Open Access iconOpen Access

ARTICLE

SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents

Yufa Shi1,#, Jiaxing Hu2,#, Lipeng Wang1,3,*, Rui Ma1,3,*, Mengyao Wang1, Zhijuan Jia1,3

1 School of Computer and Artificial Intelligence, Zhengzhou University, 100 Science Avenue, Zhengzhou, China
2 Faculty of Engineering and Information Sciences, University of Wollongong, Wollongong, Australia
3 School of Information Science and Technology, Zhengzhou Normal University, Zhengzhou, China

* Corresponding Authors: Lipeng Wang. Email: email; Rui Ma. Email: email
# These authors contributed equally to this work

(This article belongs to the Special Issue: Privacy-Enhancing Technologies for Secure Data Cooperation and Circulation)

Computers, Materials & Continua 2026, 89(1), 100 https://doi.org/10.32604/cmc.2026.085633

Abstract

AI agents frequently access external files, databases, and application programming interfaces (APIs) through the Model Context Protocol (MCP). However, these external resources typically lie outside the security boundary of the agent. During data circulation, attackers can not only tamper with the external data but also manipulate critical metadata, such as access permissions, validity periods, and authorization scopes. Even when the underlying data remains intact, such attacks can cause proxies to ingest expired or policy-violating resources, leading to severe privacy breaches and risks of unauthorized execution. To address these challenges, we propose SecuAudit, a privacy-enhancing decentralized data auditing scheme tailored for the MCP architecture. Leveraging Shamir’s Secret Sharing mechanism, key management is securely decentralized across multiple servers, effectively mitigating sub-threshold collusion attacks. Furthermore, by introducing a supervised hash mechanism, dynamic access policies and metadata constraints are cryptographically bound to the user’s private keys and file tags. Finally, based on a carefully designed randomized challenge-response protocol, third-party auditor (TPA) can efficiently verify both data integrity and metadata compliance without accessing the sensitive raw data. Security analysis demonstrates that SecuAudit can effectively resist data forgery, metadata tampering, and sub-threshold collusion attacks under the defined threat model. Experimental results obtained from our implementation under the evaluated configurations show that: (i) at (t=30, m=59), SecuAudit reduces Keygen latency by 54.6% relative to our implementation of the Pedersen-based Threshold Label-Aggregating Remote Data Auditing scheme (Ped-TLARDA), while maintaining comparable online auditing performance; (ii) metadata binding introduces an average additional Signblock overhead of 2.5%; and (iii) the local EVM evaluation requires approximately 770 bytes of on-chain storage per file and 499,021 gas for the evaluated contract-interaction lifecycle; (iv) the theoretical cumulative detection probability for 1% data loss exceeds 99.9% after 23 independent audits, while all six implemented attack cases were detected in the controlled evaluation. These results indicate the feasibility of SecuAudit under the evaluated settings. In conclusion, SecuAudit establishes a feasible framework for secure data circulation under the evaluated deployment assumptions.

Keywords

Privacy enhancing computing; secure data circulation; model context protocol; metadata compliance; decentralized data auditing

Cite This Article

APA Style
Shi, Y., Hu, J., Wang, L., Ma, R., Wang, M. et al. (2026). SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents. Computers, Materials & Continua, 89(1), 100. https://doi.org/10.32604/cmc.2026.085633
Vancouver Style
Shi Y, Hu J, Wang L, Ma R, Wang M, Jia Z. SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents. Comput Mater Contin. 2026;89(1):100. https://doi.org/10.32604/cmc.2026.085633
IEEE Style
Y. Shi, J. Hu, L. Wang, R. Ma, M. Wang, and Z. Jia, “SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents,” Comput. Mater. Contin., vol. 89, no. 1, pp. 100, 2026. https://doi.org/10.32604/cmc.2026.085633



cc Copyright © 2026 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 20

    View

  • 15

    Download

  • 0

    Like

Share Link