arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ChronosAttack:针对LLM智能体的对抗性工具调度攻击

ChronosAttack: Adversarial Tool Scheduling Attacks on LLM Agents

Arash Vashagh

arXiv 2609.27857首次发表:更新:

发表机构

University of New Brunswick(新不伦瑞克大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

ChronosAttack通过仅调整工具响应到达顺序(不修改内容)来改变LLM智能体决策,在多个模型上验证了该攻击的有效性,并指出同步与顺序一致性防御可缓解风险。

AI 中文摘要

大语言模型(LLM)智能体通常会在外部工具响应到达时立即处理它们,这使得响应时机成为决策过程的一部分。我们提出了ChronosAttack,一种仅依赖延迟的调度攻击,它改变真实工具响应到达的顺序,而不修改、添加、删除或加速这些响应。有界延迟可以改变相同证据的顺序,从而改变最终决策。我们在GPT-5.6 Sol、Gemini 3.6 Flash、DeepSeek V4 Flash和Claude Sonnet 4.6上评估了ChronosAttack。GPT-5.6 Sol和Claude在易受攻击的设置中表现出强烈的定向偏移,Gemini在相反方向上表现出较大的偏移,而DeepSeek在测试的调度下更为稳定。我们还发现,顺序智能体状态并非总是必需的,且单次调度反转即可导致较大的决策变化。同步和顺序一致性防御措施减少了攻击者对观察顺序的控制。这些结果表明,工具响应时机本身可以构成异步LLM智能体中的一个攻击面。

英文摘要

Large language model (LLM) agents often process external tool responses as they arrive, making response timing part of the decision process. We introduce ChronosAttack, a delay-only scheduling attack that changes when authentic tool responses arrive without modifying, adding, removing, or accelerating them. Bounded delays can change the order of the same evidence and alter the final decision. We evaluate ChronosAttack on GPT-5.6 Sol, Gemini 3.6 Flash, DeepSeek V4 Flash, and Claude Sonnet 4.6. GPT-5.6 Sol and Claude show strong targeted shifts in vulnerable settings, Gemini shows large shifts in the opposite direction, and DeepSeek is more stable under the tested schedules. We also find that sequential agent state is not always required and that a single scheduling inversion can cause a large decision change. Synchronization and order-consistency defenses reduce attacker control over observation order. These results show that tool-response timing can itself form an attack surface in asynchronous LLM agents.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑