University of New Brunswick Researcher Details ChronosAttack Scheduling Vulnerability in LLM Agents
Bot Mutiny |
A new study shows that simply delaying authentic tool responses can force GPT-5.6 Sol and Claude Sonnet 4.6 to change their final decisions without modifying any data.
Arash Vashagh at the University of New Brunswick has introduced ChronosAttack, a delay-only scheduling attack on large language model (LLM) agents that works through the timing of data delivery. The research, first reported by arxiv.org on August 20, 2026, introduces ChronosAttack. This method changes an agent's final decision by introducing bounded delays to authentic tool responses. The attack doesn't modify, add, or remove any information. It doesn't use malicious prompt injections or poisoned data. Instead, it exploits the fact that asynchronous LLM agents often process tool responses in the order they arrive. By changing the arrival times, an attacker changes the serialization of evidence, which in the paper's tests changed the model's final decision. ## Testing Across Four Models
Vashagh evaluated the attack against four models: OpenAI GPT-5.6 Sol, Google Gemini 3.6 Flash, DeepSeek V4 Flash, and Anthropic Claude Sonnet 4.6. The study used two controlled decision scenarios where each agent received three authentic tool observations to make a final choice. The study used two fixed decision scenarios. GPT-5.6 Sol and Claude Sonnet 4.6 showed strong targeted shifts in vulnerable settings, though Claude was resistant in one of the two scenarios. Gemini 3.6 Flash also showed large shifts, but in the opposite direction from the intended target. DeepSeek V4 Flash was more stable under the tested schedules. ## The Delay-Only Threat Model
The threat model for ChronosAttack is strictly limited. The attacker can only introduce non-negative delays, represented as δ, to an observation's natural arrival time. The attacker cannot make a response arrive earlier than it naturally would, and they cannot exceed a maximum allowed delay, represented as ϵ. The paper reports that the timing of authentic tool responses can be security-relevant even when their contents are unchanged. If an attacker can control the network latency or scheduling of a tool's response, they can control the order of the agent's interaction history. ## Sequential State and Inversion Effects
The research distinguishes between stateful and stateless agents. Stateful agents process observations sequentially and carry the interaction history forward between arrivals. Stateless agents receive all observations in a single call, where only the textual order is changed. Vashagh found that while a sequential agent state can strengthen the effectiveness of the attack, it isn't always required. In some cases, a single scheduling inversion, flipping the order of two pieces of evidence, was enough to cause a large change in the decision. Interestingly, the study noted that stronger scheduling perturbations don't always lead to stronger attacks. The effect was highly dependent on the model and the task. ## Proposed Defenses
The paper evaluates two defenses against these timing-based attacks: synchronization and order-consistency. Synchronization defenses force the agent to wait for all expected tool outputs before processing them, while order-consistency evaluates all six possible orderings of the three responses and accepts a decision only if at least four agree, otherwise abstaining. These measures reduce the attacker's ability to manipulate the observation order. The authors note the tests covered two controlled scenarios and not end-to-end production systems.
References
(2026). ChronosAttack: Adversarial Tool Scheduling Attacks on LLM Agents. arxiv.org. https://arxiv.org/abs/2609.27857