LeechHijack: Covert Computational Resource Exploitation in Intelligent Agent Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Yuanhe, Wang, Weiliu, Zhou, Zhenhong, Wang, Kun, Zhang, Jie, Sun, Li, Liu, Yang, Su, Sen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915648004685824
author Zhang, Yuanhe
Wang, Weiliu
Zhou, Zhenhong
Wang, Kun
Zhang, Jie
Sun, Li
Liu, Yang
Su, Sen
author_facet Zhang, Yuanhe
Wang, Weiliu
Zhou, Zhenhong
Wang, Kun
Zhang, Jie
Sun, Li
Liu, Yang
Su, Sen
contents Large Language Model (LLM)-based agents have demonstrated remarkable capabilities in reasoning, planning, and tool usage. The recently proposed Model Context Protocol (MCP) has emerged as a unifying framework for integrating external tools into agent systems, enabling a thriving open ecosystem of community-built functionalities. However, the openness and composability that make MCP appealing also introduce a critical yet overlooked security assumption -- implicit trust in third-party tool providers. In this work, we identify and formalize a new class of attacks that exploit this trust boundary without violating explicit permissions. We term this new attack vector implicit toxicity, where malicious behaviors occur entirely within the allowed privilege scope. We propose LeechHijack, a Latent Embedded Exploit for Computation Hijacking, in which an adversarial MCP tool covertly expropriates the agent's computational resources for unauthorized workloads. LeechHijack operates through a two-stage mechanism: an implantation stage that embeds a benign-looking backdoor in a tool, and an exploitation stage where the backdoor activates upon predefined triggers to establish a command-and-control channel. Through this channel, the attacker injects additional tasks that the agent executes as if they were part of its normal workflow, effectively parasitizing the user's compute budget. We implement LeechHijack across four major LLM families. Experiments show that LeechHijack achieves an average success rate of 77.25%, with a resource overhead of 18.62% compared to the baseline. This study highlights the urgent need for computational provenance and resource attestation mechanisms to safeguard the emerging MCP ecosystem.
format Preprint
id arxiv_https___arxiv_org_abs_2512_02321
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LeechHijack: Covert Computational Resource Exploitation in Intelligent Agent Systems
Zhang, Yuanhe
Wang, Weiliu
Zhou, Zhenhong
Wang, Kun
Zhang, Jie
Sun, Li
Liu, Yang
Su, Sen
Cryptography and Security
Computation and Language
Large Language Model (LLM)-based agents have demonstrated remarkable capabilities in reasoning, planning, and tool usage. The recently proposed Model Context Protocol (MCP) has emerged as a unifying framework for integrating external tools into agent systems, enabling a thriving open ecosystem of community-built functionalities. However, the openness and composability that make MCP appealing also introduce a critical yet overlooked security assumption -- implicit trust in third-party tool providers. In this work, we identify and formalize a new class of attacks that exploit this trust boundary without violating explicit permissions. We term this new attack vector implicit toxicity, where malicious behaviors occur entirely within the allowed privilege scope. We propose LeechHijack, a Latent Embedded Exploit for Computation Hijacking, in which an adversarial MCP tool covertly expropriates the agent's computational resources for unauthorized workloads. LeechHijack operates through a two-stage mechanism: an implantation stage that embeds a benign-looking backdoor in a tool, and an exploitation stage where the backdoor activates upon predefined triggers to establish a command-and-control channel. Through this channel, the attacker injects additional tasks that the agent executes as if they were part of its normal workflow, effectively parasitizing the user's compute budget. We implement LeechHijack across four major LLM families. Experiments show that LeechHijack achieves an average success rate of 77.25%, with a resource overhead of 18.62% compared to the baseline. This study highlights the urgent need for computational provenance and resource attestation mechanisms to safeguard the emerging MCP ecosystem.
title LeechHijack: Covert Computational Resource Exploitation in Intelligent Agent Systems
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2512.02321