TY - EJOU
AU - Shi, Yufa
AU - Hu, Jiaxing
AU - Wang, Lipeng
AU - Ma, Rui
AU - Wang, Mengyao
AU - Jia, Zhijuan
TI - SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents
T2 - Computers, Materials \& Continua
PY - 2026
VL - 89
IS - 1
SN - 1546-2226
AB - AI agents frequently access external files, databases, and application programming interfaces (APIs) through the Model Context Protocol (MCP). However, these external resources typically lie outside the security boundary of the agent. During data circulation, attackers can not only tamper with the external data but also manipulate critical metadata, such as access permissions, validity periods, and authorization scopes. Even when the underlying data remains intact, such attacks can cause proxies to ingest expired or policy-violating resources, leading to severe privacy breaches and risks of unauthorized execution. To address these challenges, we propose SecuAudit, a privacy-enhancing decentralized data auditing scheme tailored for the MCP architecture. Leveraging Shamir’s Secret Sharing mechanism, key management is securely decentralized across multiple servers, effectively mitigating sub-threshold collusion attacks. Furthermore, by introducing a supervised hash mechanism, dynamic access policies and metadata constraints are cryptographically bound to the user’s private keys and file tags. Finally, based on a carefully designed randomized challenge-response protocol, third-party auditor (TPA) can efficiently verify both data integrity and metadata compliance without accessing the sensitive raw data. Security analysis demonstrates that SecuAudit can effectively resist data forgery, metadata tampering, and sub-threshold collusion attacks under the defined threat model. Experimental results obtained from our implementation under the evaluated configurations show that: (i) at (t=30, m=59), SecuAudit reduces Keygen latency by 54.6% relative to our implementation of the Pedersen-based Threshold Label-Aggregating Remote Data Auditing scheme (Ped-TLARDA), while maintaining comparable online auditing performance; (ii) metadata binding introduces an average additional Signblock overhead of 2.5%; and (iii) the local EVM evaluation requires approximately 770 bytes of on-chain storage per file and 499,021 gas for the evaluated contract-interaction lifecycle; (iv) the theoretical cumulative detection probability for 1% data loss exceeds 99.9% after 23 independent audits, while all six implemented attack cases were detected in the controlled evaluation. These results indicate the feasibility of SecuAudit under the evaluated settings. In conclusion, SecuAudit establishes a feasible framework for secure data circulation under the evaluated deployment assumptions.
KW - Privacy enhancing computing; secure data circulation; model context protocol; metadata compliance; decentralized data auditing
DO - 10.32604/cmc.2026.085633