Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
Huazhong University of Science and Technology
Abstract
The Model Context Protocol (MCP) is an emerging open standard that defines a unified, bi-directional communication and dynamic discovery protocol between AI models and external tools or resources, aiming to enhance interoperability and reduce fragmentation across diverse systems. This paper conducts a systematic study of MCP from both architectural and security perspectives. We first define the full lifecycle of an MCP server, comprising four phases (creation, deployment, operation, and maintenance), further decomposed into 16 key activities that capture its functional evolution. Building on this lifecycle analysis, we construct a comprehensive threat taxonomy that categorizes security and privacy risks across…
Citation impact
- FWCI
- 1038.07
- Percentile
- 100%
- References
- 27
Authors
4- XHXinyi HouCorresponding
Huazhong University of Science and Technology
- YZYanjie Zhao
Huazhong University of Science and Technology
- SWShenao Wang
Huazhong University of Science and Technology
- HWHaoyu Wang
Huazhong University of Science and Technology
Topics & keywords
- Interoperability
- Vulnerability (computing)
- Context (archaeology)
- Protocol (science)
- Fragmentation (computing)
- Vulnerability assessment
- System lifecycle
- Threat model