跳到正文
Ars Technica:AI· Dan Goodin·· 4 小时前AI 评分59

MCP 智能体通信协议曝结构性缺陷,Google 等五机构确认相关漏洞

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

AI 导读

独立研究员 Syed Anas Mohiuddin 的概念验证攻击利用 MCP 的信任缺口,可让被攻击的网络内一个智能体向其他内部智能体传播恶意指令。过去五个月 Google、JP Morgan Chase、Weviate、Rapid7、法国政府跨部委数字部门和美国政府等机构确认了相关漏洞,该技术是一种针对特定智能体而非 LLM 的提示词注入形式。

正文

The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.

In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.

Unexpected and hard to mitigate

Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.

Read full article

Comments

来源:Ars Technica:AI · arstechnica.com