ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems
ChainWatch:基于杀伤链的顺序检测框架,用于基于MCP的人工智能代理系统中的多步攻击
机构 * Computer Science New York University New York, USA(计算机科学 新 York 大学 新 York 美国) ; Cybersecurity University of Maryland, College Park MD, USA(网络安全 美国马里兰大学College Park分校 MD 美国) ; Carnegie Mellon University Pittsburgh, USA(卡内基梅隆大学 彭博 美国)
专题命中 工具调用 :agent(title,abstract);AI agent(title,abstract);分类 cs.AI
AI总结 针对基于MCP的人工智能代理系统中现有防御无法可靠检测多步攻击的问题,提出ChainWatch框架,用六阶段杀伤链建模攻击进展,结合隐马尔可夫模型分类工具调用序列,能检测逃避传统机制的攻击链。