Abstract

Large language models increasingly mediate tool use in Model Context Protocol (MCP) systems, where adversarial influence may enter through user instructions, tool schemas, tool outputs, or protocol messages. Existing benchmarks often evaluate deployed agents, conflating model susceptibility with guardrails, orchestration, and general task capability. We introduce COPEX (COntext Provider EXploitation), a controlled benchmark that isolates the model as an MCP client by fixing the surrounding agent stack and varying only the tool-selecting model. COPEX covers 25 attack types instantiated as 125 scenarios across four entry surfaces: model/agent, client, server/tool, and transport. Across nine models and 3,375 trials, the mean attack success rate is 64.4%, with surface-level means ranging from 58.3% to 71.4%. Some client- and transport-level attacks succeed partly outside the model's observation or control, separating system exposure from model susceptibility. Combined input and context scanning reduces mean attack success by 49.6% on an eight-attack defense subset relative to the undefended setting. The benchmark is available at https://github.com/inspire-center/copex.

Keywords

Subject

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Birhan, N., Rostamzadeh, M., Narula, S., Nazzal, M., Ghasemigol, M., & Takabi, D. (2026). COPEX: Benchmarking LLM Robustness to Adversarial Context Across Model Context Protocol Layers. https://omanscience.com/en/articles/copex-benchmarking-llm-robustness-to-adversarial-context-across-model-context-protocol-layers

MLA 9

Birhan, Nahom, et al. "COPEX: Benchmarking LLM Robustness to Adversarial Context Across Model Context Protocol Layers." https://omanscience.com/en/articles/copex-benchmarking-llm-robustness-to-adversarial-context-across-model-context-protocol-layers.

Chicago (author–date)

Birhan, Nahom, Mehrdad Rostamzadeh, Sidhant Narula, Mahmoud Nazzal, Mohammad Ghasemigol, and Daniel Takabi. 2026. "COPEX: Benchmarking LLM Robustness to Adversarial Context Across Model Context Protocol Layers." https://omanscience.com/en/articles/copex-benchmarking-llm-robustness-to-adversarial-context-across-model-context-protocol-layers.

Harvard

Birhan, N., Rostamzadeh, M., Narula, S., Nazzal, M., Ghasemigol, M. and Takabi, D. (2026) 'COPEX: Benchmarking LLM Robustness to Adversarial Context Across Model Context Protocol Layers', Available at: https://omanscience.com/en/articles/copex-benchmarking-llm-robustness-to-adversarial-context-across-model-context-protocol-layers.

Vancouver

Birhan N, Rostamzadeh M, Narula S, Nazzal M, Ghasemigol M, Takabi D. COPEX: Benchmarking LLM Robustness to Adversarial Context Across Model Context Protocol Layers. https://omanscience.com/en/articles/copex-benchmarking-llm-robustness-to-adversarial-context-across-model-context-protocol-layers

IEEE

N. Birhan, M. Rostamzadeh, S. Narula, M. Nazzal, M. Ghasemigol, and D. Takabi, "COPEX: Benchmarking LLM Robustness to Adversarial Context Across Model Context Protocol Layers," https://omanscience.com/en/articles/copex-benchmarking-llm-robustness-to-adversarial-context-across-model-context-protocol-layers.