7 papers
"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers
Biwei Yan, Minghui Xu, Yijun Yang +4
The Model Context Protocol (MCP) has rapidly become the de facto standard for connecting large language models (LLMs) to external resources, but it also introduces a class of priva…
A Measurement Study of Cryptographic Misuse in Embodied AI Mobile Applications
Junchao Li, Xuelei Wang, Yuhang Huang +5
Embodied AI (EAI) mobile applications are evolving from auxiliary user interfaces into active control-path components, directly linking mobile-side cryptographic security to cyber-…
MIRAGE: Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents
Xuelong Dai, Jianyu Ma, Boyang Ma +3
Multimodal Large Language Model (MLLM)-based web agents provide practical, high-precision solutions for visual browser automation; however, they inherently expand the attack surfac…
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
Yuhang Huang, Boyang Ma, Biwei Yan +5
The Model Context Protocol (MCP) is an open and standardized interface that enables large language models (LLMs) to interact with external tools and services, and is increasingly a…
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
Boyang Ma, Hechuan Guo, Peizhuo Lv +5
Embodied AI systems (e.g., autonomous vehicles, service robots, and LLM-driven interactive agents) are rapidly transitioning from controlled environments to safety critical real-wo…
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
Zhihao Li, Boyang Ma, Xuelong Dai +4
The Model Context Protocol (MCP) enables large language models to invoke external tools through natural-language descriptions, forming the foundation of many AI agent applications.…