FlowGuard:从信号到MCP安全检测的证据
FlowGuard: From Signals to Evidence for MCP Security Detection
浏览论文内容
中文总结 AI 辅助
研究针对现有MCP安全扫描器不足,提出FlowGuard系统,结合语义风险分类等方法,通过运行时证据验证执行风险、检测语义风险,在基准测试和实际评估中取得良好效果,能有效评估MCP交互中的多种风险。
中文摘要 AI 辅助
模型上下文协议(MCP)使大型语言模型(LLM)代理能够通过元数据交换、工具调用和响应消费与外部工具交互。现有MCP安全扫描器主要基于可疑语义信号而非实际执行行为进行推理,导致风险评估不可靠。例如,类似凭证的字符串可能只是占位符而非实际泄露。我们提出了FlowGuard,一个基于证据的MCP安全检测系统。它结合了语义风险分类、侦察引导的有效载荷缩小、模式验证探针生成、证据判定和历史引导的细化。通过运行时证据验证执行相关风险,检测工具元数据和返回内容中的语义风险。在包含1880个MCP案例的可执行基准测试中评估,在执行相关的命令注入和文件系统访问类别上分别达到0.879和0.942的F1分数。与现有动态扫描器相比,端到端延迟最多降低2.23倍。在实际评估中,在326台服务器上报告了523个发现。这些结果表明基于证据的检测可以评估MCP交互中执行相关和语义风险。
英文摘要
The Model Context Protocol (MCP) enables LLM agents to interact with external tools through metadata exchange, tool invocation, and response consumption. Existing MCP security scanners primarily reason about suspicious semantic signals rather than real execution behaviors, which can lead to unreliable risk assessment. For example, credential-like strings may simply be placeholders rather than actual leakage. This gap requires runtime evidence for execution-related risks and careful semantic analysis for risks carried in metadata or returned content. We present FlowGuard, an evidence-grounded MCP security detection system. FlowGuard combines semantic risk triage, recon-guided payload narrowing, schema-valid probe generation, evidence adjudication, and history-guided refinement. It verifies execution-related risks through runtime evidence and detects semantic risks in tool metadata and returned content. We evaluate FlowGuard on an executable benchmark containing 1,880 MCP cases across five vulnerability categories. FlowGuard achieves F1 scores of 0.879 and 0.942 on the execution-related Command Injection and File System Access categories, respectively. Compared with existing dynamic scanners, FlowGuard reduces end-to-end latency by up to 2.23x. In the real-world evaluation, FlowGuard reports 523 findings across 326 servers. These results show that evidence-grounded detection can assess both execution-related and semantic risks in MCP interactions.