Skip to main navigation Skip to search Skip to main content

MPMA: Preference Manipulation Attack Against Model Context Protocol

  • Zihan Wang*
  • , Rui Zhang*
  • , Yu Liu
  • , Wenshu Fan
  • , Wenbo Jiang
  • , Qingchuan Zhao
  • , Hongwei Li
  • , Guowen Xu*
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Model Context Protocol (MCP) standardizes interface mapping for large language models (LLMs) to access external data and tools, which revolutionizes the paradigm of tool selection and facilitates the rapid expansion of the LLM agent tool ecosystem. However, as the MCP is increasingly adopted, third-party customized versions of the MCP server expose potential security vulnerabilities. In this paper, we first introduce a novel security threat, which we term the MCP Preference Manipulation Attack (MPMA). An attacker deploys a customized MCP server to manipulate LLMs, causing them to prioritize it over other competing MCP servers. This can result in economic benefits for attackers, such as revenue from paid MCP services or advertising income generated from free servers. To achieve MPMA, we first design a Direct Preference Manipulation Attack (DPMA) that achieves significant effectiveness by inserting the manipulative words and phrases into the tool name and description. However, such a direct modification is obvious to users and lacks stealthiness. To address these limitations, we further propose Genetic-based Advertising Preference Manipulation Attack (GAPMA). GAPMA employs four commonly used strategies to initialize descriptions and integrates a Genetic Algorithm (GA) to enhance stealthiness. The experimental results demonstrate that GAPMA balances high effectiveness and stealthiness. Our study reveals a critical vulnerability of the MCP in open ecosystems, highlighting an urgent need for robust defense mechanisms to ensure the fairness of the MCP ecosystem. © 2026, Association for the Advancement of Artificial Intelligence (www.aaai.org). All rights reserved.
Original languageEnglish
Title of host publicationProceedings of the 40th Annual AAAI Conference on Artificial Intelligence
PublisherAAAI Press
Pages35838-35846
ISBN (Print)9781577359067
DOIs
Publication statusPublished - 2026
Event40th Annual AAAI Conference on Artificial Intelligence (AAAI 2026) - Singapore EXPO, Singapore, Singapore
Duration: 20 Jan 202627 Jan 2026
https://aaai.org/conference/aaai/aaai-26/

Publication series

NameProceedings of the AAAI Conference on Artificial Intelligence
Number42
Volume40
ISSN (Print)2159-5399
ISSN (Electronic)2374-3468

Conference

Conference40th Annual AAAI Conference on Artificial Intelligence (AAAI 2026)
Abbreviated titleAAAI-26
PlaceSingapore
CitySingapore
Period20/01/2627/01/26
Internet address

Bibliographical note

Full text of this publication does not contain sufficient affiliation information. With consent from the author(s) concerned, the Research Unit(s) information for this record is based on the existing academic department affiliation of the author(s).

Funding

This work is supported by the Sichuan Science and Technology Program under Grant 2024ZHCG0188.

Fingerprint

Dive into the research topics of 'MPMA: Preference Manipulation Attack Against Model Context Protocol'. Together they form a unique fingerprint.

Cite this