כתבה
arXiv cs.AI ·
הפקיד הסטוכסטי: הפרדה סטרוקטורלית של דיירים לכלי-עזר ל-LM
The Stochastic Deputy: Structural Tenant Isolation for Tool-Using LLM Agents
במאמר זה, המחברים מציגים פתרון לבעיה של הפרדה סטרוקטורלית של דיירים לכלי-עזר ל-LM, כדי למנוע התקפות על בחירת משאבים. הם מציעים להסיר זהות דייר מה-MCP כלי-עזר, ולקשור תחום למאמן מאומת.
תקציר מקורי באנגליתarXiv:2609.14780v1 Announce Type: cross Abstract: Multi-tenant tools commonly accept a tenant identifier and validate it against the caller's entitlement. For a large language model (LLM) agent, that pattern delegates resource selection to a process whose context may contain attacker controlled instructions. We formalize this stochastic deputy problem and present a structural defense: remove tenant identity from the Model Context Protocol (MCP) tool schema, bind scope to a verified credential, and enforce it below the agent. In a 373-trial ablation across eight model configurations and two transports, a correctly validated tenant parameter served every out-of-scope attempt: 26 of 26, or 26 of 41 plausible-pretext trials overall. With the parameter removed, no tool signature could express t
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית