惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
V
V2EX
Martin Fowler
Martin Fowler
博客园 - Franky
P
Proofpoint News Feed
P
Palo Alto Networks Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog
The Register - Security
The Register - Security
Latest news
Latest news
S
Security @ Cisco Blogs
Simon Willison's Weblog
Simon Willison's Weblog
Recorded Future
Recorded Future
大猫的无限游戏
大猫的无限游戏
M
Microsoft Research Blog - Microsoft Research
Scott Helme
Scott Helme
T
Tailwind CSS Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
True Tiger Recordings
有赞技术团队
有赞技术团队
I
Intezer
Cisco Talos Blog
Cisco Talos Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
The GitHub Blog
The GitHub Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tenable Blog
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
Hacker News: Ask HN
Hacker News: Ask HN
S
Security Archives - TechRepublic
F
Future of Privacy Forum
爱范儿
爱范儿
PCI Perspectives
PCI Perspectives
H
Help Net Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
N
Netflix TechBlog - Medium
罗磊的独立博客
Apple Machine Learning Research
Apple Machine Learning Research
MongoDB | Blog
MongoDB | Blog
Security Latest
Security Latest
美团技术团队
博客园 - 三生石上(FineUI控件)
S
Schneier on Security
量子位
C
CERT Recently Published Vulnerability Notes
SecWiki News
SecWiki News

cs.AI updates on arXiv.org

Memory-Induced Supra-Competitive Outcomes Between Deep Reinforcement Learning Agents in Optimal Trade Execution Support-aware offline policy selection for advertising marketplaces AttuneBench: A Conversation-Based Benchmark for LLM Emotional Intelligence Gated DeltaNet-2: Decoupling Erase and Write in Linear Attention Evaluation of Pipelines for Data Integration into Knowledge Graphs Unlocking Proactivity in Task-Oriented Dialogue CLORE: Content-Level Optimization for Reasoning Efficiency ChronoMedicalWorld: A Medical World Model for Learning Patient Trajectories from Longitudinal Care Data RefusalBench: Why Refusal Rate Misranks Frontier LLMs on Biological Research Prompts Trace2Skill: Verifier-Guided Skill Evolution for Long-Context EDA Agents Multivariate Financial Forecasting using the Chronos Time Series Foundation Models SMDD-Bench: Can LLMs Solve Real-World Small Molecule Drug Design Tasks? Is Capability a Liability? More Capable Language Models Make Worse Forecasts When It Matters Most Cross-domain benchmarks reveal when coordinated AI agents improve scientific inference from partial evidence Deep Reinforcement Learning for Flexible Job Shop Scheduling with Random Job Arrivals Knowledge Graph Re-engineering Along the Ontological Continuum (extended version) Predicting Performance of Symbolic and Prompt Programs with Examples Visibility nowcasting in South Korea: a machine learning approach to class imbalance and distribution shift Toward AI VIS Co-Scientists: A General and End-to-End Agent Harness for Solving Complex Data Visualization Tasks PocketAgents: A Manifest-Driven Library of Autonomous Defense Agents Towards a compositional semantics for quantitative confidence assessment in assurance arguments LCGuard: Latent Communication Guard for Safe KV Sharing in Multi-Agent Systems Thermodynamic Irreversibility of Training Algorithms Understanding Perspectives of Patients, Caregivers and Clinicians towards Emerging Collaborative-decision Making Technologies TerminalWorld: Benchmarking Agents on Real-World Terminal Tasks Meta-Learning for Rapid Adaptation in Reference Tracking of Uncertain Nonlinear Systems MOSS: Self-Evolution through Source-Level Rewriting in Autonomous Agent Systems SciCore-Mol: Augmenting Large Language Models with Pluggable Molecular Cognition Modules Format-Constraint Coupling in Knowledge Graph Construction from Statistical Tables KAPPS: A knowledge-based CPPS Architecture for the Circular Factory LLM-Metrics: Measuring Research Impact Through Large Language Model Memory Towards a General Intelligence and Interface for Wearable Health Data Local Covariate Selection for Average Causal Effect Estimation without Pretreatment and Causal Sufficiency Assumptions High-speed Networking for Giga-Scale AI Factories A Causal Argumentation Method for Explainability of Machine Learning Models The Attribution Impossibility: No Feature Ranking Is Faithful, Stable, and Complete Under Collinearity OPPO: Bayesian Value Recursion for Token-Level Credit Assignment in LLM Reasoning Scalable On-Policy Reinforcement Learning via Adaptive Batch Scaling Addressing the Synergy Gap: The Six Elements of the Design Space Measuring Cross-Modal Synergy: A Benchmark for VLM Explainability IdleSpec: Exploiting Idle Time via Speculative Planning for LLM Agents Patch Hierarchical Attention Transformer for Efficient Particle Jet Tagging ExComm: Exploration-Stage Communication for Error-Resilient Agentic Test-Time Scaling FLUID: From Ephemeral IDs to Multimodal Semantic Codes for Industrial-Scale Livestreaming Recommendation The Illusion of Reasoning: Exposing Evasive Data Contamination in LLMs via Zero-CoT Truncation Parametric Modular Answer Set Programs Made Declarative The Impact of AI Usage and Informativeness on Skill Development in Logical Reasoning Autonomous LLM Agents & CTFs: A Second Look S2ED: From Story to Executable Descriptions for Consistency-Aware Story Illustration MonoScale: Scaling Multi-Agent System with Monotonic Improvement WorkstreamBench: Evaluating LLM Agents on End-to-End Spreadsheet Tasks in Finance HarnessAPI: A Skill-First Framework for Unified Streaming APIs and MCP Tools AOP-Wiki EMOD 3.0: Data Model Expansions and Content Evaluation Framework for Using Agentic AI to Improve Integration between AOPs and New Approach Methodologies (NAMs) Who Uses AI? Platforms, Workforce, and AI Exposure Claw AI Lab: An Autonomous Multi-Agent Research Team AI-Enabled Serious Games: Integrating Intelligence and Adaptivity in Training Systems Compiling Agentic Workflows into LLM Weights: Near-Frontier Quality at Two Orders of Magnitude Less Cost A Subjective Logic-based method for runtime confidence updates in safety arguments Meta-Soft: Leveraging Composable Meta-Tokens for Context-Preserving KV Cache Compression ArborKV: Structure-Aware KV Cache Management for Scaling Tree-based LLM Reasoning Spreadsheet-RL: Advancing Large Language Model Agents on Realistic Spreadsheet Tasks via Reinforcement Learning Beyond the Org Chart: AI and the Transformation of Invisible Work Think Thrice Before You Speak: Dual knowledge-enhanced Theory-of-Mind Reasoning for Persuasive Agents Advancing Mathematics Research with AI-Driven Formal Proof Search TO-Agents: A Multi-Agent AI Pipeline for Preference-Guided Topology Optimization Investigating Concept Alignment Using Implausible Category Members LLM Retrieval for Stable and Predictable Ad Recommendations MindLoom: Composing Thought Modes for Frontier-Level Reasoning Data Synthesis Planning, Scheduling, and Behavior in EV Charging Systems: A Critical Survey and Trilemma Framework Graph neural network explanations reveal a topological signature of disease-associated hubs in biological networks Learning Altruistic Collaboration in Heterogeneous Multi-Team Systems What Counts as AI Sycophancy? A Taxonomy and Expert Survey of a Fragmented Construct A Reproducible Log-Driven AutoML Framework for Interpretable Pipeline Optimization in Healthcare Risk Prediction Harnesses for Inference-Time Alignment over Execution Trajectories When Are Teacher Tokens Reliable? Position-Weighted On-Policy Self-Distillation for Reasoning PEARL: Unbiased Percentile Estimation via Contrastive Learning for Industrial-Scale Livestream Recommendation MPDocBench-Parse: Benchmarking Practical Multi-page Document Parsing EvoScene-VLA: Evolving Scene Beliefs Inside the Action Decoder for Chunked Robot Control Active Evidence-Seeking and Diagnostic Reasoning in Large Language Models for Clinical Decision Support The Log is the Agent: Event-Sourced Reactive Graphs for Auditable, Forkable Agentic Systems TBP-mHC: full expressivity for manifold-constrained hyper connections through transportation polytopes ECPO: Evidence-Coupled Policy Optimization for Evidence-Certified Candidate Ranking Faster Completion, Less Learning: Generative AI Reduced Study Time on Math Problems and the Knowledge They Build Evaluating Large Language Models as Live Strategic Agents: Provider Performance, Hybrid Decomposition, and Operational Gaps in Timed Risk Play Adapting the Interface, Not the Model: Runtime Harness Adaptation for Deterministic LLM Agents Scaling Observation-aware Planning in Uncertain Domains A Camera-Cooperative ISAC Framework for Multimodal Non-Cooperative UAVs Sensing Skill Weaving: Efficient LLM Improvement via Modular Skillpacks AtelierEval: Agentic Evaluation of Humans & LLMs as Text-to-Image Prompters SGR-Bench: Benchmarking Search Agents on State-Gated Retrieval Can AI Make Conflicts Worse? An Alignment Failure in LLM Deployment Across Conflict Contexts Implicit Safety Alignment from Crowd Preferences The Shape of Testimony: A Scalable Framework for Oral History Archive Comparison Latent-space Attacks for Refusal Evasion in Language Models Benchmarking and Improving Monitors for Out-Of-Distribution Alignment Failure in LLMs Forecasting Scientific Progress with Artificial Intelligence CausalGuard: Conformal Inference under Graph Uncertainty Towards Direct Evaluation of Harness Optimizers via Priority Ranking Engineering Hybrid Physics-Informed Neural Networks for Next-Generation Electricity Systems: A State-of-the-Art Review Protein Thoughts: Interpretable Reasoning with Tree of Thoughts and Embedding-Space Flow Matching for Protein-Protein Interaction Discovery
Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
Saeid Jamshi · 2026-05-23 · via cs.AI updates on arXiv.org

View PDF HTML (experimental)

Abstract:The Model Context Protocol (MCP) enables Large Language Models (LLMs) to interact with external tools via tool descriptors, thereby extending their capabilities for task execution, autonomous decision-making, and multi-agent coordination. Existing MCP deployments treat tool descriptors as trusted metadata, despite their direct integration into the LLM reasoning context. This introduces a previously underexplored semantic attack surface. Current defenses primarily target prompt injection, neglecting descriptor-level manipulation that can bias tool selection and downstream reasoning. To address this gap, we formalize three descriptor-driven attack classes: Tool Poisoning, Shadowing, and Rug Pull. We propose a layered defense solution that integrates descriptor integrity verification, pre-context semantic vetting with an auxiliary LLM, and lightweight runtime guardrails, without requiring model retraining. We evaluate GPT-5.3, DeepSeek-V3, and LLaMA-3.5 across eight prompting strategies in controlled, adversarial MCP scenarios in which tool metadata is manipulated to simulate realistic attacks. Results demonstrate that descriptor manipulation can substantially alter tool-selection behavior, producing unsafe tool invocations in up to 36% of trials under baseline configurations. The proposed full-stack mitigation reduces unsafe invocations to 15% while increasing the block rate to 74%, demonstrating substantial improvement in resistance to descriptor-driven attacks. Cross-model analysis further reveals significant differences in robustness, latency, and sensitivity to descriptor-level manipulation across LLM architectures and prompting strategies. This study provides a controlled cross-model evaluation of descriptor-level threats and mitigation strategies in tool-calling LLM systems, establishing an empirical foundation for deploying secure and resilient tool-augmented LLMs.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2512.06556 [cs.CR]
  (or arXiv:2512.06556v2 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2512.06556

arXiv-issued DOI via DataCite

Submission history

From: Saeid Jamshidi [view email]
[v1] Sat, 6 Dec 2025 20:07:58 UTC (10,647 KB)
[v2] Thu, 21 May 2026 13:44:50 UTC (6,543 KB)