Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | Huang, Yuhang, Ma, Boyang, Yan, Biwei, Dai, Xuelong, Zhang, Yechao, Xu, Minghui, Xu, Kaidi, Zhang, Yue |
|---|---|
| Format: | Preprint |
| Publié: |
2026
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Documents similaires
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
par: Li, Zhihao, et autres
Publié: (2026)
par: Li, Zhihao, et autres
Publié: (2026)
I'm Spartacus, No, I'm Spartacus: Measuring and Understanding LLM Identity Confusion
par: Li, Kun, et autres
Publié: (2024)
par: Li, Kun, et autres
Publié: (2024)
"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
par: Yan, Biwei, et autres
Publié: (2025)
par: Yan, Biwei, et autres
Publié: (2025)
Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
par: Huang, Yuhang, et autres
Publié: (2025)
par: Huang, Yuhang, et autres
Publié: (2025)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
par: Li, Zhihao, et autres
Publié: (2025)
par: Li, Zhihao, et autres
Publié: (2025)
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
par: Ma, Boyang, et autres
Publié: (2026)
par: Ma, Boyang, et autres
Publié: (2026)
When Skills Lie: Hidden-Comment Injection in LLM Agents
par: Wang, Qianli, et autres
Publié: (2026)
par: Wang, Qianli, et autres
Publié: (2026)
AgentDID: Trustless Identity Authentication for AI Agents
par: Xu, Minghui, et autres
Publié: (2026)
par: Xu, Minghui, et autres
Publié: (2026)
LIFT: Automating Symbolic Execution Optimization with Large Language Models for AI Networks
par: Wang, Ruoxi, et autres
Publié: (2025)
par: Wang, Ruoxi, et autres
Publié: (2025)
Low Rank Comes with Low Security: Gradient Assembly Poisoning Attacks against Distributed LoRA-based LLM Systems
par: Dong, Yueyan, et autres
Publié: (2026)
par: Dong, Yueyan, et autres
Publié: (2026)
On Protecting the Data Privacy of Large Language Models (LLMs): A Survey
par: Yan, Biwei, et autres
Publié: (2024)
par: Yan, Biwei, et autres
Publié: (2024)
What You Code Is What We Prove: Translating BLE App Logic into Formal Models with LLMs for Vulnerability Detection
par: Yan, Biwei, et autres
Publié: (2025)
par: Yan, Biwei, et autres
Publié: (2025)
The Agent Economy: A Blockchain-Based Foundation for Autonomous AI Agents
par: Xu, Minghui
Publié: (2026)
par: Xu, Minghui
Publié: (2026)
A Systematic Study of Code Obfuscation Against LLM-based Vulnerability Detection
par: Li, Xiao, et autres
Publié: (2025)
par: Li, Xiao, et autres
Publié: (2025)
CallShield: Secure Caller Authentication over Real-Time Audio Channels
par: Rabh, Mouna, et autres
Publié: (2026)
par: Rabh, Mouna, et autres
Publié: (2026)
Give and Take: An End-To-End Investigation of Giveaway Scam Conversion Rates
par: Liu, Enze, et autres
Publié: (2024)
par: Liu, Enze, et autres
Publié: (2024)
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
par: Zhou, Huijun, et autres
Publié: (2026)
par: Zhou, Huijun, et autres
Publié: (2026)
Usability as a Weapon: Attacking the Safety of LLM-Based Code Generation via Usability Requirements
par: Li, Yue, et autres
Publié: (2026)
par: Li, Yue, et autres
Publié: (2026)
Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
par: Shan, Zhengyang, et autres
Publié: (2026)
par: Shan, Zhengyang, et autres
Publié: (2026)
Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial Transferability
par: Zhang, Yechao, et autres
Publié: (2023)
par: Zhang, Yechao, et autres
Publié: (2023)
Why does weak-OOD help? A Further Step Towards Understanding Jailbreaking VLMs
par: Zhou, Yuxuan, et autres
Publié: (2025)
par: Zhou, Yuxuan, et autres
Publié: (2025)
TYPEPULSE: Detecting Type Confusion Bugs in Rust Programs
par: Chen, Hung-Mao, et autres
Publié: (2025)
par: Chen, Hung-Mao, et autres
Publié: (2025)
Secure Transfer Learning: Training Clean Models Against Backdoor in (Both) Pre-trained Encoders and Downstream Datasets
par: Zhang, Yechao, et autres
Publié: (2025)
par: Zhang, Yechao, et autres
Publié: (2025)
MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
par: Kumar, Sonu, et autres
Publié: (2025)
par: Kumar, Sonu, et autres
Publié: (2025)
Dataset Ownership in the Era of Large Language Models
par: Li, Kun, et autres
Publié: (2025)
par: Li, Kun, et autres
Publié: (2025)
Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device Fingerprinting
par: Specter, Michael A., et autres
Publié: (2025)
par: Specter, Michael A., et autres
Publié: (2025)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
par: Zhang, Dongsen, et autres
Publié: (2025)
par: Zhang, Dongsen, et autres
Publié: (2025)
One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP
par: Xu, Binyan, et autres
Publié: (2025)
par: Xu, Binyan, et autres
Publié: (2025)
A Survey on Large Language Model (LLM) Security and Privacy: The Good, the Bad, and the Ugly
par: Yao, Yifan, et autres
Publié: (2023)
par: Yao, Yifan, et autres
Publié: (2023)
Spa-VLM: Stealthy Poisoning Attacks on RAG-based VLM
par: Yu, Lei, et autres
Publié: (2025)
par: Yu, Lei, et autres
Publié: (2025)
Everything You Wanted to Know About LLM-based Vulnerability Detection But Were Afraid to Ask
par: Li, Yue, et autres
Publié: (2025)
par: Li, Yue, et autres
Publié: (2025)
Almost-Free Queue Jumping for Prior Inputs in Private Neural Inference
par: Zhang, Qiao, et autres
Publié: (2026)
par: Zhang, Qiao, et autres
Publié: (2026)
QSignAI: Quantum-Randomness-Seeded Identity Signatures at the Intersection of AI for Science and Science for AI
par: Liu, Dongping, et autres
Publié: (2026)
par: Liu, Dongping, et autres
Publié: (2026)
AutoIoT: Automated IoT Platform Using Large Language Models
par: Cheng, Ye, et autres
Publié: (2024)
par: Cheng, Ye, et autres
Publié: (2024)
Simplified and Secure MCP Gateways for Enterprise AI Integration
par: Brett, Ivo
Publié: (2025)
par: Brett, Ivo
Publié: (2025)
The Imitation Game: Using Large Language Models as Chatbots to Combat Chat-Based Cybercrimes
par: Yao, Yifan, et autres
Publié: (2025)
par: Yao, Yifan, et autres
Publié: (2025)
Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators
par: Danduri, Datta Manikanta Sri Hari, et autres
Publié: (2026)
par: Danduri, Datta Manikanta Sri Hari, et autres
Publié: (2026)
ConfusedPilot: Confused Deputy Risks in RAG-based LLMs
par: RoyChowdhury, Ayush, et autres
Publié: (2024)
par: RoyChowdhury, Ayush, et autres
Publié: (2024)
Distributed Security: From Isolated Properties to Synergistic Trust
par: Xu, Minghui
Publié: (2026)
par: Xu, Minghui
Publié: (2026)
AccLock: Unlocking Identity with Heartbeat Using In-Ear Accelerometers
par: Wang, Lei, et autres
Publié: (2026)
par: Wang, Lei, et autres
Publié: (2026)
Documents similaires
-
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
par: Li, Zhihao, et autres
Publié: (2026) -
I'm Spartacus, No, I'm Spartacus: Measuring and Understanding LLM Identity Confusion
par: Li, Kun, et autres
Publié: (2024) -
"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
par: Yan, Biwei, et autres
Publié: (2025) -
Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
par: Huang, Yuhang, et autres
Publié: (2025) -
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
par: Li, Zhihao, et autres
Publié: (2025)