"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
Fuente:
arXiv
Saved in:
| Main Authors: | Yan, Biwei, Zhang, Yue, Xu, Minghui, Wu, Hao, Zhang, Yechao, Li, Kun, Zhang, Guoming, Cheng, Xiuzhen |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Automatic Generation of a Cryptography Misuse Taxonomy Using Large Language Models
by: Zhang, Yang, et al.
Published: (2025)
by: Zhang, Yang, et al.
Published: (2025)
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
by: Huang, Yuhang, et al.
Published: (2026)
by: Huang, Yuhang, et al.
Published: (2026)
Mutation-based Evaluation of Cryptographic API Misuse Detectors
by: Ami, Amit Seal, et al.
Published: (2021)
by: Ami, Amit Seal, et al.
Published: (2021)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)
by: Li, Zhihao, et al.
Published: (2025)
On Protecting the Data Privacy of Large Language Models (LLMs): A Survey
by: Yan, Biwei, et al.
Published: (2024)
by: Yan, Biwei, et al.
Published: (2024)
Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMs
by: Xia, Yifan, et al.
Published: (2024)
by: Xia, Yifan, et al.
Published: (2024)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
by: Song, Hao, et al.
Published: (2025)
by: Song, Hao, et al.
Published: (2025)
Beyond Static Tools: Evaluating Large Language Models for Cryptographic Misuse Detection
by: Masood, Zohaib, et al.
Published: (2024)
by: Masood, Zohaib, et al.
Published: (2024)
Evaluating Cryptographic API Misuse Detectors for Go
by: Andersson, Vivi, et al.
Published: (2026)
by: Andersson, Vivi, et al.
Published: (2026)
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
by: Li, Zhihao, et al.
Published: (2026)
by: Li, Zhihao, et al.
Published: (2026)
Dataset Ownership in the Era of Large Language Models
by: Li, Kun, et al.
Published: (2025)
by: Li, Kun, et al.
Published: (2025)
Low Rank Comes with Low Security: Gradient Assembly Poisoning Attacks against Distributed LoRA-based LLM Systems
by: Dong, Yueyan, et al.
Published: (2026)
by: Dong, Yueyan, et al.
Published: (2026)
What You Code Is What We Prove: Translating BLE App Logic into Formal Models with LLMs for Vulnerability Detection
by: Yan, Biwei, et al.
Published: (2025)
by: Yan, Biwei, et al.
Published: (2025)
ChatGPT's Potential in Cryptography Misuse Detection: A Comparative Analysis with Static Analysis Tools
by: Firouzi, Ehsan, et al.
Published: (2024)
by: Firouzi, Ehsan, et al.
Published: (2024)
When LLMs Copy to Think: Uncovering Copy-Guided Attacks in Reasoning LLMs
by: Li, Yue, et al.
Published: (2025)
by: Li, Yue, et al.
Published: (2025)
Securing the Model Context Protocol (MCP): Risks, Controls, and Governance
by: Errico, Herman, et al.
Published: (2025)
by: Errico, Herman, et al.
Published: (2025)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
by: Zhang, Dongsen, et al.
Published: (2025)
by: Zhang, Dongsen, et al.
Published: (2025)
Understanding Mobile App Reviews to Guide Misuse Audits
by: Garg, Vaibhav, et al.
Published: (2023)
by: Garg, Vaibhav, et al.
Published: (2023)
Almost-Free Queue Jumping for Prior Inputs in Private Neural Inference
by: Zhang, Qiao, et al.
Published: (2026)
by: Zhang, Qiao, et al.
Published: (2026)
A Practical Trigger-Free Backdoor Attack on Neural Networks
by: Wang, Jiahao, et al.
Published: (2024)
by: Wang, Jiahao, et al.
Published: (2024)
Benchmarking Misuse Mitigation Against Covert Adversaries
by: Brown, Davis, et al.
Published: (2025)
by: Brown, Davis, et al.
Published: (2025)
Everything You Wanted to Know About LLM-based Vulnerability Detection But Were Afraid to Ask
by: Li, Yue, et al.
Published: (2025)
by: Li, Yue, et al.
Published: (2025)
VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers
by: Sun, Pengyu, et al.
Published: (2026)
by: Sun, Pengyu, et al.
Published: (2026)
The Midas Touch: Triggering the Capability of LLMs for RM-API Misuse Detection
by: Yang, Yi, et al.
Published: (2024)
by: Yang, Yi, et al.
Published: (2024)
Confusion is the Final Barrier: Rethinking Jailbreak Evaluation and Investigating the Real Misuse Threat of LLMs
by: Yan, Yu, et al.
Published: (2025)
by: Yan, Yu, et al.
Published: (2025)
Automated Side-Channel Analysis of Cryptographic Protocol Implementations
by: Nasrabadi, Faezeh, et al.
Published: (2025)
by: Nasrabadi, Faezeh, et al.
Published: (2025)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
From base cases to backdoors: An Empirical Study of Unnatural Crypto-API Misuse
by: Olaiya, Victor, et al.
Published: (2025)
by: Olaiya, Victor, et al.
Published: (2025)
Safeguarding LLMs Against Misuse and AI-Driven Malware Using Steganographic Canaries
by: Raz, Md, et al.
Published: (2026)
by: Raz, Md, et al.
Published: (2026)
SAGE: Signal-Amplified Guided Embeddings for LLM-based Vulnerability Detection
by: Shan, Zhengyang, et al.
Published: (2026)
by: Shan, Zhengyang, et al.
Published: (2026)
LIFT: Automating Symbolic Execution Optimization with Large Language Models for AI Networks
by: Wang, Ruoxi, et al.
Published: (2025)
by: Wang, Ruoxi, et al.
Published: (2025)
I'm Spartacus, No, I'm Spartacus: Measuring and Understanding LLM Identity Confusion
by: Li, Kun, et al.
Published: (2024)
by: Li, Kun, et al.
Published: (2024)
LibScan: Smart Contract Library Misuse Detection with Iterative Feedback and Static Verification
by: Wang, Yishun, et al.
Published: (2026)
by: Wang, Yishun, et al.
Published: (2026)
VGMShield: Mitigating Misuse of Video Generative Models
by: Pang, Yan, et al.
Published: (2024)
by: Pang, Yan, et al.
Published: (2024)
AgentDID: Trustless Identity Authentication for AI Agents
by: Xu, Minghui, et al.
Published: (2026)
by: Xu, Minghui, et al.
Published: (2026)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
by: Narajala, Vineeth Sai, et al.
Published: (2025)
by: Narajala, Vineeth Sai, et al.
Published: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Adversaries Can Misuse Combinations of Safe Models
by: Jones, Erik, et al.
Published: (2024)
by: Jones, Erik, et al.
Published: (2024)
SMCP: Secure Model Context Protocol
by: Hou, Xinyi, et al.
Published: (2026)
by: Hou, Xinyi, et al.
Published: (2026)
Classifying Implementations of Cryptographic Primitives and Protocols that Use Post-Quantum Algorithms
by: Mallick, Tushin, et al.
Published: (2025)
by: Mallick, Tushin, et al.
Published: (2025)
Similar Items
-
Automatic Generation of a Cryptography Misuse Taxonomy Using Large Language Models
by: Zhang, Yang, et al.
Published: (2025) -
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
by: Huang, Yuhang, et al.
Published: (2026) -
Mutation-based Evaluation of Cryptographic API Misuse Detectors
by: Ami, Amit Seal, et al.
Published: (2021) -
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025) -
On Protecting the Data Privacy of Large Language Models (LLMs): A Survey
by: Yan, Biwei, et al.
Published: (2024)