paper-with-me

홈 › Papers

Invisible Threats from Model Context Protocol: Generating Stealthy Injection Payload via Tree-based Adaptive Search

2026-03-25 · Yulin Shen, Xudong Pan, Geng Hong, Min Yang arxiv

Recent advances in the Model Context Protocol (MCP) have enabled large language models (LLMs) to invoke external tools with unprecedented ease. This creates a new class of powerful and tool augmented agents. Unfortunately, this capability also introduces an under explored attack surface, specifically the malicious manipulation of tool responses. Existing techniques for indirect prompt injection that target MCP suffer from high deployment costs, weak semantic coherence, or heavy white box requirements. Furthermore, they are often easily detected by recently proposed defenses. In this paper, we propose Tree structured Injection for Payloads (TIP), a novel black-box attack which generates natural payloads to reliably seize control of MCP enabled agents even under defense. Technically, We cast payload generation as a tree structured search problem and guide the search with an attacker LLM operating under our proposed coarse-to-fine optimization framework. To stabilize learning and avoid local optima, we introduce a path-aware feedback mechanism that surfaces only high quality historical trajectories to the attacker model. The framework is further hardened against defensive transformations by explicitly conditioning the search on observable defense signals and dynamically reallocating the exploration budget. Extensive experiments on four mainstream LLMs show that TIP attains over 95% attack success in undefended settings while requiring an order of magnitude fewer queries than prior adaptive attacks. Against four representative defense approaches, TIP preserves more than 50% effectiveness and significantly outperforms the state-of-the-art attacks. By implementing the attack on real world MCP systems, our results expose an invisible but practical threat vector in MCP deployments. We also discuss potential mitigation approaches to address this critical security gap.

📄 PDF Abstract BibTeX arXiv:2603.24203

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models

2025-05-22 · Junjie Xiong, Changjia Zhu, Shuhang Lin, Chong Zhang 외

Large Language Models (LLMs) are increasingly equipped with capabilities of real-time web search and integrated with protocols like Model Context Protocol (MCP). This extension could introduce new security vulnerabilitie…

IAP: Invisible Adversarial Patch Attack through Perceptibility-Aware Localization and Perturbation Optimization

2025-07-09 · Subrat Kishore Dutta, Xiao Zhang arxiv

Despite modifying only a small localized input region, adversarial patches can drastically change the prediction of computer vision models. However, prior methods either cannot perform satisfactorily under targeted attac…

Color Constancy

Hidden Tail: Adversarial Image Causing Stealthy Resource Consumption in Vision-Language Models

2025-08-26 · Rui Zhang, Zihan Wang, Tianli Yang, Hongwei Li 외 arxiv

Vision-Language Models (VLMs) are increasingly deployed in real-world applications, but their high inference cost makes them vulnerable to resource consumption attacks. Prior attacks attempt to extend VLM output sequence…

A Dual Stealthy Backdoor: From Both Spatial and Frequency Perspectives

2023-07-03 · Yudong Gao, Honglong Chen, Peng Sun, Junjian Li 외

Backdoor attacks pose serious security threats to deep neural networks (DNNs). Backdoored models make arbitrarily (targeted) incorrect predictions on inputs embedded with well-designed triggers while behaving normally on…

Backdoor Attack

VisualTrap: A Stealthy Backdoor Attack on GUI Agents via Visual Grounding Manipulation

2025-07-09 · Ziang Ye, Yang Zhang, Wentao Shi, Xiaoyu You 외

Graphical User Interface (GUI) agents powered by Large Vision-Language Models (LVLMs) have emerged as a revolutionary approach to automating human-machine interactions, capable of autonomously operating personal devices …

Backdoor AttackVisual Grounding