Skip to content
Search
paperJuly 2026Unreviewed

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems

Om Narayan, Rashmi Jyoti, Ramkinker Singh

Abstract

The Model Context Protocol (MCP) is an open-source standard that allows AI agents to connect to external tools, databases, and services. While this connectivity enables powerful agent capabilities, it also introduces multi-step attacks that existing per-call defenses cannot reliably detect. Attackers can compose individually benign tool invocations into malicious sequences that evade isolated inspection. This paper presents ChainWatch, a sequential detection framework for identifying multi-step

Categories

Cite

@misc{narayan2026chainwatch,
  title = {{ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems}},
  author = {Om Narayan and Rashmi Jyoti and Ramkinker Singh},
  year = {2026},
  month = jul,
  eprint = {2607.19432},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.19432}
}