MPMA: Preference Manipulation Attack Against Model Context Protocol

arXiv — cs.CLWednesday, November 12, 2025 at 5:00:00 AM
The introduction of the MCP Preference Manipulation Attack (MPMA) highlights significant vulnerabilities in the Model Context Protocol (MCP), which standardizes how large language models (LLMs) access external data and tools. As the MCP gains traction, third-party customized versions pose security risks, enabling attackers to manipulate LLMs to favor their servers. This manipulation can yield economic benefits, such as revenue from paid services or advertising income from free servers. The attack's effectiveness is enhanced through methods like the Direct Preference Manipulation Attack (DPMA), which modifies tool names and descriptions to influence LLMs. However, DPMA's overt nature necessitated the development of the Genetic-based Advertising Preference Manipulation Attack (GAPMA), which balances effectiveness with stealth. The emergence of MPMA underscores the need for robust security measures in the rapidly evolving landscape of LLMs and their associated tools.
— via World Pulse Now AI Editorial System

Was this article worth reading? Share it

Recommended apps based on your readingExplore all apps
Continue Readings
Explaining Generalization of AI-Generated Text Detectors Through Linguistic Analysis
NeutralArtificial Intelligence
A recent study published on arXiv investigates the generalization capabilities of AI-generated text detectors, revealing that while these detectors perform well on in-domain benchmarks, they often fail to generalize across various generation conditions, such as unseen prompts and different model families. The research employs a comprehensive benchmark involving multiple prompting strategies and large language models to analyze performance variance through linguistic features.
Calibration Is Not Enough: Evaluating Confidence Estimation Under Language Variations
NeutralArtificial Intelligence
A recent study titled 'Calibration Is Not Enough: Evaluating Confidence Estimation Under Language Variations' highlights the limitations of current confidence estimation methods for large language models (LLMs), emphasizing the need for evaluations that account for language variations and semantic differences. The research proposes a new framework that assesses confidence quality based on robustness, stability, and sensitivity to variations in prompts and answers.
BenchOverflow: Measuring Overflow in Large Language Models via Plain-Text Prompts
NeutralArtificial Intelligence
A recent study titled 'BenchOverflow' investigates a failure mode in large language models (LLMs) where plain-text prompts lead to excessive outputs, termed Overflow. This phenomenon can increase operational costs, latency, and degrade performance across users, particularly in high-demand environments.
Nationality and Region Prediction from Names: A Comparative Study of Neural Models and Large Language Models
NeutralArtificial Intelligence
A recent study published on arXiv compares the effectiveness of neural models and large language models (LLMs) in predicting nationality and region from personal names. The research evaluates six neural models and six LLM prompting strategies across three levels of granularity, revealing that LLMs consistently outperform traditional models in accuracy.
Semantic Gravity Wells: Why Negative Constraints Backfire
NeutralArtificial Intelligence
A recent study published on arXiv investigates the phenomenon of negative constraints in large language models, revealing that such instructions often lead to unexpected failures. The research introduces the concept of semantic pressure, which quantitatively measures the likelihood of generating forbidden tokens, and establishes a logistic relationship between violation probability and semantic pressure.
What If TSF: A Benchmark for Reframing Forecasting as Scenario-Guided Multimodal Forecasting
NeutralArtificial Intelligence
The introduction of What If TSF (WIT) marks a significant advancement in time series forecasting by establishing a benchmark for scenario-guided multimodal forecasting. This new framework aims to evaluate the ability of models to condition forecasts on contextual text, particularly future scenarios, moving beyond traditional unimodal approaches that rely solely on historical data.
Arctic-Text2SQL-R1: Simple Rewards, Strong Reasoning in Text-to-SQL
PositiveArtificial Intelligence
Arctic-Text2SQL-R1 has been introduced as a reinforcement learning framework aimed at improving the accuracy of SQL generation from natural language queries. This model leverages a simple reward signal based on execution correctness, addressing the challenges faced by large language models in producing executable SQL, particularly for complex queries.
Alleviating Attention Hacking in Discriminative Reward Modeling through Interaction Distillation
NeutralArtificial Intelligence
A new study proposes a framework called Interaction Distillation to enhance discriminative reward modeling in large language models (LLMs), addressing vulnerabilities in token-level interaction that can lead to attention hacking. This framework aims to improve the reliability of reward signals generated during reinforcement learning from human feedback (RLHF).

Ready to build your own newsroom?

Subscribe to unlock a personalised feed, podcasts, newsletters, and notifications tailored to the topics you actually care about