AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhan, Zhonghao, Sadi, Amir Al, Li, Krinos, Haddadi, Hamed
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917041278025728
author Zhan, Zhonghao
Sadi, Amir Al
Li, Krinos
Haddadi, Hamed
author_facet Zhan, Zhonghao
Sadi, Amir Al
Li, Krinos
Haddadi, Hamed
contents In this work, we study security of Model Context Protocol (MCP) agent toolchains and their applications in smart homes. We introduce AegisMCP, a protocol-level intrusion detector. Our contributions are: (i) a minimal attack suite spanning instruction-driven escalation, chain-of-tool exfiltration, malicious MCP server registration, and persistence; (ii) NEBULA-Schema (Network-Edge Behavioral Learning for Untrusted LLM Agents), a reusable protocol-level instrumentation that represents MCP activity as a streaming heterogeneous temporal graph over agents, MCP servers, tools, devices, remotes, and sessions; and (iii) a CPU-only streaming detector that fuses novelty, session-DAG structure, and attribute cues for near-real-time edge inference, with optional fusion of local prompt-guardrail signals. On an emulated smart-home testbed spanning multiple MCP stacks and a physical bench, AegisMCP achieves sub-second per-window model inference and end-to-end alerting. The latency of AegisMCP is consistently sub-second on Intel N150-class edge hardware, while outperforming traffic-only and sequence baselines; ablations confirm the importance of DAG and install/permission signals. We release code, schemas, and generators for reproducible evaluation.
format Preprint
id arxiv_https___arxiv_org_abs_2510_19462
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices
Zhan, Zhonghao
Sadi, Amir Al
Li, Krinos
Haddadi, Hamed
Cryptography and Security
In this work, we study security of Model Context Protocol (MCP) agent toolchains and their applications in smart homes. We introduce AegisMCP, a protocol-level intrusion detector. Our contributions are: (i) a minimal attack suite spanning instruction-driven escalation, chain-of-tool exfiltration, malicious MCP server registration, and persistence; (ii) NEBULA-Schema (Network-Edge Behavioral Learning for Untrusted LLM Agents), a reusable protocol-level instrumentation that represents MCP activity as a streaming heterogeneous temporal graph over agents, MCP servers, tools, devices, remotes, and sessions; and (iii) a CPU-only streaming detector that fuses novelty, session-DAG structure, and attribute cues for near-real-time edge inference, with optional fusion of local prompt-guardrail signals. On an emulated smart-home testbed spanning multiple MCP stacks and a physical bench, AegisMCP achieves sub-second per-window model inference and end-to-end alerting. The latency of AegisMCP is consistently sub-second on Intel N150-class edge hardware, while outperforming traffic-only and sequence baselines; ablations confirm the importance of DAG and install/permission signals. We release code, schemas, and generators for reproducible evaluation.
title AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices
topic Cryptography and Security
url https://arxiv.org/abs/2510.19462