论文

用 MCP 网关让医疗 AI Agent 安全读取设备数据

A Safety-Bounded SDC-to-MCP Gateway for Medical AI Agents

精选理由

论文做了一个把医疗设备接入 MCP 的安全网关,Agent 只能读数据和模拟操作,代码不会真的控制设备,做医疗 AI 的可以看看。

论文提出一个 IEEE 11073 SDC 到 MCP 的网关,把医疗设备的指标、报警和语义元数据以只读资源形式暴露给语言模型 Agent。选定的操作能力以策略校验的 dry-run 工具呈现,Agent 侧请求不会真正触发 SDC 设备操作,形成无执行边界。Python 原型覆盖了模拟故障、生命周期实验以及独立的 Java 与 Python 协议实现路径。实验显示语义元数据提升了报警输出中指标标识符的合规度,同时暴露了结构化输出失败与叙述性答案之间的差距。

原文 · arXiv cs.AI

A Safety-Bounded SDC-to-MCP Gateway for Medical AI Agents

The Model Context Protocol (MCP) provides a common interface through which AI applications discover and use external resources and tools. It allows language-model agents to ground their reasoning in current system state and interact with heterogeneous services. In medical environments, however, exposing device state and action affordances requires deterministic constraints on possible effects. We present an IEEE 11073 Service-Oriented Device Connectivity (SDC)-to-MCP gateway that exposes metrics, alarms, context references, and semantic metadata as read-only resources, while representing selected action affordances as policy-validated dry-run tools. The term safety-bounded denotes a narrow no-execution property: agent-facing requests dispatch no SDC device operation. A Python prototype supports simulated fault and lifecycle experiments, a software-reference protocol path spanning independent Java and Python implementations, deterministic baselines, representation ablations, and multi-model agent evaluation. The results show semantically explicit resource exposure, visible rejection of invalid or outdated state, and preservation of the no-execution boundary across resource, proposal, and authorization paths. Explicit semantic metadata improved conformity to required metric identifiers in structured alarm outputs relative to a generic representation, while retained structured-output failures reveal a distinction between plausible narrative answers and task-compliant machine-readable results.