Contagion on the Trading Floor: How Adversarial Signals Spread in Multi-Agent Trading Systems
arXiv:2609.19789 · doi:10.1007/978-3-032-37673-2_12
Abstract
Multi-agent trading systems built on large language models (LLMs) are beginning to appear in quantitative finance, yet their robustness to adversarial inputs is largely unknown. We study the vulnerability of LLM trading stacks to black-box, input-only attacks that enter solely via admissible social-media feeds. We introduce the Generic Multi-Agent Trading System (GMATS), a framework that captures modern multiagent trading architectures and instantiate a class of black-box poisoning attackers that treat an LLM as a post generator and inject budget-constrained, plausibly benign social-media content into the analyst's evidence stream. We define contagion metrics that trace how adversarial content propagates through the stack, including belief-shift scores at analyst and coordinator layers and attack-clean deltas on standard backtest metrics. Experiments on a safe offline benchmark with historical market and social data show that even simple input-only attackers can materially degrade risk-return profiles, sharply reducing Sharpe ratios. At the same time, we find that suitably designed multi-agent topologies and coordinator prompts can dampen adversarial shocks and improve average robustness under identical poisoning budgets.
Published in ECML PKDD 2026. 25 pages, including 7 pages of supplementary material
References in corpus (14)
- AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
- CAMEL: Communicative Agents for "Mind" Exploration of Large Language Model Society
- Prompt Injection attack against LLM-integrated Applications
- Large Language Model based Multi-Agents: A Survey of Progress and Challenges
- Disinformation Capabilities of Large Language Models
- Assessing Look-Ahead Bias in Stock Return Predictions Generated By GPT Sentiment Analysis
- TradingAgents: Multi-Agents LLM Financial Trading Framework
- InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
- Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast
- Can LLM-based Financial Investing Strategies Outperform the Market in Long Run?
- TradingGroup: A Multi-Agent Trading System with Self-Reflection and Data-Synthesis
- Exploring Sentiment Manipulation by LLM-Enabled Intelligent Trading Agents
- QuantHarness: Price-Driven Multi-Agent LLMs for High-Frequency Trading
- ContestTrade: A Multi-Agent Trading System Based on Internal Contest Mechanism