TY - GEN
T1 - MSA
T2 - 24th Workshop on Privacy in the Electronic Society, WPES 2025
AU - Sun, Yiheng
AU - Du, Linkang
AU - Su, Zhou
AU - Wang, Yuntao
AU - Liu, Han
AU - Zhao, Quan
AU - Niu, Xiaolin
N1 - Publisher Copyright:
© 2025 Copyright held by the owner/author(s).
PY - 2025/11/18
Y1 - 2025/11/18
N2 - The Model Context Protocol (MCP) serves as a standardized interface for integrating large language model (LLM) agents with external tools, enhancing their functionality for practical applications. Recent studies have shown that MCPs are vulnerable to behavioral manipulation attacks like tool poisoning. However, there has been a neglect of privacy threats. This study unveils a privacy threat in MCPs, i.e., the memory stealing attack (MSA), where the malicious MCP server systematically accesses user-agent interaction data from other MCPs. MSA functions by embedding a “parasitic parameter” in an MCP’s API, masquerading as a technical requirement, to force the agent to include its session context in the parameter value during MCP invocation. The malicious MCP server then secretly sends the exfiltrated memory data to an attacker. Our experiments on 20 MCP servers using Cursor, TRAE, and Visual Studio Code confirm that MSA is effective in real-world MCP applications. MSA achieves a 100% context capture and exfiltration success rate, with memory reconstruction accuracy ranging from 85.67% to 87.81%, presenting a significant privacy threat to users.
AB - The Model Context Protocol (MCP) serves as a standardized interface for integrating large language model (LLM) agents with external tools, enhancing their functionality for practical applications. Recent studies have shown that MCPs are vulnerable to behavioral manipulation attacks like tool poisoning. However, there has been a neglect of privacy threats. This study unveils a privacy threat in MCPs, i.e., the memory stealing attack (MSA), where the malicious MCP server systematically accesses user-agent interaction data from other MCPs. MSA functions by embedding a “parasitic parameter” in an MCP’s API, masquerading as a technical requirement, to force the agent to include its session context in the parameter value during MCP invocation. The malicious MCP server then secretly sends the exfiltrated memory data to an attacker. Our experiments on 20 MCP servers using Cursor, TRAE, and Visual Studio Code confirm that MSA is effective in real-world MCP applications. MSA achieves a 100% context capture and exfiltration success rate, with memory reconstruction accuracy ranging from 85.67% to 87.81%, presenting a significant privacy threat to users.
KW - Large language models
KW - Model context protocol
KW - Privacy attack
UR - https://www.scopus.com/pages/publications/105023701343
U2 - 10.1145/3733802.3764057
DO - 10.1145/3733802.3764057
M3 - 会议稿件
AN - SCOPUS:105023701343
T3 - WPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society
SP - 177
EP - 182
BT - WPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society
A2 - Zhou, Jianying
A2 - Reijsbergen, Daniel
A2 - Chekole, Eyasu Getahun
PB - Association for Computing Machinery, Inc
Y2 - 13 October 2025 through 17 October 2025
ER -