当智能体在Web3中行动:MCP、技能与工具调用的攻击面调查
When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling
浏览论文内容
中文总结 AI 辅助
本调查针对智能体通过MCP等在Web3区块链上行动的攻击面,构建风险映射矩阵,发现现有防护不足,推导了相关研究议程。
中文摘要 AI 辅助
AI智能体越来越多地采取行动,而非仅进行读取:在模型上下文协议(MCP)生态系统中,已部署的修改外部状态的工具占比从27%升至65%。当智能体通过MCP、技能和工具调用在公共区块链上行使此权限时,攻击后果由区块链执行层而非传统软件假设决定。本调查指出,该层的四个特性(不可逆性、签名权限、持续自主性及序列级组合)定性改变了威胁模型,将通用智能体安全的可恢复故障转化为持续的不可逆损失。我们将零散的MCP安全文献整理为攻击面分类法,提出Web3风险映射矩阵,将每个攻击类别与其放大影响、负责放大器、代表性缓解措施及残留缺口关联。我们综合防御措施,包括新兴的基于区块链的机制,发现其虽在改进但仍不足:已测防护措施可阻止不到30%的攻击,而模型级安全可拒绝不到3%的攻击。最后,我们将本研究与邻近调查进行定位,并从矩阵的空白单元格中推导研究议程。
英文摘要
AI agents increasingly act rather than merely read: across the Model Context Protocol (MCP) ecosystem, the share of deployed tools that modify external state has risen from 27% to 65% of tool use. When agents exercise this authority on public blockchains through MCP, skills, and tool calling, the consequences of an attack are governed by the blockchain execution layer rather than by conventional software assumptions. This survey argues that four properties of that layer (irreversibility, signing authority, continuous autonomy, and sequence-level composition) qualitatively change the threat model, turning the recoverable failures of generic agent security into a standing, irreversible loss. We organize the fragmented MCP-security literature into an attack-surface taxonomy, then contribute a Web3 risk-mapping matrix that ties each attack class to its amplified impact, the responsible amplifiers, a representative mitigation, and the residual gap. We synthesize defenses, including emerging blockchain-based mechanisms, and find them improving but insufficient: measured protections stop fewer than 30% of attacks, and model-level safety refuses fewer than 3%. We close by positioning the work against adjacent surveys and deriving a research agenda from the matrix's open cells.
发表机构
- University of Houston(休斯顿大学)
- PayPal AI Labs(PayPal人工智能实验室)
机构由 AI 辅助整理,请以论文原文为准。