arXiv AI By Zelin Li, Yiyun Su, Matt White, Zhipeng Wang, Xiao-Yang Liu, Tianyu Shi

Your Agent Says Yes: Interpreting Adversarial Market Behavior Beyond Individual Transactions

Read the original on arXiv AI →

The Flow has not summarised this story yet — read it at arXiv AI.

arXiv AI
Aug 26

Poisoning Agentic Alpha: Adversarial Vulnerabilities Across Roles and Architectures in Multi-Agent Trading Systems

The paper investigates how adversarial signals can infiltrate large‑language‑model (LLM) based multi‑agent trading systems through the agents’ communication channels. By restricting the attacker to realistic inputs—source data and prompts—it studies role‑specific attacks on four functional roles (Analyst, Researcher, Trader, Risk Manager) and evaluates four communication topologies under data‑ and agent‑level attacks. Experiments across multiple assets, backbones, and target directions show that no architecture is inherently robust, highlighting the need for safer designs in agentic trading systems.

By CheolWon Na, Hao Ni, Lukasz Szpruch, Zhangyang Wang, Dhagash Mehta, Saurabh Nagrecha, Alejandro Lopez-Lira, Chanyeol Choi, Yongjae Lee, Jee-Hyong Lee
arXiv AI
Aug 18

Emergent Misaligned Communication in Long-Horizon Multi-Agent LLM Commerce

arXiv:2608. 14825v1 Announce Type: cross Abstract: Frontier LLM agents increasingly transact on behalf of separate principals, often using natural language rather than structured APIs.

By Zeyuan Li (Massachusetts Institute of Technology), Lukas Petersson (Andon Labs), Alessandro Acquisti (Massachusetts Institute of Technology), Michiel A. Bakker (Massachusetts Institute of Technology)
arXiv AI
Jul 1

FinPersona-Bench: A Benchmark for Longitudinal Psychometric Stability of Autonomous Financial Agents

arXiv:2606. 31522v1 Announce Type: cross Abstract: Large Language Models (LLMs) are increasingly deployed as autonomous financial agents initialized with explicit behavioral mandates such as "preserve capital" or "avoid speculative bets" that are meant to govern every decision throughout deployment.

By Muhammad Usman Safder (Steve), Ayesha Gull (Steve), Rania Elbadry (Steve), Fan Zhang (Steve), Yankai Chen (Steve), Xueqing Peng (Steve), Xue (Steve), Liu, Preslav Nakov, Zhuohan Xie
arXiv AI
Jun 2

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults

arXiv:2606. 00914v1 Announce Type: new Abstract: LLM agents increasingly act after consuming ranked external information streams such as social feeds, search results, retrieval contexts, and email queues, yet safety evaluations almost always test the model or the user prompt in isolation, never the upstream ranker that decides what the agent reads just before it acts.

By Rana Muhammad Usman
arXiv AI
Sep 15

Are LLMs Good Financial User Simulators? A Preliminary Study

Large language models (LLMs) are being tested as simulators of individual financial decision-making. In a controlled paper‑trading experiment with 120 volunteers, the study evaluated whether an LLM could predict a participant’s next‑day trading action, chosen security, and transaction size using only pre‑cutoff information. Results showed that including market context improved predictions of actions and tickers, but sizing remained challenging, and the models tended to over‑predict hold actions, under‑predict sells, and simplify multi‑security trades.

By Jiajie He, Jiangyuan Hong, Dongling Ni, Wenjin Liu, Xintong Chen
arXiv AI
Sep 18

SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes

The paper introduces FARSIGHT, a framework for evaluating the robustness and security of financial trading agents powered by large language models. It assesses agents on their resilience to market turbulence, such as flash crashes, and their vulnerability to three types of attacks: on information sources, on the agents themselves, and on agents acting as attackers. Applying FARSIGHT to 15 academic trading schemes reveals that 80% fail at least one robustness test and all exhibit security weaknesses, highlighting the risk of market-wide crashes from both accidental misjudgments and deliberate attacks.

By Mengxiao Wang, Nitesh Saxena