发表机构
IBM Research(IBM研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出AEGIS,该组件借助LLM将MCP工具调用归一化为统一表示,结合Open Policy Agent与ContextForge AI Gateway,可防止跨异构MCP工具和模态的资源滥用。
AI 中文摘要
模型上下文协议(MCP)是一种开源JSON-RPC协议,它标准化了大型语言模型(LLM)如何通过被称为工具的程序化函数与外部系统交互。攻击者或恶意智能体可以利用这些MCP工具的某些模态来降低基于智能体的应用程序的整体服务质量,例如,智能体可能请求过大的搜索半径或过长的视频,从而使后端系统过载,可能导致性能下降或拒绝服务。包括文本、图像、视频和位置在内的每种模态都引入了不同的资源滥用向量,使得开发一致的缓解策略变得复杂。此外,多模态和跨域工具暴露了多样化的请求模式和参数,使得难以定义既具有通用性又足够精确以实施有意义资源约束的策略。在本文中,我们提出了AEGIS,这是一个策略实施组件,它使管理员能够针对异构MCP工具和模态定义细粒度的资源滥用防护措施。AEGIS利用大型语言模型的推理能力,将多样化的工具调用分析、分类并归一化为安全从业者可访问的统一、策略友好的表示形式。AEGIS与Open Policy Agent和ContextForge AI Gateway集成,在保持基于MCP的智能体生态系统灵活性的同时,检测并缓解滥用行为。
英文摘要
The Model Context Protocol (MCP) is an open source JSON-RPC protocol that standardizes how large language models (LLMs) interact with external systems through programmatic functions known as tools. Attackers or malicious agents can exploit certain modalities of these MCP tools to degrade the overall quality of service of agent-based applications. For example, an agent may request an excessively large search radius or very long videos, overloading backend systems and potentially causing slowdowns or denial-of-service. Each modality including text, images, video, and location introduces distinct vectors for resource abuse, complicating the development of consistent mitigation strategies. Moreover, multimodal and crossdomain tools expose diverse request schemas and parameters, making it difficult to define policies that are both generalizable and precise enough to enforce meaningful resource constraints. In this paper, we present AEGIS, a policy enforcement component that enables administrators to define fine-grained safeguards against resource abuse across heterogeneous MCP tools and modalities. AEGIS leverages the reasoning capabilities of large language models to analyze, categorize, and normalize diverse tool invocations into a unified, policy-friendly representation accessible to security practitioners. Integrated with the Open Policy Agent and the ContextForge AI Gateway, AEGIS detects and mitigates abusive behaviors while preserving the flexibility of MCP-based agent ecosystems.