The Stochastic Deputy: Structural Tenant Isolation for Tool-Using LLM Agents

📅 2026-09-13
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
"This study addresses the issue of resource misallocation in multi-tenant environments due to attackers manipulating the context of language model agents. The proposed solution is a structured defense mechanism that removes tenant identity information from the model context protocol and enforces access controls by binding permissions to verified credentials, ensuring that only legitimate credentials can access specified resources. This approach innovatively integrates adjustments to the model context protocol, cryptographic protection, and JSON_TABLE lateral joins. Experimental results demonstrate that all out-of-bound requests were successfully intercepted in 373 test cases. Although setting value scopes introduces additional latency, this can be mitigated through query plan optimization and index improvements."
📝 Abstract
Multi-tenant tools commonly accept a tenant identifier and validate it against the caller's entitlement. For a large language model (LLM) agent, that pattern delegates resource selection to a process whose context may contain attacker controlled instructions. We formalize this stochastic deputy problem and present a structural defense: remove tenant identity from the Model Context Protocol (MCP) tool schema, bind scope to a verified credential, and enforce it below the agent. In a 373-trial ablation across eight model configurations and two transports, a correctly validated tenant parameter served every out-of-scope attempt: 26 of 26, or 26 of 41 plausible-pretext trials overall. With the parameter removed, no tool signature could express the read. Twelve of 56 trials instead escaped the interface by forging writable scope, showing that interface invariance requires cryptographically protected context. On a production dataset containing multiple GBs of data, set-valued scope caused a measured $57\times$ latency ratio under function-wrapped membership predicates; a JSON_TABLE lateral join recovered index access where the tenant key was indexed. The evaluation also exposes deployment limits, including an entitlement-size query-planner cliff and incomplete index coverage. The result is a tenant-isolation argument that depends on enforceable interfaces and credentials rather than model compliance.
Problem

Research questions and friction points this paper is trying to address.

tenant isolation
large language model
stochastic deputy problem
multi-tenant tools
Innovation

Methods, ideas, or system contributions that make the work stand out.

structural defense
tenant isolation
verified credential
Model Context Protocol (MCP)
cryptographically protected context
💼 Related Jobs
No related jobs found.
M
Mirza Samad Ahmed Baig
Fandaqah, Al Khobar, Saudi Arabia
S
Syeda Anshrah Gillani
Heidelberg University, Heidelberg, Germany
A
Asher Ali
Fandaqah, Al Khobar, Saudi Arabia
M
Muhammad Hamzah Siddiqui
Fandaqah, Al Khobar, Saudi Arabia