logo

Time-of-Check Time-of-Use Attacks Against LLMs

ID: 8ffda92a-4cb3-5d61-92fc-93998c6b4e8f

STIX ID: report--8ffda92a-4cb3-5d61-92fc-93998c6b4e8f

Feed Name: Schneier on Security

Threat Score
20/100

Date Published: 2025-09-18

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This post summarizes research that identifies and evaluates Time-of-Check to Time-of-Use (TOCTOU) vulnerabilities in LLM-enabled agents, introducing TOCTOU-Bench (66 realistic user tasks) to measure susceptibility. The study adapts detection and mitigation techniques—prompt rewriting, state integrity monitoring, and tool-fusing—and reports up to 25% automated detection accuracy, a 3% reduction in vulnerable plan generation, a 95% reduction in the attack window, and a decrease in executed-trajectory TOCTOU vulnerabilities from 12% to 8% when combining defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.