6 papers
"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers
Biwei Yan, Minghui Xu, Yijun Yang +4
The Model Context Protocol (MCP) has rapidly become the de facto standard for connecting large language models (LLMs) to external resources, but it also introduces a class of priva…
MIRAGE: Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents
Xuelong Dai, Jianyu Ma, Boyang Ma +3
Multimodal Large Language Model (MLLM)-based web agents provide practical, high-precision solutions for visual browser automation; however, they inherently expand the attack surfac…
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
Yuhang Huang, Boyang Ma, Biwei Yan +5
The Model Context Protocol (MCP) is an open and standardized interface that enables large language models (LLMs) to interact with external tools and services, and is increasingly a…
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
Zhihao Li, Boyang Ma, Xuelong Dai +4
The Model Context Protocol (MCP) enables large language models to invoke external tools through natural-language descriptions, forming the foundation of many AI agent applications.…
"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
Biwei Yan, Yue Zhang, Minghui Xu +5
The Model Context Protocol (MCP) is rapidly emerging as the middleware for LLM-based applications, offering a standardized interface for tool integration. However, its built-in sec…
What You Code Is What We Prove: Translating BLE App Logic into Formal Models with LLMs for Vulnerability Detection
Biwei Yan, Yue Zhang, Minghui Xu +3
The application layer of Bluetooth Low Energy (BLE) is a growing source of security vulnerabilities, as developers often neglect to implement critical protections such as encryptio…