跳到主要导航 跳到搜索 跳到主要内容

MSA: A Cross-MCP Privacy Attack via Memory Exfiltration of Large Language Models

  • Yiheng Sun
  • , Linkang Du
  • , Zhou Su
  • , Yuntao Wang
  • , Han Liu
  • , Quan Zhao
  • , Xiaolin Niu
  • Xi'an Jiaotong University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The Model Context Protocol (MCP) serves as a standardized interface for integrating large language model (LLM) agents with external tools, enhancing their functionality for practical applications. Recent studies have shown that MCPs are vulnerable to behavioral manipulation attacks like tool poisoning. However, there has been a neglect of privacy threats. This study unveils a privacy threat in MCPs, i.e., the memory stealing attack (MSA), where the malicious MCP server systematically accesses user-agent interaction data from other MCPs. MSA functions by embedding a “parasitic parameter” in an MCP’s API, masquerading as a technical requirement, to force the agent to include its session context in the parameter value during MCP invocation. The malicious MCP server then secretly sends the exfiltrated memory data to an attacker. Our experiments on 20 MCP servers using Cursor, TRAE, and Visual Studio Code confirm that MSA is effective in real-world MCP applications. MSA achieves a 100% context capture and exfiltration success rate, with memory reconstruction accuracy ranging from 85.67% to 87.81%, presenting a significant privacy threat to users.

源语言英语
主期刊名WPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society
编辑Jianying Zhou, Daniel Reijsbergen, Eyasu Getahun Chekole
出版商Association for Computing Machinery, Inc
177-182
页数6
ISBN(电子版)9798400718984
DOI
出版状态已出版 - 18 11月 2025
活动24th Workshop on Privacy in the Electronic Society, WPES 2025 - Taipei, 中国台湾
期限: 13 10月 202517 10月 2025

丛书

姓名WPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society

会议

会议24th Workshop on Privacy in the Electronic Society, WPES 2025
国家/地区中国台湾
Taipei
时期13/10/2517/10/25

学术指纹

探究 'MSA: A Cross-MCP Privacy Attack via Memory Exfiltration of Large Language Models' 的科研主题。它们共同构成独一无二的学术指纹。

引用此