Timing Attacks on Delegation Authorization via Benign Content in LLM Agent Systems
Abstract
In LLM agent systems, a delegation can be revoked while delegated work is still in progress, and downstream consumers may continue to rely on cached authorization state until it refreshes. A worker can therefore produce a task-aligned result after its delegation becomes invalid, creating a timing gap in which stale authorization can turn task-aligned execution into an unauthorized downstream effect. This work examines whether an attacker whose control is limited to external content can move execution into this gap without modifying trusted instructions or authorization state. We introduce Orphaned-Delegation Completion (ODC), a timing attack in which a benign, task-relevant checklist induces additional verification work and shifts worker completion past revocation. ODC is governed by two timing conditions: orphan production after revocation (Gate 1) and result adoption while the consumer's cached authorization state still marks the delegation as valid (Gate 2). Their overlap defines a bounded attack window, so increasing workload can first enable and then suppress attack success. On LangGraph with DeepSeek-V4-Flash, ASR rises from 0.3% at N=0 to 94.6% at N=8, then falls to 1.4% at N=12. The same mechanism appears across relay models, transfers to AutoGen and CrewAI, and persists across downstream effect types. Content controls show that the timing shift follows induced verification work rather than document length alone, while more frequent authorization refresh reduces cached-valid adoption while leaving orphan production largely unchanged. These results show that benign, task-relevant content can make execution time security-relevant under revocable delegation and motivate revalidating authority when downstream effects are committed.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.