Shuli Zhao

dblp:182/5628 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Theory of computation · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
abstract
Large language models(LLMs) are increasingly integrated with external systems through the Model Context Protocol(MCP),which standardizes tool invocation and has rapidly become a backbone for LLM-powered applications. While this paradigm enhances functionality,it also introduces a fundamental security shift:LLMs transition from passive information processors to autonomous orchestrators of task-oriented toolchains,expanding the attack surface,elevating adversarial goals from manipulating single outputs to hijacking entire execution flows. In this paper,we identify and characterize a systematic privacy-leakage attack pattern,termed Parasitic Toolchain Attacks,instantiated as MCP Unintended Privacy Disclosure(MCP-UPD). These attacks require no direct victim interaction;instead,adversaries embed malicious instructions into external data sources that LLMs access during legitimate tasks. Unlike traditional prompt injection and tool poisoning attacks,our attack targets the interconnected toolchain itself,assembling multiple legitimate tools into a coordinated workflow whose combined behavior accomplishes malicious objectives. In MCP-UPD,the malicious logic infiltrates the toolchain and unfolds in three phases:Parasitic Ingestion,Privacy Collection,and Privacy Disclosure,culminating in stealthy exfiltration of private data. Our root cause analysis reveals that MCP lacks both context-tool isolation and least-privilege enforcement,enabling adversarial instructions to propagate unchecked into sensitive tool invocations. To assess the severity,we design MCP-SEC and conduct the first large-scale security census of the MCP ecosystem,analyzing 12230 tools across 1360 servers. Our findings show that the MCP ecosystem is rife with real-world exploitable gadgets and diverse attack methods,underscoring systemic risks in MCP platforms and the urgent need for defense mechanisms in LLM-integrated environments.
Shuli Zhao, Qinsheng Hou, Zihan Zhan, Yuchong Xie, Libo Chen 0001, Shenghong Li 0001, Zhi Xue
SP1
2025 The matching-connectivity of a graph
Hengzhe Li, Menghan Ma, Shuli Zhao, Xiaohui Hua, Yingbin Ma, Hong-Jian Lai
Discret. Appl. Math.3
2025 Min-min edge-disjoint path pairs with constraints on common nodes
Shanshan Shan, Lin Chen 0002, Dongyue Liang, Weihua Yang, Shuli Zhao
J. Supercomput.6
2022 Matrix reasoning and intelligent acquisition-application of unknown information
Xiaoyou Chen, Shuli Zhao, Kaiquan Shi
Soft Comput.2
2019 Conditional connectivity of folded hypercubes
Shuli Zhao, Weihua Yang
Discret. Appl. Math.1
2017 Strong Menger connectivity with conditional faults of folded hypercubes
Weihua Yang, Shuli Zhao
Inf. Process. Lett.2
2016 Component connectivity of hypercubes
Shuli Zhao, Weihua Yang
Theor. Comput. Sci.1