O2 Muu julkaisu

A Formal Security Framework for Model Context Protocol-Based Tool Access in Agentic AI Systems;




TekijätAlam, Mohammad Zahangir

Julkaisuvuosi2026

DOIhttps://doi.org/10.2139/ssrn.6891368

Julkaisun avoimuus kirjaamishetkelläAvoimesti saatavilla

Julkaisukanavan avoimuus Kokonaan avoin julkaisukanava

Verkko-osoitehttp://dx.doi.org/10.2139/ssrn.6891368

Preprintin osoitehttp://dx.doi.org/10.2139/ssrn.6891368


Tiivistelmä

The increasing deployment of agentic AI systems powered by large language models introduces significant security challenges at the interface between autonomous agents and external tool ecosystems. Existing security mechanisms, including role-based access control, OAuth-based authorization, and API gateway models, are designed for static, human-initiated interactions and fail to enforce trust boundaries across dynamic, runtime-delegated principal hierarchies in multi-agent environments. To address these limitations, we propose FSM-MCP, a mathematically grounded formal security model for MCP-based tool access in agentic AI systems. The model defines a hierarchical trust structure spanning users, orchestrator agents, sub-agents, and MCP servers, formalizing capability delegation, trust-boundary enforcement, and least-privilege tool invocation as verifiable security axioms. This formalization enables rigorous reasoning about tool-access integrity and precise detection of security violations across agent layers. To evaluate FSM-MCP, we simulate five threat classes — tool spoofing, privilege escalation, cross-agent prompt injection, context poisoning, and orchestrator hijacking — across three publicly available benchmarks, namely AgentBench, ToolBench, and APIBench, ensuring comprehensive and reproducible evaluation across diverse heterogeneous agentic deployment scenarios. Experimental results demonstrate that FSM-MCP reduces successful attack execution by 91.3% while introducing only 4.7% mean latency overhead, consistently outperforming unprotected baseline deployments and conventional access-control mechanisms across all evaluated threat classes. The framework improves trust delegation precision and inter-agent authentication robustness through capability-scoped access tokens, cryptographically signed tool manifests, context sanitization, and inter-agent message authentication. These results establish the first rigorous security foundation for MCP-based agentic AI deployment and provide a reproducible benchmark for evaluating tool-access threats in hierarchical multi-agent systems.


Julkaisussa olevat rahoitustiedot
This research received no funding.


Last updated on