Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data
Fuente:
arXiv
Saved in:
| Main Authors: | Croce, Nicola, South, Tobin |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration
by: Das, Debeshee, et al.
Published: (2026)
by: Das, Debeshee, et al.
Published: (2026)
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
by: Wang, Bin, et al.
Published: (2025)
by: Wang, Bin, et al.
Published: (2025)
Private, Verifiable, and Auditable AI Systems
by: South, Tobin
Published: (2025)
by: South, Tobin
Published: (2025)
Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use
by: Zhang, Wuyang, et al.
Published: (2026)
by: Zhang, Wuyang, et al.
Published: (2026)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026)
by: Li, Ruiqi, et al.
Published: (2026)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
by: Ahmadi, Arash, et al.
Published: (2025)
by: Ahmadi, Arash, et al.
Published: (2025)
WHITE PAPER: A Brief Exploration of Data Exfiltration using GCG Suffixes
by: Valbuena, Victor
Published: (2024)
by: Valbuena, Victor
Published: (2024)
TrojanDec: Data-free Detection of Trojan Inputs in Self-supervised Learning
by: Liu, Yupei, et al.
Published: (2025)
by: Liu, Yupei, et al.
Published: (2025)
Secure Tool Manifest and Digital Signing Solution for Verifiable MCP and LLM Pipelines
by: Jamshidi, Saeid, et al.
Published: (2026)
by: Jamshidi, Saeid, et al.
Published: (2026)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
by: Felendler, Yuval, et al.
Published: (2026)
by: Felendler, Yuval, et al.
Published: (2026)
TrojanWhisper: Evaluating Pre-trained LLMs to Detect and Localize Hardware Trojans
by: Faruque, Md Omar, et al.
Published: (2024)
by: Faruque, Md Omar, et al.
Published: (2024)
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
by: Uppala, Rohith
Published: (2026)
by: Uppala, Rohith
Published: (2026)
MCP-in-SoS: Risk assessment framework for open-source MCP servers
by: Kumar, Pratyay, et al.
Published: (2026)
by: Kumar, Pratyay, et al.
Published: (2026)
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
by: Li, Zhihao, et al.
Published: (2026)
by: Li, Zhihao, et al.
Published: (2026)
MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
by: Kumar, Sonu, et al.
Published: (2025)
by: Kumar, Sonu, et al.
Published: (2025)
Evasion-Resilient Detection of DNS-over-HTTPS Data Exfiltration: A Practical Evaluation and Toolkit
by: Elaoumari, Adam
Published: (2025)
by: Elaoumari, Adam
Published: (2025)
SkillTrojan: Backdoor Attacks on Skill-Based Agent Systems
by: Feng, Yunhao, et al.
Published: (2026)
by: Feng, Yunhao, et al.
Published: (2026)
QUIC-Exfil: Exploiting QUIC's Server Preferred Address Feature to Perform Data Exfiltration Attacks
by: Grübl, Thomas, et al.
Published: (2025)
by: Grübl, Thomas, et al.
Published: (2025)
PentestMCP: A Toolkit for Agentic Penetration Testing
by: Ezetta, Zachary, et al.
Published: (2025)
by: Ezetta, Zachary, et al.
Published: (2025)
Simplified and Secure MCP Gateways for Enterprise AI Integration
by: Brett, Ivo
Published: (2025)
by: Brett, Ivo
Published: (2025)
MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models
by: Shabgahi, Soheil Zibakhsh, et al.
Published: (2025)
by: Shabgahi, Soheil Zibakhsh, et al.
Published: (2025)
Hijacking Agent Memory: Stealthy Trojan Attacks Through Conversational Interaction
by: Wang, Hongtao, et al.
Published: (2026)
by: Wang, Hongtao, et al.
Published: (2026)
Trojan's Whisper: Stealthy Manipulation of OpenClaw through Injected Bootstrapped Guidance
by: Liu, Fazhong, et al.
Published: (2026)
by: Liu, Fazhong, et al.
Published: (2026)
Auditing MCP Servers for Over-Privileged Tool Capabilities
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
TrojanGYM: A Detector-in-the-Loop LLM for Adaptive RTL Hardware Trojan Insertion
by: Sreekumar, Saideep, et al.
Published: (2026)
by: Sreekumar, Saideep, et al.
Published: (2026)
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
by: Hao, Run, et al.
Published: (2026)
by: Hao, Run, et al.
Published: (2026)
Robust Client-Server Watermarking for Split Federated Learning
by: Tang, Jiaxiong, et al.
Published: (2025)
by: Tang, Jiaxiong, et al.
Published: (2025)
Hammering the Diagnosis: Rowhammer-Induced Stealthy Trojan Attacks on ViT-Based Medical Imaging
by: Latibari, Banafsheh Saber, et al.
Published: (2025)
by: Latibari, Banafsheh Saber, et al.
Published: (2025)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
by: Narajala, Vineeth Sai, et al.
Published: (2025)
by: Narajala, Vineeth Sai, et al.
Published: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Compatibility at a Cost: Systematic Discovery and Exploitation of MCP Clause-Compliance Vulnerabilities
by: Yang, Nanzi, et al.
Published: (2026)
by: Yang, Nanzi, et al.
Published: (2026)
Governed MCP: Kernel-Level Tool Governance for AI Agents via Logit-Based Safety Primitives
by: Son, Daeyeon
Published: (2026)
by: Son, Daeyeon
Published: (2026)
Understanding Byzantine Robustness in Federated Learning with A Black-box Server
by: Zhao, Fangyuan, et al.
Published: (2024)
by: Zhao, Fangyuan, et al.
Published: (2024)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)
by: Li, Zhihao, et al.
Published: (2025)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
by: Zhang, Dongsen, et al.
Published: (2025)
by: Zhang, Dongsen, et al.
Published: (2025)
CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security
by: Rostamzadeh, Mehrdad, et al.
Published: (2026)
by: Rostamzadeh, Mehrdad, et al.
Published: (2026)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
by: Liu, Shi, et al.
Published: (2026)
by: Liu, Shi, et al.
Published: (2026)
ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control
by: Bhatt, Manish, et al.
Published: (2025)
by: Bhatt, Manish, et al.
Published: (2025)
KnowledgeSG: Privacy-Preserving Synthetic Text Generation with Knowledge Distillation from Server
by: Wang, Wenhao, et al.
Published: (2024)
by: Wang, Wenhao, et al.
Published: (2024)
Similar Items
-
Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration
by: Das, Debeshee, et al.
Published: (2026) -
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
by: Wang, Bin, et al.
Published: (2025) -
Private, Verifiable, and Auditable AI Systems
by: South, Tobin
Published: (2025) -
Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use
by: Zhang, Wuyang, et al.
Published: (2026) -
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026)