Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
Fuente:
arXiv
Guardado en:
| Autores principales: | Li, Zhihao, Ma, Boyang, Dai, Xuelong, Xu, Minghui, Zhang, Yue, Yan, Biwei, Li, Kun |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
por: Huang, Yuhang, et al.
Publicado: (2026)
por: Huang, Yuhang, et al.
Publicado: (2026)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
por: Li, Zhihao, et al.
Publicado: (2025)
por: Li, Zhihao, et al.
Publicado: (2025)
"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
por: Yan, Biwei, et al.
Publicado: (2025)
por: Yan, Biwei, et al.
Publicado: (2025)
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
por: Uppala, Rohith
Publicado: (2026)
por: Uppala, Rohith
Publicado: (2026)
Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
por: Shan, Zhengyang, et al.
Publicado: (2026)
por: Shan, Zhengyang, et al.
Publicado: (2026)
On Protecting the Data Privacy of Large Language Models (LLMs): A Survey
por: Yan, Biwei, et al.
Publicado: (2024)
por: Yan, Biwei, et al.
Publicado: (2024)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
por: Li, Ruiqi, et al.
Publicado: (2026)
por: Li, Ruiqi, et al.
Publicado: (2026)
Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
por: Huang, Yuhang, et al.
Publicado: (2025)
por: Huang, Yuhang, et al.
Publicado: (2025)
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
por: Hao, Run, et al.
Publicado: (2026)
por: Hao, Run, et al.
Publicado: (2026)
If You Don't Understand It, Don't Use It: Eliminating Trojans with Filters Between Layers
por: Hernandez, Adriano
Publicado: (2024)
por: Hernandez, Adriano
Publicado: (2024)
I'm Spartacus, No, I'm Spartacus: Measuring and Understanding LLM Identity Confusion
por: Li, Kun, et al.
Publicado: (2024)
por: Li, Kun, et al.
Publicado: (2024)
When Skills Lie: Hidden-Comment Injection in LLM Agents
por: Wang, Qianli, et al.
Publicado: (2026)
por: Wang, Qianli, et al.
Publicado: (2026)
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
por: Ma, Boyang, et al.
Publicado: (2026)
por: Ma, Boyang, et al.
Publicado: (2026)
AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices
por: Zhan, Zhonghao, et al.
Publicado: (2025)
por: Zhan, Zhonghao, et al.
Publicado: (2025)
Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models
por: Yu, Zhiyuan, et al.
Publicado: (2024)
por: Yu, Zhiyuan, et al.
Publicado: (2024)
Data Reconstruction: When You See It and When You Don't
por: Cohen, Edith, et al.
Publicado: (2024)
por: Cohen, Edith, et al.
Publicado: (2024)
Don't Forget Too Much: Towards Machine Unlearning on Feature Level
por: Xu, Heng, et al.
Publicado: (2024)
por: Xu, Heng, et al.
Publicado: (2024)
MIRAGE: Misleading Retrieval-Augmented Generation via Black-box and Query-agnostic Poisoning Attacks
por: Chen, Tailun, et al.
Publicado: (2025)
por: Chen, Tailun, et al.
Publicado: (2025)
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
por: Tan, Zhuoran, et al.
Publicado: (2026)
por: Tan, Zhuoran, et al.
Publicado: (2026)
Dataset Ownership in the Era of Large Language Models
por: Li, Kun, et al.
Publicado: (2025)
por: Li, Kun, et al.
Publicado: (2025)
Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security
por: Albrecht, Jannik, et al.
Publicado: (2024)
por: Albrecht, Jannik, et al.
Publicado: (2024)
What You Code Is What We Prove: Translating BLE App Logic into Formal Models with LLMs for Vulnerability Detection
por: Yan, Biwei, et al.
Publicado: (2025)
por: Yan, Biwei, et al.
Publicado: (2025)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
por: Pan, Shidong, et al.
Publicado: (2024)
por: Pan, Shidong, et al.
Publicado: (2024)
Auditing MCP Servers for Over-Privileged Tool Capabilities
por: Huang, Charoes, et al.
Publicado: (2026)
por: Huang, Charoes, et al.
Publicado: (2026)
Don't Hash Me Like That: Exposing and Mitigating Hash-Induced Unfairness in Local Differential Privacy
por: Balioglu, Berkay Kemal, et al.
Publicado: (2025)
por: Balioglu, Berkay Kemal, et al.
Publicado: (2025)
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
por: Wang, Zhiqiang, et al.
Publicado: (2025)
por: Wang, Zhiqiang, et al.
Publicado: (2025)
AutoIoT: Automated IoT Platform Using Large Language Models
por: Cheng, Ye, et al.
Publicado: (2024)
por: Cheng, Ye, et al.
Publicado: (2024)
Don't Click That: Teaching Web Agents to Resist Deceptive Interfaces
por: Zhang, Yilin, et al.
Publicado: (2026)
por: Zhang, Yilin, et al.
Publicado: (2026)
"Explain, Don't Just Warn!" -- A Real-Time Framework for Generating Phishing Warnings with Contextual Cues
por: Roy, Sayak Saha, et al.
Publicado: (2025)
por: Roy, Sayak Saha, et al.
Publicado: (2025)
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
por: Zhou, Huijun, et al.
Publicado: (2026)
por: Zhou, Huijun, et al.
Publicado: (2026)
Don't Trust Your Upstream: Exploiting LLM Multi-Agent System via Topology-Guided Adversarial Propagation
por: Liang, Ruichao, et al.
Publicado: (2025)
por: Liang, Ruichao, et al.
Publicado: (2025)
Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills
por: He, Wenhui, et al.
Publicado: (2026)
por: He, Wenhui, et al.
Publicado: (2026)
Overthinking Loops in Agents: A Structural Risk via MCP Tools
por: Lee, Yohan, et al.
Publicado: (2026)
por: Lee, Yohan, et al.
Publicado: (2026)
I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object Detectors
por: Lin, Zijin, et al.
Publicado: (2024)
por: Lin, Zijin, et al.
Publicado: (2024)
Don't Let MEV Slip: The Costs of Swapping on the Uniswap Protocol
por: Adams, Austin, et al.
Publicado: (2023)
por: Adams, Austin, et al.
Publicado: (2023)
Secure Tool Manifest and Digital Signing Solution for Verifiable MCP and LLM Pipelines
por: Jamshidi, Saeid, et al.
Publicado: (2026)
por: Jamshidi, Saeid, et al.
Publicado: (2026)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
por: Felendler, Yuval, et al.
Publicado: (2026)
por: Felendler, Yuval, et al.
Publicado: (2026)
Explainable Machine Learning for Phishing Detection on Heterogeneous Datasets with MCP-Enabled Deployment
por: Dora, Nikhil Kumar, et al.
Publicado: (2026)
por: Dora, Nikhil Kumar, et al.
Publicado: (2026)
Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
por: Zhao, Shuli, et al.
Publicado: (2025)
por: Zhao, Shuli, et al.
Publicado: (2025)
LIFT: Automating Symbolic Execution Optimization with Large Language Models for AI Networks
por: Wang, Ruoxi, et al.
Publicado: (2025)
por: Wang, Ruoxi, et al.
Publicado: (2025)
Ejemplares similares
-
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
por: Huang, Yuhang, et al.
Publicado: (2026) -
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
por: Li, Zhihao, et al.
Publicado: (2025) -
"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
por: Yan, Biwei, et al.
Publicado: (2025) -
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
por: Uppala, Rohith
Publicado: (2026) -
Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
por: Shan, Zhengyang, et al.
Publicado: (2026)