Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models
cs.CR, cs.AI, cs.CL
Submitted: 2026-04-22
Updated: 2026-08-31
Code: https://github.com/GraySwanAI/nanoGCG
Terminology
Sources
- Granite-Function Calling Model: Introducing Function Calling Abilities via Multi-task Learning of Granular Tasks
- AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents
- Small Language Models are the Future of Agentic AI
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Query-Based Adversarial Prompt Generation
- The Emerged Security and Privacy of LLM Agent: A Survey with Case Studies
- Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
- Mistral 7B
- Small Models, Big Tasks: An Exploratory Empirical Study on Small Language Models for Function Calling
- AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models
- Improving Small-Scale Large Language Models Function Calling for Reasoning Tasks
- GPT-4 Technical Report
- Gorilla: Large Language Model Connected with Massive APIs
- Qwen3 Technical Report
- Attack Atlas: A Practitioner's Perspective on Challenges and Pitfalls in Red Teaming GenAI
- Toolformer: Language Models Can Teach Themselves to Use Tools
- LLaMA: Open and Efficient Foundation Language Models
- Chain-of-Tools: Utilizing Massive Unseen Tools in the CoT Reasoning of Frozen Language Models
- The Dark Side of Function Calling: Pathways to Jailbreaking Large Language Models
- ReAct: Synergizing Reasoning and Acting in Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs