← Back to search
paper llmsec-2026-00071
MCPShield: Content-Aware Attack Detection for LLM Agent Tool-Call Traffic
Sultan Zavrak
2026-05
Abstract
The Model Context Protocol (MCP) has become a widely adopted interface for LLM agents to invoke external tools, yet learned monitoring of MCP tool-call traffic remains underexplored. In this article, MCPShield is presented as an attack detection framework for MCP tool-call traffic that encodes each agent session as a graph (tool calls as nodes, sequential and data-flow links as edges), enriches nodes with sentence-embedding features over arguments and responses, and classifies sessions as benign
Categories
Cite This Resource
@article{llmsec202600071,
title = {MCPShield: Content-Aware Attack Detection for LLM Agent Tool-Call Traffic},
author = {Sultan Zavrak},
year = {2026},
url = {https://arxiv.org/abs/2605.11053},
} Metadata
- Added
- 2026-05-17
- Added by
- automation
- Source
- arxiv
- arxiv_id
- 2605.11053