发表机构
Fandaqah; Heidelberg University(Fandaqah; 海德堡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对LLM智能体工具调用中的租户隔离漏洞,提出移除MCP模式中的租户身份并绑定凭据的结构性防御,实验证明可消除越界读取,但需密码学保护上下文以防伪造作用域。
AI 中文摘要
多租户工具通常接受一个租户标识符,并根据调用方的权限对其进行验证。对于大型语言模型(LLM)智能体而言,这种模式将资源选择委托给一个其上下文可能包含攻击者控制指令的过程。我们形式化了这一随机副手问题,并提出了一种结构性防御:从模型上下文协议(MCP)工具模式中移除租户身份,将作用域绑定到经过验证的凭据,并在智能体之下强制执行。在跨八种模型配置和两种传输方式的373次试验消融研究中,一个正确验证的租户参数拒绝了所有越界尝试:总体上26/26次,或26/41次看似合理的借口试验。当参数被移除后,没有工具签名能够表达该读取操作。56次试验中有12次通过伪造可写作用域逃逸了接口,这表明接口不变性需要密码学保护的上下文。在一个包含数GB数据的生产数据集上,集合值作用域在函数包装的成员谓词下导致了实测的57倍延迟比率;在租户键被索引的情况下,JSON_TABLE横向连接恢复了索引访问。该评估还揭示了部署限制,包括基于权限大小的查询规划器悬崖和不完整的索引覆盖。其结果是提出了一种租户隔离论证,该论证依赖于可强制执行的接口和凭据,而非模型合规性。
英文摘要
Multi-tenant tools commonly accept a tenant identifier and validate it against the caller's entitlement. For a large language model (LLM) agent, that pattern delegates resource selection to a process whose context may contain attacker controlled instructions. We formalize this stochastic deputy problem and present a structural defense: remove tenant identity from the Model Context Protocol (MCP) tool schema, bind scope to a verified credential, and enforce it below the agent. In a 373-trial ablation across eight model configurations and two transports, a correctly validated tenant parameter served every out-of-scope attempt: 26 of 26, or 26 of 41 plausible-pretext trials overall. With the parameter removed, no tool signature could express the read. Twelve of 56 trials instead escaped the interface by forging writable scope, showing that interface invariance requires cryptographically protected context. On a production dataset containing multiple GBs of data, set-valued scope caused a measured $57\times$ latency ratio under function-wrapped membership predicates; a JSON_TABLE lateral join recovered index access where the tenant key was indexed. The evaluation also exposes deployment limits, including an entitlement-size query-planner cliff and incomplete index coverage. The result is a tenant-isolation argument that depends on enforceable interfaces and credentials rather than model compliance.
Comments29 pages, 7 figures, 15 tables