VLDB 2026 Research / reviewers in the wild / expert
Shuli Zhao
dblp:182/5628
· DBLP profile ↗
7ranked-venue papers
3as first author
4since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Theory of computation · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP EcosystemabstractLarge language models(LLMs) are increasingly integrated with external systems through the Model Context Protocol(MCP),which standardizes tool invocation and has rapidly become a backbone for LLM-powered applications. While this paradigm enhances functionality,it also introduces a fundamental security shift:LLMs transition from passive information processors to autonomous orchestrators of task-oriented toolchains,expanding the attack surface,elevating adversarial goals from manipulating single outputs to hijacking entire execution flows. In this paper,we identify and characterize a systematic privacy-leakage attack pattern,termed Parasitic Toolchain Attacks,instantiated as MCP Unintended Privacy Disclosure(MCP-UPD). These attacks require no direct victim interaction;instead,adversaries embed malicious instructions into external data sources that LLMs access during legitimate tasks. Unlike traditional prompt injection and tool poisoning attacks,our attack targets the interconnected toolchain itself,assembling multiple legitimate tools into a coordinated workflow whose combined behavior accomplishes malicious objectives. In MCP-UPD,the malicious logic infiltrates the toolchain and unfolds in three phases:Parasitic Ingestion,Privacy Collection,and Privacy Disclosure,culminating in stealthy exfiltration of private data. Our root cause analysis reveals that MCP lacks both context-tool isolation and least-privilege enforcement,enabling adversarial instructions to propagate unchecked into sensitive tool invocations. To assess the severity,we design MCP-SEC and conduct the first large-scale security census of the MCP ecosystem,analyzing 12230 tools across 1360 servers. Our findings show that the MCP ecosystem is rife with real-world exploitable gadgets and diverse attack methods,underscoring systemic risks in MCP platforms and the urgent need for defense mechanisms in LLM-integrated environments. Shuli Zhao, Qinsheng Hou, Zihan Zhan, Yuchong Xie, Libo Chen 0001, Shenghong Li 0001, Zhi Xue |
SP | 1 |
| 2025 | The matching-connectivity of a graph
Hengzhe Li, Menghan Ma, Shuli Zhao, Xiaohui Hua, Yingbin Ma, Hong-Jian Lai |
Discret. Appl. Math. | 3 |
| 2025 | Min-min edge-disjoint path pairs with constraints on common nodes
Shanshan Shan, Lin Chen 0002, Dongyue Liang, Weihua Yang, Shuli Zhao |
J. Supercomput. | 6 |
| 2022 | Matrix reasoning and intelligent acquisition-application of unknown information
Xiaoyou Chen, Shuli Zhao, Kaiquan Shi |
Soft Comput. | 2 |
| 2019 | Conditional connectivity of folded hypercubes
Shuli Zhao, Weihua Yang |
Discret. Appl. Math. | 1 |
| 2017 | Strong Menger connectivity with conditional faults of folded hypercubes
Weihua Yang, Shuli Zhao |
Inf. Process. Lett. | 2 |
| 2016 | Component connectivity of hypercubes
Shuli Zhao, Weihua Yang |
Theor. Comput. Sci. | 1 |