O2 Muu julkaisu
A Formal Security Framework for Model Context Protocol-Based Tool Access in Agentic AI Systems; 
Tekijät: Alam, Mohammad Zahangir
Julkaisuvuosi: 2026
DOI: https://doi.org/10.2139/ssrn.6891368
Julkaisun avoimuus kirjaamishetkellä: Avoimesti saatavilla
Julkaisukanavan avoimuus : Kokonaan avoin julkaisukanava
Verkko-osoite: http://dx.doi.org/10.2139/ssrn.6891368
Preprintin osoite: http://dx.doi.org/10.2139/ssrn.6891368
The increasing deployment of agentic AI systems powered by large language models introduces significant security challenges at the interface between autonomous agents and external tool ecosystems. Existing security mechanisms, including role-based access control, OAuth-based authorization, and API gateway models, are designed for static, human-initiated interactions and fail to enforce trust boundaries across dynamic, runtime-delegated principal hierarchies in multi-agent environments. To address these limitations, we propose FSM-MCP, a mathematically grounded formal security model for MCP-based tool access in agentic AI systems. The model defines a hierarchical trust structure spanning users, orchestrator agents, sub-agents, and MCP servers, formalizing capability delegation, trust-boundary enforcement, and least-privilege tool invocation as verifiable security axioms. This formalization enables rigorous reasoning about tool-access integrity and precise detection of security violations across agent layers. To evaluate FSM-MCP, we simulate five threat classes — tool spoofing, privilege escalation, cross-agent prompt injection, context poisoning, and orchestrator hijacking — across three publicly available benchmarks, namely AgentBench, ToolBench, and APIBench, ensuring comprehensive and reproducible evaluation across diverse heterogeneous agentic deployment scenarios. Experimental results demonstrate that FSM-MCP reduces successful attack execution by 91.3% while introducing only 4.7% mean latency overhead, consistently outperforming unprotected baseline deployments and conventional access-control mechanisms across all evaluated threat classes. The framework improves trust delegation precision and inter-agent authentication robustness through capability-scoped access tokens, cryptographically signed tool manifests, context sanitization, and inter-agent message authentication. These results establish the first rigorous security foundation for MCP-based agentic AI deployment and provide a reproducible benchmark for evaluating tool-access threats in hierarchical multi-agent systems.
Julkaisussa olevat rahoitustiedot:
This research received no funding.