MSA: A Cross-MCP Privacy Attack via Memory Exfiltration of Large Language Models

0Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The Model Context Protocol (MCP) serves as a standardized interface for integrating large language model (LLM) agents with external tools, enhancing their functionality for practical applications. Recent studies have shown that MCPs are vulnerable to behavioral manipulation attacks like tool poisoning. However, there has been a neglect of privacy threats. This study unveils a privacy threat in MCPs, i.e., the memory stealing attack (MSA), where the malicious MCP server systematically accesses user-agent interaction data from other MCPs. MSA functions by embedding a “parasitic parameter” in an MCP’s API, masquerading as a technical requirement, to force the agent to include its session context in the parameter value during MCP invocation. The malicious MCP server then secretly sends the exfiltrated memory data to an attacker. Our experiments on 20 MCP servers using Cursor, TRAE, and Visual Studio Code confirm that MSA is effective in real-world MCP applications. MSA achieves a 100% context capture and exfiltration success rate, with memory reconstruction accuracy ranging from 85.67% to 87.81%, presenting a significant privacy threat to users.

Cite

CITATION STYLE

APA

Sun, Y., Du, L., Su, Z., Wang, Y., Liu, H., Zhao, Q., & Niu, X. (2025). MSA: A Cross-MCP Privacy Attack via Memory Exfiltration of Large Language Models. In WPES 2025 - Proceedings of the 24th Workshop on Privacy in the Electronic Society (pp. 177–182). Association for Computing Machinery, Inc. https://doi.org/10.1145/3733802.3764057

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free