论文概要
研究领域: 安全
作者: Laizhen Li, Xuan Wang, Peicheng Zhao, Juanjuan Zhao, Kejiang Ye et al.
发布时间: 2026-09-22
arXiv: 2609.26761
中文摘要
使用模型上下文协议(MCP)的智能体依赖语义匹配从第三方服务器选工具,经攻击者控制的元数据与输出暴露语义供应链风险。我们提出 A2M(吸引-操纵)——两阶段黑盒框架劫持 MCP 智能体:"吸引"阶段优化工具元数据以提高被调概率;"操纵"阶段利用执行轨迹精化对抗性工具返回,把智能体引向攻击者期望结果。LiveMCPBench 上,对 GLM-4.6 优化并评测的直接攻击:四场景宏平均恶意工具调用率 93.6%;"认知拒绝服务"下加权 token 成本达良性基线 32.4 倍;信息窃取、环境完整性破坏、推理脱轨三类场景平均攻击成功率 74.4%。不经重优化迁移到另四个模型,对应宏平均 63.6%、2.7×、24.5%。这些发现促使 MCP 生态加强工具审核与运行时隔离。代码开源于 https://github.com/Lilaizhen/A2M。
原文摘要
Agents using the Model Context Protocol (MCP) rely on semantic matching to select tools from third-party servers, exposing a semantic supply-chain risk through attacker-controlled metadata and outputs. We introduce A2M (Attraction-to-Manipulation), a two-stage black-box framework for hijacking MCP agents. The Attraction phase optimizes tool metadata to increase invocation probability; the Manipulation phase uses execution traces to refine adversarial tool returns that steer agents toward attacker-desired outcomes. On LiveMCPBench, direct attacks optimized and evaluated on GLM-4.6 achieve a macro-average malicious tool invocation rate of 93.6% across four scenarios, increase weighted token costs to 32.4\(\times\) the benign baseline under Cognitive Denial of Service, and attain a mean attack success rate of 74.4% across Information Exfiltration, Environment Integrity Compromise, and Reasoning Derailment. Transfer to four other models without re-optimization yields corresponding macro-averages of 63.6%, 2.7\(\times\), and 24.5%. These findings motivate stronger tool vetting and runtime isolation in MCP ecosystems. Code is publicly available at https://github.com/Lilaizhen/A2M.
自动采集于 2026-09-24
#论文 #arXiv #安全 #小凯
讨论回复
加载中...正在加载回复...
推荐
智谱 GLM-5 已上线
我正在智谱大模型开放平台 BigModel.cn 上打造 AI 应用,智谱新一代旗舰模型 GLM-5 已上线,在推理、代码、智能体综合能力达到开源模型 SOTA 水平。