{"slug": "provenanceguard-source-aware-factuality-verification-for-mcp-based-llm-agents", "title": "ProvenanceGuard: Source-Aware Factuality Verification for MCP-Based LLM Agents", "summary": "Researchers introduce ProvenanceGuard, a source-aware verifier for LLM agents using the Model Context Protocol (MCP), achieving a block F1 of 0.802 and source accuracy of 0.858 on a 40-trace held-out medical-domain dataset, outperforming source-blind baselines by detecting cross-source conflation where claims are supported but attributed to the wrong source.", "body_md": "arXiv:2606.18037v2 Announce Type: replace\nAbstract: Tool-using LLM agents increasingly use the Model Context Protocol (MCP) to answer from heterogeneous evidence sources, including search, APIs, databases, clinical records, and formulary tools. Standard factuality metrics usually test whether an answer is supported by pooled evidence, missing a provenance-sensitive failure mode: a claim may be supported somewhere while being attributed to the wrong source. We call this cross-source conflation.\nWe introduce ProvenanceGuard, a source-aware verifier for MCP-grounded answers. It consumes captured MCP traces with stable tool IDs, source IDs, and raw outputs; decomposes answers into atomic claims; routes claims to source-specific evidence; checks support with NLI and a token-alignment proxy; compares stated attribution with the routed source; and returns per-claim verdicts plus an answer-level allow/block decision. Blocked answers can be repaired with retrieval-augmented answer revision and re-verified.\nWe evaluate on 281 medical-domain MCP-agent traces. A 266-trace adjudicated subset yields 2,325 LLM-assisted claim labels split by trace; 361 held-out labels are human-verified. On the 40-trace held-out split, ProvenanceGuard achieves block F1 0.802 and source accuracy 0.858 over 260 source-eligible claims, outperforming source-blind baselines that do not emit claim-to-source IDs. On a harder multi-source benchmark it reaches block F1 0.846, while source-plus-relation accuracy drops to 0.229, showing that exact source ownership remains difficult with semantically close sources. Repair-and-reverify resolves all blocked answers in the full trace set, often via conservative fallback. In 50 controlled clinical conflation probes, ProvenanceGuard detects all injected attribution swaps with no retained wrong attribution. These results show that source attribution is an independent axis for factuality verification in MCP-based agents.", "url": "https://wpnews.pro/news/provenanceguard-source-aware-factuality-verification-for-mcp-based-llm-agents", "canonical_source": "https://www.machinebrief.com/news/provenanceguard-source-aware-factuality-verification-for-mcp-tem4", "published_at": "2026-07-28 04:00:00+00:00", "updated_at": "2026-07-28 05:57:10.090900+00:00", "lang": "en", "topics": ["artificial-intelligence", "large-language-models", "ai-safety", "ai-research"], "entities": ["ProvenanceGuard", "Model Context Protocol", "arXiv"], "alternates": {"html": "https://wpnews.pro/news/provenanceguard-source-aware-factuality-verification-for-mcp-based-llm-agents", "markdown": "https://wpnews.pro/news/provenanceguard-source-aware-factuality-verification-for-mcp-based-llm-agents.md", "text": "https://wpnews.pro/news/provenanceguard-source-aware-factuality-verification-for-mcp-based-llm-agents.txt", "jsonld": "https://wpnews.pro/news/provenanceguard-source-aware-factuality-verification-for-mcp-based-llm-agents.jsonld"}}