The solution i've seen is:
sleep(float(hash(request_content)) % n)
this assumes that the attacker cannot control any non-relevant part of request_content.