NaturalSloth: Revisiting Denial-of-Service Attacks on Large Language Models
Yiming Chen, Zexin Li, Xianghu Yue, Robby T. Tan, Haizhou Li
Abstract
LLM serving is limited by provider-side resources: longer generations consume more GPU time, increase latency, and reduce throughput in multi-tenant systems. This creates a denial-of-service (DoS) risk, where attackers degrade service by inducing excessive generation. Prior work on LLM DoS primarily relies on adversarial perturbations that delay end-of-sequence termination. We show perturbations are often unnecessary: natural, benign-looking instructions that specify impractical and meaningless tasks can already trigger excessive generation. To study this overlooked vulnerability, we introduce , an adversarial dataset of natural, instruction-based DoS prompts. Starting from a human-curated seed set spanning diverse attack categories, we design a multi-agent synthesis framework to scale the dataset while preserving malicious intent and increasing semantic diversity. Experiments across a wide range of proprietary and open-source LLMs show that NaturalSloth consistently induces excessive generation, with attack effectiveness further amplified when combined with jailbreak techniques. Our analysis also reveals significant limitations of existing defenses, highlighting the need for dedicated protections against natural DoS attacks.- Anthology ID:
- 2026.acl-long.901
- Volume:
- Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)
- Month:
- July
- Year:
- 2026
- Address:
- San Diego, California, United States
- Editors:
- Maria Liakata, Viviane P. Moreira, Jiajun Zhang, David Jurgens
- Venue:
- ACL
- SIG:
- Publisher:
- Association for Computational Linguistics
- Note:
- Pages:
- 19685–19702
- Language:
- URL:
- https://preview.aclanthology.org/ingest-acl/2026.acl-long.901/
- DOI:
- Cite (ACL):
- Yiming Chen, Zexin Li, Xianghu Yue, Robby T. Tan, and Haizhou Li. 2026. NaturalSloth: Revisiting Denial-of-Service Attacks on Large Language Models. In Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pages 19685–19702, San Diego, California, United States. Association for Computational Linguistics.
- Cite (Informal):
- NaturalSloth: Revisiting Denial-of-Service Attacks on Large Language Models (Chen et al., ACL 2026)
- PDF:
- https://preview.aclanthology.org/ingest-acl/2026.acl-long.901.pdf