTML tags if unnecessary
def clean_input(text):
    text = text.strip()
    if len(text) > 1000:
        text = text[:1000] + " [TRUNCATED]"
    return text

📊 4. Add Logging & Monitoring

Log each question and response:

with open("logs.txt", "a") as f:
    f.write(f"Q: {user_input}nA: {response}nn")

Advanced: Use Langsmith or OpenTelemetry for tracing.


🧠 5. Limit Memory or Context Length

If using LangChain memory, don’t overload:

from langchain.memory import ConversationBufferMemory

memory = ConversationBufferMemory(memory_key="chat_history", k=3)  # keep last 3 turns

⚡ 6. Cache Repeated Responses

Avoid regenerating responses for common queries:

from functools import lru_cache

@lru_cache(maxsize=50)
def ask_bot_cached(query):
    return qa_chain.run(query)

Or use tools like LangChain’s InMemoryCache, Redis, or SQLite.


🧪 Try It Yourself Activity

Task: Add security and performance layers to your chatbot:

  1. Ask for a password at login
  2. Stop a user from submitting more than once every 5 seconds
  3. Log all user inputs and bot outputs to a file
  4. Limit input to 500 characters
  5. Cache and reuse responses to repeated questions

Challenge: Add a way to detect and reject harmful prompts like “How to make a bomb” or “Write malicious code.”


💡 Tips & Best Practices

  • Use Gradio Auth, JWT tokens, or OAuth for secure deployments
  • Periodically audit logs for strange behavior
  • Clean up temporary files or embeddings from old sessions
  • Use try/except to catch LLM errors gracefully
  • If using third-party APIs (like Google Sheets), protect API keys!

🧠 Recap:

You’ve now learned how to:

  • Secure your chatbot using passwords and input limits
  • Monitor and optimize performance with caching and memory control
  • Build a responsible and resilient assistant ready for real-world use

69