paper-with-me

홈 › Papers

ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control

2025-06-02 · Manish Bhatt, Vineeth Sai Narajala, Idan Habler

The Model Context Protocol (MCP) plays a crucial role in extending the capabilities of Large Language Models (LLMs) by enabling integration with external tools and data sources. However, the standard MCP specification presents significant security vulnerabilities, notably Tool Poisoning and Rug Pull attacks. This paper introduces the Enhanced Tool Definition Interface (ETDI), a security extension designed to fortify MCP. ETDI incorporates cryptographic identity verification, immutable versioned tool definitions, and explicit permission management, often leveraging OAuth 2.0. We further propose extending MCP with fine-grained, policy-based access control, where tool capabilities are dynamically evaluated against explicit policies using a dedicated policy engine, considering runtime context beyond static OAuth scopes. This layered approach aims to establish a more secure, trustworthy, and controllable ecosystem for AI applications interacting with LLMs and external tools.

📄 PDF Abstract BibTeX arXiv:2506.01333

Code (0)

등록된 구현이 없습니다.

Tasks

Management

Similar Papers 제목 키워드 기반

Training Large Language Models for Advanced Typosquatting Detection

2025-03-28 · Jackson Welch

Typosquatting is a long-standing cyber threat that exploits human error in typing URLs to deceive users, distribute malware, and conduct phishing attacks. With the proliferation of domain names and new Top-Level Domains …

LLM App Squatting and Cloning

2024-11-12 · Yinglin Xie, Xinyi Hou, Yanjie Zhao, Kai Chen 외

Impersonation tactics, such as app squatting and app cloning, have posed longstanding challenges in mobile app stores, where malicious actors exploit the names and reputations of popular apps to deceive users. With the r…

Language ModelingLanguage ModellingLarge Language Model

Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach

2025-04-28 · Vineeth Sai Narajala, Ken Huang, Idan Habler

The rise of generative AI (GenAI) multi-agent systems (MAS) necessitates standardized protocols enabling agents to discover and interact with external tools. However, these protocols introduce new security challenges, pa…

NetDiffuser: Deceiving DNN-Based Network Attack Detection Systems with Diffusion-Generated Adversarial Traffic

2026-03-09 · Pratyay Kumar, Abu Saleh Md Tayeen, Satyajayant Misra, Huiping Cao 외 arxiv

Deep learning (DL)-based Network Intrusion Detection System (NIDS) has demonstrated great promise in detecting malicious network traffic. However, they face significant security risks due to their vulnerability to advers…

Network Intrusion Detection

Sound-skwatter (Did You Mean: Sound-squatter?) AI-powered Generator for Phishing Prevention

2023-10-10 · Rodolfo Valentim, Idilio Drago, Marco Mellia, Federico Cerutti

Sound-squatting is a phishing attack that tricks users into malicious resources by exploiting similarities in the pronunciation of words. Proactive defense against sound-squatting candidates is complex, and existing solu…