英文标题:The Stochastic Deputy: Structural Tenant Isolation for Tool-Using LLM Agents
作者:Mirza Samad Ahmed Baig, Syeda Anshrah Gillani, Asher Ali, Muhammad Hamzah Siddiqui
arXiv ID:2609.14780 | 分类:cs.CR | 发表:2026-09-13
许可:CC-BY
摘要 多租户工具通常接受一个租户标识符,并依据调用方的授权对其进行校验。对于大语言模型(LLM)智能体而言,这种模式将资源选择委托给了一个其上下文可能包含攻击者可控指令的进程。我们将这一随机代理问题形式化,并提出一种结构性防御:从模型上下文协议(MCP)工具模式中移除租户身份,将作用域绑定到经过验证的凭证,并在智能体之下强制执行。在一项跨八种模型配置和两种传输方式的 {{PT_MATH_1}} 次试验消融中,一个被正确校验的租户参数放行了每一次越界尝试:{{PT_MATH_3}} 中的 {{PT_MATH_2}},即总体上 {{PT_MATH_5}} 次合理借口试验中的 {{PT_MATH_4
Multi-tenant tools commonly accept a tenant identifier and validate it against the caller's entitlement. For a large language model (LLM) agent, that pattern delegates resource selection to a process whose context may contain attacker controlled instructions. We formalize this stochastic deputy problem and present a structural defense: remove tenant identity from the Model Context Protocol (MCP) tool schema, bind scope to a verified credential, and enforce it below the agent. In a 373-trial ablation across eight model configurations and two transports, a correctly validated tenant parameter served every out-of-scope attempt: 26 of 26, or 26 of 41 plausible-pretext trials overall. With the parameter removed, no tool signature could express the read. Twelve of 56 trials instead escaped the interface by forging writable scope, showing that interface invariance requires cryptographically protected context. On a production dataset containing multiple GBs of data, set-valued scope caused a measured $57\times$ latency ratio under function-wrapped membership predicates; a JSON_TABLE lateral join recovered index access where the tenant key was indexed. The evaluation also exposes deployment limits, including an entitlement-size query-planner cliff and incomplete index coverage. The result is a tenant-isolation argument that depends on enforceable interfaces and credentials rather than model compliance.
查看完整双语翻译 →
正在跳转到翻译阅读页… 如果没有自动跳转,请点击这里。