{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:AW4MVA4KKM5ZWT7FWPOL4X7Q22","short_pith_number":"pith:AW4MVA4K","schema_version":"1.0","canonical_sha256":"05b8ca838a533b9b4fe5b3dcbe5ff0d6ac4f8151f64450da1be17324f93fc381","source":{"kind":"arxiv","id":"2603.07473","version":2},"attestation_state":"computed","paper":{"title":"Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Biwei Yan, Boyang Ma, Kaidi Xu, Minghui Xu, Xuelong Dai, Yechao Zhang, Yue Zhang, Yuhang Huang","submitted_at":"2026-03-08T05:24:16Z","abstract_excerpt":"The Model Context Protocol (MCP) is an open and standardized interface that enables large language models (LLMs) to interact with external tools and services, and is increasingly adopted by AI agents. However, the security of MCP-based systems remains largely unexplored.In this work, we conduct a large-scale security analysis of MCP servers integrated within MCP clients. We show that treating MCP servers as trusted entities without authenticating the caller identity is fundamentally insecure. Since MCP servers often cannot distinguish who is invoking a request, a single authorization decision "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2603.07473","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-08T05:24:16Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"1791396c6944095eec82f38f3e1b7d7e87302c542d8b85a74eedf4cca0393153","abstract_canon_sha256":"671172e18e6519ffefff4d5772b405289e6f418a76aba555f7cf7c68cd59ec67"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-22T01:22:21.421864Z","signature_b64":"+R5kjilSIKecTmKFzrY8pRw9jERp6K8NQ3ZQQFwVci0Gr/c8ZWPwas69M/cq9lS9dT//cRxATFaOrRft1sm6Bw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"05b8ca838a533b9b4fe5b3dcbe5ff0d6ac4f8151f64450da1be17324f93fc381","last_reissued_at":"2026-07-22T01:22:21.420939Z","signature_status":"signed_v1","first_computed_at":"2026-07-22T01:22:21.420939Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Biwei Yan, Boyang Ma, Kaidi Xu, Minghui Xu, Xuelong Dai, Yechao Zhang, Yue Zhang, Yuhang Huang","submitted_at":"2026-03-08T05:24:16Z","abstract_excerpt":"The Model Context Protocol (MCP) is an open and standardized interface that enables large language models (LLMs) to interact with external tools and services, and is increasingly adopted by AI agents. However, the security of MCP-based systems remains largely unexplored.In this work, we conduct a large-scale security analysis of MCP servers integrated within MCP clients. We show that treating MCP servers as trusted entities without authenticating the caller identity is fundamentally insecure. Since MCP servers often cannot distinguish who is invoking a request, a single authorization decision "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.07473","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2603.07473/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2603.07473","created_at":"2026-07-22T01:22:21.421384+00:00"},{"alias_kind":"arxiv_version","alias_value":"2603.07473v2","created_at":"2026-07-22T01:22:21.421384+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.07473","created_at":"2026-07-22T01:22:21.421384+00:00"},{"alias_kind":"pith_short_12","alias_value":"AW4MVA4KKM5Z","created_at":"2026-07-22T01:22:21.421384+00:00"},{"alias_kind":"pith_short_16","alias_value":"AW4MVA4KKM5ZWT7F","created_at":"2026-07-22T01:22:21.421384+00:00"},{"alias_kind":"pith_short_8","alias_value":"AW4MVA4K","created_at":"2026-07-22T01:22:21.421384+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2605.22333","citing_title":"A First Measurement Study on Authentication Security in Real-World Remote MCP Servers","ref_index":22,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22","json":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22.json","graph_json":"https://pith.science/api/pith-number/AW4MVA4KKM5ZWT7FWPOL4X7Q22/graph.json","events_json":"https://pith.science/api/pith-number/AW4MVA4KKM5ZWT7FWPOL4X7Q22/events.json","paper":"https://pith.science/paper/AW4MVA4K"},"agent_actions":{"view_html":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22","download_json":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22.json","view_paper":"https://pith.science/paper/AW4MVA4K","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2603.07473&json=true","fetch_graph":"https://pith.science/api/pith-number/AW4MVA4KKM5ZWT7FWPOL4X7Q22/graph.json","fetch_events":"https://pith.science/api/pith-number/AW4MVA4KKM5ZWT7FWPOL4X7Q22/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22/action/timestamp_anchor","attest_storage":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22/action/storage_attestation","attest_author":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22/action/author_attestation","sign_citation":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22/action/citation_signature","submit_replication":"https://pith.science/pith/AW4MVA4KKM5ZWT7FWPOL4X7Q22/action/replication_record"}},"created_at":"2026-07-22T01:22:21.421384+00:00","updated_at":"2026-07-22T01:22:21.421384+00:00"}