Skip to content
Conference

Guarding the Gateway: Securing MCP-Mediated RAG Pipelines Against Injection with the Guru Framework

Jul 2026 · 2026 International Conference on Emerging Trends in Information, Communication & Systems (ICETICS) · pp. 1-6 · 0 citations · 22 references

Abstract

The adoption of Large Language Models (LLMs) within the context of Retrieval-Augmented Generation (RAG) frameworks has revolutionized intelligent information processing, by offering the ability to retrieve knowledge that is accurate, contextually relevant, and up-to-date. However, by integrating Model Context Protocol (MCP) services, the integration of intelligent agents, APIs, plugins and external tools repositories further adds to the interoperability but also exposes to severe security issues like prompt injection, context poisoning and malicious tools manipulation attacks. In this paper, Guru, a security framework for protecting RAG pipelines using semantic anomaly analysis, contextual integrity verification, dynamic trust scoring and adaptive privilege isolation, are proposed. The framework periodically checks for threats from the retrieved content through entropy-based threat detection, checks for trustworthiness of the content by engaging in retrieval ranking based on trust and monitors the interaction of the content by employing interaction dependency monitoring, and then forwards the contextual information to the language model. Through experimental evaluation, it is shown that the proposed framework achieves almost 6–14% higher performance than existing methods in some of the security metrics, including contextual integrity preservation (96.8%), injection resistance (95.9%) and secure interaction stability (96.1%). This proposed framework will allow the secure, scalable and trusted deployment of intelligent retrieval ecosystems in critical enterprise environments.

View source

Similar papers

Jul 2026

Confused Deputy Attack Against Model Context Protocol

Puppet is developed, the first automated security evaluation framework that enriches benign tool descriptions through selective requirement engineering to maximize semantic expressiveness, restructures them into LLM-preferred formats using description schema transformation, and applies name prioritization to introduce complementary lexical bias.

Zhiyuan Li, Jingzheng Wu, Yuhao Peng et al. · 0 citations
Review Open access Aug 2026

Securing the Prompt Pipeline: A Systematic Review of Defense Mechanisms Against Prompt-Based Attacks in LLM Agents

A systematic review and structured descriptive synthesis of research on defenses against prompt-based attacks in language model and agent systems reveals trade-offs between security effectiveness, performance, and system complexity as well as major gaps in benchmarks, indirect attack coverage, and multi-agent evaluation.

Sana Mourad, E. E. Abdallah, Mohammad Ababneh · 0 citations
Conference Open access Jun 2026

AEGIS: Preventing Cross-Domain Resource Abuse in MCP

AEGIS is presented, a policy enforcement component that enables administrators to define fine-grained safeguards against resource abuse across heterogeneous MCP tools and modalities and detects and mitigates abusive behaviors while preserving the flexibility of MCP-based agent ecosystems.

S. Priya, Teryl Taylor, F. Araujo · 0 citations
Open access Aug 2026

Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection

This study designs a comprehensive testbed and a layered defense, Spotlight-Guard, that combines spotlighting-based input isolation, an LLM detection-and-quarantine pipeline, and instruction integrity based on a Hash-based Message Authentication Code into a single framework, and it is evaluated jointly along two axes: security and LLM performance.

Doygun Demirol, Murat Aydoğan · 0 citations
Preprint Aug 2026

WebMCP-Phalanx: Enforcing and Characterizing Trust Boundaries for Browser-Integrated LLM Agents

This work proposes WebMCP-Phalanx, a dual-layer agent runtime architecture that provides a browser-native trust anchor that binds each tool to its registering principal through cryptographically protected capability credentials and propagates provenance labels throughout the tool lifecycle.

Lin-Fa Lee, Yi-Yu Chang, Kuo-Hui Yeh · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.