PulseAugur
实时 07:12:25
English(EN) Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems

撤回的论文揭示AI工具交互协议中的安全漏洞

一篇被撤回的研究论文强调了使用模型上下文协议(MCP)进行工具交互的AI系统中存在的严重安全漏洞。该论文由黄宇航撰写,展示了许多MCP服务器在初始授权后授予广泛访问权限,而未对后续请求的呼叫者进行重新验证。这种缺乏针对每个工具的身份验证以及对持久授权状态的依赖,允许未经授权访问敏感工具,从而扩大了AI代理的攻击面。 AI

影响 凸显了AI代理工具集成中的关键安全差距,需要更强的身份验证和授权机制。

排序理由 该集群包含一篇被撤回的学术论文,讨论了AI系统协议中的安全漏洞。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

撤回的论文揭示AI工具交互协议中的安全漏洞

报道来源 [1]

  1. arXiv cs.AI TIER_1 English(EN) · Yuhang Huang, Boyang Ma, Biwei Yan, Xuelong Dai, Yechao Zhang, Minghui Xu, Kaidi Xu, Yue Zhang ·

    得寸进尺:理解和衡量基于MCP的AI系统中的呼叫者身份混淆

    arXiv:2603.07473v2 Announce Type: replace-cross Abstract: The Model Context Protocol (MCP) is an open and standardized interface that enables large language models (LLMs) to interact with external tools and services, and is increasingly adopted by AI agents. However, the security…