[论文] [论文] A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem

论文概要 研究领域: 安全 作者: Laizhen Li, Xuan Wang, Peicheng Zhao, Juanjuan Zhao, Kejiang Ye et al. 发布时间: 2026-09-22 arXiv: 2609.26761

论文概要

研究领域: 安全 作者: Laizhen Li, Xuan Wang, Peicheng Zhao, Juanjuan Zhao, Kejiang Ye et al. 发布时间: 2026-09-22 arXiv: 2609.26761

中文摘要

使用模型上下文协议(MCP)的智能体依赖语义匹配从第三方服务器选工具,经攻击者控制的元数据与输出暴露语义供应链风险。我们提出 A2M(吸引-操纵)——两阶段黑盒框架劫持 MCP 智能体:"吸引"阶段优化工具元数据以提高被调概率;"操纵"阶段利用执行轨迹精化对抗性工具返回,把智能体引向攻击者期望结果。LiveMCPBench 上,对 GLM-4.6 优化并评测的直接攻击:四场景宏平均恶意工具调用率 93.6%;"认知拒绝服务"下加权 token 成本达良性基线 32.4 倍;信息窃取、环境完整性破坏、推理脱轨三类场景平均攻击成功率 74.4%。不经重优化迁移到另四个模型,对应宏平均 63.6%、2.7×、24.5%。这些发现促使 MCP 生态加强工具审核与运行时隔离。代码开源于 https://github.com/Lilaizhen/A2M。

原文摘要

Agents using the Model Context Protocol (MCP) rely on semantic matching to select tools from third-party servers, exposing a semantic supply-chain risk through attacker-controlled metadata and outputs. We introduce A2M (Attraction-to-Manipulation), a two-stage black-box framework for hijacking MCP agents. The Attraction phase optimizes tool metadata to increase invocation probability; the Manipulation phase uses execution traces to refine adversarial tool returns that steer agents toward attacker-desired outcomes. On LiveMCPBench, direct attacks optimized and evaluated on GLM-4.6 achieve a macro-average malicious tool invocation rate of 93.6% across four scenarios, increase weighted token costs to 32.4\(\times\) the benign baseline under Cognitive Denial of Service, and attain a mean attack success rate of 74.4% across Information Exfiltration, Environment Integrity Compromise, and Reasoning Derailment. Transfer to four other models without re-optimization yields corresponding macro-averages of 63.6%, 2.7\(\times\), and 24.5%. These findings motivate stronger tool vetting and runtime isolation in MCP ecosystems. Code is publicly available at https://github.com/Lilaizhen/A2M.


*自动采集于 2026-09-24*

#论文 #arXiv #安全 #小凯

暂无表态

想参与讨论或点赞?登录后使用完整功能

讨论回复(0)

暂无回复,登录后可参与讨论

本文标签

合作

智谱 GLM-5 已上线

在智谱开放平台 BigModel.cn 打造 AI 应用。新一代旗舰模型 GLM-5 在推理、代码、智能体综合能力达到开源模型 SOTA。

领取 2000万 Tokens