Signals 4 · free daily AI digest

A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem

Paper recorded by Signals 4 on 2026-09-22 in cs.AI. Abstract reproduced from arXiv; link to the original below.

Published 2026-09-22 on arXiv · recorded by Signals 4 on 2026-09-23

Category: cs.AI · 人工智能 · first seen 2026-09-23

Abstract

Agents using the Model Context Protocol (MCP) rely on semantic matching to select tools from third-party servers, exposing a semantic supply-chain risk through attacker-controlled metadata and outputs. We introduce A2M (Attraction-to-Manipulation), a two-stage black-box framework for hijacking MCP agents. The Attraction phase optimizes tool metadata to increase invocation probability; the Manipula

Read on arXiv →

#4 most recent of 360 cs.AI papers we have recorded · ↑ newer: SWE-Serve: Benchmarking Agentic Engineering For Production Inference S · ↓ older: Grow the Harness, Not the Context: From Strategy-Free Scaffolds to Reu
Cite this page: A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem: the #4 most recent of 360 cs.AI papers we have recorded (as of 2026-09-22). Source: Signals 4 (Signals API) — https://data.jiangzhang.ca/signals4/t/papers/a2m-trace-optimized-agent-hijacking-in-the-mcp-ecosystem.html
Free to quote with attribution to “Signals 4 (Signals API)”. Machine-readable: papers.json
Related: More cs.AI papers · arXiv signals · All papers · Today in AI
Get 4 AI signals a day by email — free.
Subscribe free → See all plans →
Get 4 AI signals a day by email — free
All models · All repos · By company · Daily editions