arXiv:2604.07551cs.CRcs.AI2026-04被引 1

为大模型工具调用协议设计分层防御体系,明确各环节安全责任。

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security

  • 按架构层级划分攻击类型,明确每类攻击的责任主体。
  • 发现现有防护多集中在工具层,宿主编排与供应链层存在明显短板。
  • 适合关注AI系统安全架构的开发者与安全研究人员参考。

模型上下文协议(MCP)使大语言模型能够动态发现并调用第三方工具,显著扩展智能体能力,但也带来了独特的安全挑战。与仅依赖提示词交互不同,MCP暴露了预执行产物、共享上下文、多轮工作流以及第三方供应链,易受独立运行组件中恶意行为的影响。尽管已有研究识别出MCP特异性攻击并评估了防御措施,但多数工作仍以攻击为中心或依赖基准测试,难以指导安全责任在MCP架构中的合理分配。鉴于MCP具有多方协作与分布式信任边界的特点,这一问题尤为关键。本文提出一种面向防御部署的MCP安全分析框架,构建基于层级对齐的攻击分类体系,将威胁映射至六个MCP层级,并识别主要与次要防御点,支持在控制工具、服务器或生态组件的攻击者环境下进行系统性纵深防御推理。将现有学术与工业界防御措施结构化地映射到该框架后发现,防护分布不均,且主要集中在工具层,而宿主编排、传输及供应链层仍存在持续性漏洞。这些结果表明,许多MCP安全弱点源于架构层面的错配,而非孤立的实现缺陷。

原文摘要 · Abstract (English)

The Model Context Protocol (MCP) enables large language models (LLMs) to dynamically discover and invoke third-party tools, significantly expanding agent capabilities while introducing a distinct security landscape. Unlike prompt-only interactions, MCP exposes pre-execution artifacts, shared context, multi-turn workflows, and third-party supply chains to adversarial influence across independently operated components. While recent work has identified MCP-specific attacks and evaluated defenses, existing studies are largely attack-centric or benchmark-driven, providing limited guidance on where mitigation responsibility should reside within the MCP architecture. This is problematic given MCP's multi-party design and distributed trust boundaries. We present a defense-placement-oriented security analysis of MCP, introducing a layer-aligned taxonomy that organizes attacks by the architectural component responsible for enforcement. Threats are mapped across six MCP layers, and primary and secondary defense points are identified to support principled defense-in-depth reasoning under adversaries controlling tools, servers, or ecosystem components. A structured mapping of existing academic and industry defenses onto this framework reveals uneven and predominantly tool-centric protection, with persistent gaps at the host orchestration, transport, and supply-chain layers. These findings suggest that many MCP security weaknesses stem from architectural misalignment rather than isolated implementation flaws.

安全架构大模型安全防御体系

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。