TEMPO An Injection-Independent Check–Use Race Condition in Tool-Augmented LLM Agents
Abstract
Tool-augmented large language model agents are typically secured via a check- then-use paradigm: agents verify a shared entity (recipient address, file contents, inbox event) before executing downstream actions. We show that the inherent la- tency between check and use creates an exploitable race window: an adversary that mutates the underlying shared state within this window causes the agent to act on a value it never verified. We formalize this vulnerability class as TEMPO, and show it is mechanistically orthogonal to prompt injection: while injection ma- nipulates the content/semantic layer, TEMPO exploits the state/temporal layer. A content-robust system prompt that reduces prompt injection success from 91.7% to 12.5% leaves TEMPO attack success unchanged at 100%. Across eight vic- tim models, two adversary types, and three race primitives, TEMPO achieves 100% attack success against reconnaissance-equipped attackers. The vulnerability transfers seamlessly to a disjoint payment approval workflow and reproduces on a production-grade LangGraph+SQLite stack with an out-of-process adversary. Benchmarking standard defense primitives alongside their latency costs reveals highly non-portable guard coverage: the same version check blocks 98.7% of attacks on one victim but only 7.1% on another. Finally, an adaptive re-arming at- tacker is strictly dominated by the simpler open-loop baseline in all configurations where the open-loop attack succeeds.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.