用MCP协议藏身于AI流量中,让大模型红队代理隐蔽协作。
Hiding in the AI Traffic: Abusing MCP for LLM-Powered Agentic Red Teaming
- 通过MCP协议实现无周期心跳的异步并行通信
- 实验显示检测足迹大幅降低,人工干预减少90%以上
- 适合研究高级威胁模拟与防御系统设计者
生成式AI正重塑进攻性网络安全,使具备规划、执行和自适应能力的自主红队代理成为可能。然而现有方法在通用性与专精性间存在权衡,实际部署中仍面临幻觉、上下文限制及伦理问题。本文提出一种基于模型上下文协议(MCP)的新型命令与控制(C2)架构,可隐蔽协调分布式、自适应的侦察代理。我们发现该架构不仅提升了系统整体目标导向行为,更消除了主机与网络层面可被用于检测的特征痕迹。通过分析当前最先进的生成式红队方法,从微调专用模型到模块化或智能体框架,我们揭示其自动化能力与任务精度间的权衡。进一步说明,基于MCP的C2支持异步并行操作与实时情报共享,无需定期心跳。还探索了该架构的高级对抗能力、避检技术及其双用途伦理影响,建议在实验室环境中进行受控评估。实验对比传统C2显示,手动工作量显著减少,检测痕迹大幅降低。结论指出未来可集成自主攻击、防御型大模型代理、预测性规避动作与多智能体集群。所提出的MCP驱动的C2框架为真实可信的AI驱动红队操作迈出关键一步,既能模拟高级持续性威胁,亦可推动下一代防御系统的研发。
原文摘要 · Abstract (English)
Generative AI is reshaping offensive cybersecurity by enabling autonomous red team agents that can plan, execute, and adapt during penetration tests. However, existing approaches face trade-offs between generality and specialization, and practical deployments reveal challenges such as hallucinations, context limitations, and ethical concerns. In this work, we introduce a novel command & control (C2) architecture leveraging the Model Context Protocol (MCP) to coordinate distributed, adaptive reconnaissance agents covertly across networks. Notably, we find that our architecture not only improves goal-directed behavior of the system as whole, but also eliminates key host and network artifacts that can be used to detect and prevent command & control behavior altogether. We begin with a comprehensive review of state-of-the-art generative red teaming methods, from fine-tuned specialist models to modular or agentic frameworks, analyzing their automation capabilities against task-specific accuracy. We then detail how our MCP-based C2 can overcome current limitations by enabling asynchronous, parallel operations and real-time intelligence sharing without periodic beaconing. We furthermore explore advanced adversarial capabilities of this architecture, its detection-evasion techniques, and address dual-use ethical implications, proposing defensive measures and controlled evaluation in lab settings. Experimental comparisons with traditional C2 show drastic reductions in manual effort and detection footprint. We conclude with future directions for integrating autonomous exploitation, defensive LLM agents, predictive evasive maneuvers, and multi-agent swarms. The proposed MCP-enabled C2 framework demonstrates a significant step toward realistic, AI-driven red team operations that can simulate advanced persistent threats while informing the development of next-generation defensive systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。