July 2026Unreviewed
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems
Om Narayan, Rashmi Jyoti, Ramkinker Singh
Abstract
The Model Context Protocol (MCP) is an open-source standard that allows AI agents to connect to external tools, databases, and services. While this connectivity enables powerful agent capabilities, it also introduces multi-step attacks that existing per-call defenses cannot reliably detect. Attackers can compose individually benign tool invocations into malicious sequences that evade isolated inspection. This paper presents ChainWatch, a sequential detection framework for identifying multi-step
Categories
Cite
@misc{narayan2026chainwatch,
title = {{ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems}},
author = {Om Narayan and Rashmi Jyoti and Ramkinker Singh},
year = {2026},
month = jul,
eprint = {2607.19432},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.19432}
}