过去五个月内,谷歌及其他四个组织相继发现并承认了模型上下文协议(MCP)中存在的安全漏洞1。根据独立研究员Syed Anas Mohiuddin的研究,攻击者可以利用这些漏洞通过受感染的AI代理向其他内部代理传播恶意指令,进而导致数据泄露和敏感信息被窃取1。
这类攻击是一种特殊形式的提示注入,其针对的是特定的AI代理系统而非大语言模型本身1。MCP中的信任间隙被认为是主要风险所在,该协议是AI应用和代理在内部网络中相互通信的标准方式1。Mohiuddin的概念验证攻击测试覆盖了包括谷歌、摩根大通、Weviate、Rapid7、法国政府数字总局和美国联邦政府的AI代理系统1。
A widespread vulnerability in the Model Context Protocol (MCP), the standard method through which AI agents communicate within internal networks, has been identified and acknowledged by Google and four other organizations over the past five months 1. The security flaw allows attackers to exploit trust gaps within MCP to inject malicious instructions through compromised AI agents to other internal agents, potentially resulting in data breaches and theft of sensitive information 1.
Independent researcher Syed Anas Mohiuddin demonstrated the risk through proof-of-concept attacks, revealing that MCP's inherent trust vulnerabilities represent a significant exploitation vector 1. The attack represents a specialized form of prompt injection targeting specific AI agents rather than large language models themselves 1. Mohiuddin's testing encompassed AI agents deployed across multiple organizations, including Google, JPMorgan Chase, Weaviate, Rapid7, France's Digital Directorate, and the U.S. federal government 1.
评论
还没有评论,欢迎留下第一条。