MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Fuente:
arXiv
Saved in:
| Main Authors: | Wang, Zhiqiang, Gao, Yichao, Wang, Yanting, Liu, Suyuan, Sun, Haifeng, Cheng, Haoran, Shi, Guanquan, Du, Haohua, Li, Xiangyang |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
MindGuard: Intrinsic Decision Inspection for Securing LLM Agents Against Metadata Poisoning
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026)
by: Li, Ruiqi, et al.
Published: (2026)
SoK: Trust-Authorization Mismatch in LLM Agent Interactions
by: Shi, Guanquan, et al.
Published: (2025)
by: Shi, Guanquan, et al.
Published: (2025)
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
by: Hao, Run, et al.
Published: (2026)
by: Hao, Run, et al.
Published: (2026)
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
by: Zhou, Huijun, et al.
Published: (2026)
by: Zhou, Huijun, et al.
Published: (2026)
IntentMiner: Intent Inversion Attack via Tool Call Analysis in the Model Context Protocol
by: Yao, Yunhao, et al.
Published: (2025)
by: Yao, Yunhao, et al.
Published: (2025)
Auditing MCP Servers for Over-Privileged Tool Capabilities
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
by: Zhao, Weibo, et al.
Published: (2025)
by: Zhao, Weibo, et al.
Published: (2025)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
by: Liu, Shi, et al.
Published: (2026)
by: Liu, Shi, et al.
Published: (2026)
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
by: Wang, Bin, et al.
Published: (2025)
by: Wang, Bin, et al.
Published: (2025)
SECNEURON: Reliable and Flexible Abuse Control in Local LLMs via Hybrid Neuron Encryption
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data
by: Croce, Nicola, et al.
Published: (2025)
by: Croce, Nicola, et al.
Published: (2025)
Can LLM Infer Risk Information From MCP Server System Logs?
by: Fu, Jiayi, et al.
Published: (2025)
by: Fu, Jiayi, et al.
Published: (2025)
VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers
by: Sun, Pengyu, et al.
Published: (2026)
by: Sun, Pengyu, et al.
Published: (2026)
ExtendAttack: Attacking Servers of LRMs via Extending Reasoning
by: Zhu, Zhenhao, et al.
Published: (2025)
by: Zhu, Zhenhao, et al.
Published: (2025)
Activation-Guided Local Editing for Jailbreaking Attacks
by: Wang, Jiecong, et al.
Published: (2025)
by: Wang, Jiecong, et al.
Published: (2025)
Benchmarking Poisoning Attacks against Retrieval-Augmented Generation
by: Zhang, Baolei, et al.
Published: (2025)
by: Zhang, Baolei, et al.
Published: (2025)
Mitigating Data Poisoning Attacks to Local Differential Privacy
by: Li, Xiaolin, et al.
Published: (2025)
by: Li, Xiaolin, et al.
Published: (2025)
Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs
by: Wang, Chao, et al.
Published: (2026)
by: Wang, Chao, et al.
Published: (2026)
Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
by: Zhao, Shuli, et al.
Published: (2025)
by: Zhao, Shuli, et al.
Published: (2025)
PoisonCatcher: Revealing and Identifying LDP Poisoning Attacks in IIoT
by: Shuai, Lisha, et al.
Published: (2024)
by: Shuai, Lisha, et al.
Published: (2024)
Knowledge Poisoning Attacks on Medical Multi-Modal Retrieval-Augmented Generation
by: Yang, Peiru, et al.
Published: (2026)
by: Yang, Peiru, et al.
Published: (2026)
RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement
by: Wang, Ziye, et al.
Published: (2026)
by: Wang, Ziye, et al.
Published: (2026)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026)
by: Huang, Yiheng, et al.
Published: (2026)
Tricking Retrievers with Influential Tokens: An Efficient Black-Box Corpus Poisoning Attack
by: Wang, Cheng, et al.
Published: (2025)
by: Wang, Cheng, et al.
Published: (2025)
Provable Watermarking for Data Poisoning Attacks
by: Zhu, Yifan, et al.
Published: (2025)
by: Zhu, Yifan, et al.
Published: (2025)
Denial-of-Service Poisoning Attacks against Large Language Models
by: Gao, Kuofeng, et al.
Published: (2024)
by: Gao, Kuofeng, et al.
Published: (2024)
Sharpness-Aware Data Poisoning Attack
by: He, Pengfei, et al.
Published: (2023)
by: He, Pengfei, et al.
Published: (2023)
Poisoning Attacks and Defenses in Recommender Systems: A Survey
by: Wang, Zongwei, et al.
Published: (2024)
by: Wang, Zongwei, et al.
Published: (2024)
Poisoned-MRAG: Knowledge Poisoning Attacks to Multimodal Retrieval Augmented Generation
by: Liu, Yinuo, et al.
Published: (2025)
by: Liu, Yinuo, et al.
Published: (2025)
Defense against Poisoning Attacks under Shuffle-DP
by: Wang, Siyi, et al.
Published: (2026)
by: Wang, Siyi, et al.
Published: (2026)
SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs
by: Xia, Hongfei, et al.
Published: (2025)
by: Xia, Hongfei, et al.
Published: (2025)
Comprehensive Evaluation of Cloaking Backdoor Attacks on Object Detector in Real-World
by: Ma, Hua, et al.
Published: (2025)
by: Ma, Hua, et al.
Published: (2025)
Spa-VLM: Stealthy Poisoning Attacks on RAG-based VLM
by: Yu, Lei, et al.
Published: (2025)
by: Yu, Lei, et al.
Published: (2025)
IndirectAD: Practical Data Poisoning Attacks against Recommender Systems for Item Promotion
by: Wang, Zihao, et al.
Published: (2025)
by: Wang, Zihao, et al.
Published: (2025)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
by: Ahmadi, Arash, et al.
Published: (2025)
by: Ahmadi, Arash, et al.
Published: (2025)
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
by: Tan, Zhuoran, et al.
Published: (2026)
by: Tan, Zhuoran, et al.
Published: (2026)
Data Poisoning Attacks in Intelligent Transportation Systems: A Survey
by: Wang, Feilong, et al.
Published: (2024)
by: Wang, Feilong, et al.
Published: (2024)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
by: Zhang, Dongsen, et al.
Published: (2025)
by: Zhang, Dongsen, et al.
Published: (2025)
PRSA: Prompt Stealing Attacks against Real-World Prompt Services
by: Yang, Yong, et al.
Published: (2024)
by: Yang, Yong, et al.
Published: (2024)
Similar Items
-
MindGuard: Intrinsic Decision Inspection for Securing LLM Agents Against Metadata Poisoning
by: Wang, Zhiqiang, et al.
Published: (2025) -
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026) -
SoK: Trust-Authorization Mismatch in LLM Agent Interactions
by: Shi, Guanquan, et al.
Published: (2025) -
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
by: Hao, Run, et al.
Published: (2026) -
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
by: Zhou, Huijun, et al.
Published: (2026)