The paper investigates how adversarial signals can infiltrate large‑language‑model (LLM) based multi‑agent trading systems through the agents’ communication channels. By restricting the attacker to realistic inputs—source data and prompts—it studies role‑specific attacks on four functional roles (Analyst, Researcher, Trader, Risk Manager) and evaluates four communication topologies under data‑ and agent‑level attacks. Experiments across multiple assets, backbones, and target directions show that no architecture is inherently robust, highlighting the need for safer designs in agentic trading systems.
By CheolWon Na, Hao Ni, Lukasz Szpruch, Zhangyang Wang, Dhagash Mehta, Saurabh Nagrecha, Alejandro Lopez-Lira, Chanyeol Choi, Yongjae Lee, Jee-Hyong Lee
The paper "SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes" introduces FARSIGHT, a framework that evaluates financial LLM agents on robustness to market turbulence and security against three attack types. Applying FARSIGHT to 15 academic schemes reveals that 80% fail at least one robustness metric and all exhibit security vulnerabilities, highlighting the risk that a single compromised agent can trigger market-wide crashes.
The paper introduces FARSIGHT, a framework for evaluating the robustness and security of financial trading agents powered by large language models. It assesses agents on their resilience to market turbulence, such as flash crashes, and their vulnerability to three types of attacks: on information sources, on the agents themselves, and on agents acting as attackers. Applying FARSIGHT to 15 academic trading schemes reveals that 80% fail at least one robustness test and all exhibit security weaknesses, highlighting the risk of market-wide crashes from both accidental misjudgments and deliberate attacks.
By Mengxiao Wang, Nitesh Saxena
The paper introduces Market Signal Injection (MSI), an attack that alters how market data is formatted or described—without changing its numerical values—to influence large language model (LLM) pricing agents. Experiments on nine open‑weight and three proprietary models in simulated duopoly and triopoly markets show that sentiment‑based formatting changes cause significant shifts in firm behavior, profits, and consumer surplus. The study also demonstrates that model susceptibility varies across families, that larger models are not always more robust, and that techniques such as input canonicalization and decision boundary anchoring can partially mitigate these attacks.
By Dohun Lee, Hyunwoo Park
arXiv:2605. 01133v3 Announce Type: replace-cross Abstract: Large language model (LLM)-powered multi-agent systems (MAS) enable agents to communicate and share information, achieving strong performance on complex tasks.
By Lingxi Zhang, Guangtao Zheng, Hanjie Chen
arXiv:2508. 16481v3 Announce Type: replace Abstract: Ensuring the safe use of agentic systems requires a thorough understanding of the range of malicious behaviors these systems may exhibit.
By Jonathan N\"other, Adish Singla, Goran Radanovic
arXiv:2606. 02946v1 Announce Type: new Abstract: Live streaming has emerged as a primary medium for social interaction and digital commerce, yet it is increasingly plagued by sophisticated risks.
By Yiran Qiao, Jing Chen, Jiaqi Xu, Yang Liu, Qiwei Zhong, Xiang Ao
As large language models (LLMs) are deployed in high-stakes domains, adversaries may poison training data to implant backdoors: hidden triggers that covertly manipulate model behavior at inference time. We ask whether a defender can recover such a trigger under realistic affordances, namely white-box access to the weights and knowledge of the behavior of concern, but no training data, no trusted reference model, no knowledge of the trigger, and no certainty that the model is poisoned.
arXiv:2609.38270v1 Announce Type: cross
Abstract: Advancing beyond traditional static scoring models, LLM-powered agentic recommender systems (LLM-ARS) instantiate users and items as autonomous agent...
By Yurong Hao, Wen Zhou, Guowei Guan, Tiantong Wu, Fuyao Zhang, Wei Yang Bryan Lim
arXiv:2606. 10525v1 Announce Type: cross Abstract: Indirect prompt injection poses a critical threat to LLM agents that interact with untrusted external data, yet automated attack methods--proven effective for jailbreaking--remain underexplored in realistic agentic settings.
By David Hofer, Edoardo Debenedetti, Florian Tram\`er
arXiv:2607. 26849v1 Announce Type: cross Abstract: As large language models (LLMs) are deployed in high-stakes domains, adversaries may poison training data to implant backdoors: hidden triggers that covertly manipulate model behavior at inference time.
By Anthony Hughes, Nicole Xing, Collin Francel, Andy Kim, Andrew Draganov
arXiv:2603. 21194v2 Announce Type: replace-cross Abstract: Multi-agent discussions have been widely adopted, motivating growing efforts to develop attacks that expose their vulnerabilities.
By Qiuchi Xiang, Haoxuan Qu, Hossein Rahmani, Jun Liu