Skip to main navigation Skip to search Skip to main content

MSA: A Cross-MCP Privacy Attack via Memory Exfiltration of Large Language Models

  • Yiheng Sun
  • , Linkang Du
  • , Zhou Su
  • , Yuntao Wang
  • , Han Liu
  • , Quan Zhao
  • , Xiaolin Niu
  • Xi'an Jiaotong University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The Model Context Protocol (MCP) serves as a standardized interface for integrating large language model (LLM) agents with external tools, enhancing their functionality for practical applications. Recent studies have shown that MCPs are vulnerable to behavioral manipulation attacks like tool poisoning. However, there has been a neglect of privacy threats. This study unveils a privacy threat in MCPs, i.e., the memory stealing attack (MSA), where the malicious MCP server systematically accesses user-agent interaction data from other MCPs. MSA functions by embedding a “parasitic parameter” in an MCP’s API, masquerading as a technical requirement, to force the agent to include its session context in the parameter value during MCP invocation. The malicious MCP server then secretly sends the exfiltrated memory data to an attacker. Our experiments on 20 MCP servers using Cursor, TRAE, and Visual Studio Code confirm that MSA is effective in real-world MCP applications. MSA achieves a 100% context capture and exfiltration success rate, with memory reconstruction accuracy ranging from 85.67% to 87.81%, presenting a significant privacy threat to users.

Original languageEnglish
Title of host publicationWPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society
EditorsJianying Zhou, Daniel Reijsbergen, Eyasu Getahun Chekole
PublisherAssociation for Computing Machinery, Inc
Pages177-182
Number of pages6
ISBN (Electronic)9798400718984
DOIs
StatePublished - 18 Nov 2025
Event24th Workshop on Privacy in the Electronic Society, WPES 2025 - Taipei, Taiwan, Province of China
Duration: 13 Oct 202517 Oct 2025

Publication series

NameWPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society

Conference

Conference24th Workshop on Privacy in the Electronic Society, WPES 2025
Country/TerritoryTaiwan, Province of China
CityTaipei
Period13/10/2517/10/25

Keywords

  • Large language models
  • Model context protocol
  • Privacy attack

Fingerprint

Dive into the research topics of 'MSA: A Cross-MCP Privacy Attack via Memory Exfiltration of Large Language Models'. Together they form a unique fingerprint.

Cite this