A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
研究解决了MCP生态系统中代理被劫持的风险问题,通过A2M框架优化元数据和执行轨迹来提高攻击效率,从而揭示了加强工具审查和运行时隔离的必要性。
📝 Abstract
Agents using the Model Context Protocol (MCP) rely on semantic matching to select tools from third-party servers, exposing a semantic supply-chain risk through attacker-controlled metadata and outputs. We introduce A2M (Attraction-to-Manipulation), a two-stage black-box framework for hijacking MCP agents. The Attraction phase optimizes tool metadata to increase invocation probability; the Manipulation phase uses execution traces to refine adversarial tool returns that steer agents toward attacker-desired outcomes. On LiveMCPBench, direct attacks optimized and evaluated on GLM-4.6 achieve a macro-average malicious tool invocation rate of 93.6% across four scenarios, increase weighted token costs to 32.4$\times$ the benign baseline under Cognitive Denial of Service, and attain a mean attack success rate of 74.4% across Information Exfiltration, Environment Integrity Compromise, and Reasoning Derailment. Transfer to four other models without re-optimization yields corresponding macro-averages of 63.6%, 2.7$\times$, and 24.5%. These findings motivate stronger tool vetting and runtime isolation in MCP ecosystems. Code is publicly available at https://github.com/Lilaizhen/A2M.
Problem

Research questions and friction points this paper is trying to address.

MCP Ecosystem
Semantic Supply-Chain Risk
Agent Hijacking
Innovation

Methods, ideas, or system contributions that make the work stand out.

two-stage black-box framework
semantic matching
execution traces
adversarial tool returns
💼 Related Jobs
No related jobs found.
L
Laizhen Li
Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences; University of Chinese Academy of Sciences
X
Xuan Wang
Nanyang Technological University
P
Peicheng Zhao
Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences; Southern University of Science and Technology
J
Juanjuan Zhao
Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences
Kejiang Ye
Kejiang Ye
Professor, Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences
Cloud ComputingAI SystemsIndustrial Internet
C
Cheng-zhong Xu
University of Macau
Xitong Gao
Xitong Gao
Shenzhen Institute of Advanced Technology, Chinese Academy of Sciences
Efficient Training and InferenceAI Security and Privacy