FINDING · EVALUATION
Injecting uniformly sampled random delays between agent actions substantially degrades an unadapted XGBoost classifier, but a classifier retrained on delayed traces largely recovers performance across all four datasets. Under 5-second delay injection, the classifier shifts weight onto structural features (click-coordinate dispersion, structural key ratio, link-click ratio) that survive timing perturbation.
From 2026-lugoloobi-known-their-actions — Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces · §6.1, Figure 5 · 2026 · arXiv preprint
Implications
- Timing randomization is not a durable defense against adaptive adversaries: a single retraining round on delayed traces restores attribution accuracy — circumvention agent designers should assume any deployed jitter will be matched within weeks.
- Effective obfuscation requires suppressing action-structural signals (homogenizing click spatial distributions, normalizing key ratio, standardizing scroll behavior) in addition to inter-event timing jitter.
Tags
Extracted by claude-sonnet-4-6 — review before relying.