May 2026Unreviewed
SecureMCP: A Policy-Enforced LLM Data Access Framework for AIoT Systems via Model Context Protocol
Wonbae Kim, Hee-Kyong Yoo
Abstract
The deployment of Large Language Model (LLM)-generated SQL queries in Artificial Intelligence of Things (AIoT) systems introduces critical security risks, as prompt injection attacks can manipulate LLMs into producing unauthorized queries that expose sensitive data or execute destructive operations. Existing NL2SQL research focuses on query accuracy, while MCP server implementations provide only SQL-level protections without fine-grained role-based access control. This paper proposes SecureMCP,
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{kim2026securemcpa,
title = {{SecureMCP: A Policy-Enforced LLM Data Access Framework for AIoT Systems via Model Context Protocol}},
author = {Wonbae Kim and Hee-Kyong Yoo},
year = {2026},
month = may,
eprint = {2605.05260},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.05260}
}