Poisoning Agentic Alpha: Adversarial Vulnerabilities Across Roles and Architectures in Multi-Agent Trading Systems
cs.AI, cs.CE, cs.CR, cs.MA
Submitted: 2026-08-25
Updated: 2026-08-25
Code: https://github.com/cwna97/multi_agent_trading_attack
License: http://creativecommons.org/licenses/by/4.0/
The gist: LLM-based multi-agent trading systems, in which specialized agents collaborate through structured communication to produce trading decisions, are moving rapidly from research prototypes to live
Terminology
Abstract
LLM-based multi-agent trading systems, in which specialized agents collaborate through structured communication to produce trading decisions, are moving rapidly from research prototypes to live deployments that control real assets. The same inter-agent communication that makes them effective also exposes them: a corrupted signal can propagate to the final decision and translate into realized financial loss. Unlike prior attacks that presume privileged access to system internals, we restrict the adversary to what is practically reachable---the source data and prompts agents consume---yielding a low-barrier, and thus democratized threat model instantiated as role-specific adversaries. We present the first systematic empirical study in the financial domain to characterize how an adversarial signal enters a multi-agent trading system and how far it survives toward the decision. Along the role axis, we decompose a widely-used trading pipeline into four functional roles---Analyst, Researcher, Trader, and Risk Manager---and pair each with an attack matched to its interface. Along the structural axis, we evaluate four communication topologies under data- and agent-level attacks, using the Adversarial Signal Preservation Score (APS) as a post-hoc lens on why some designs are more robust than others. We conduct experiments across five assets, two backbones, and two target directions. A central finding is that no architecture is inherently robust. These findings provide insights for the future design of safer and more robust agentic trading systems.
Sources
- Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
- Learning to Conceal Risk: Controllable Multi-turn Red Teaming for LLMs in the Financial Domain
- Gemini: A Family of Highly Capable Multimodal Models
- Architecture Matters for Multi-Agent Security
- Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities
- Towards a Science of Scaling Agent Systems
- TradingGPT: Multi-Agent System with Layered Memory and Distinct Characters for Enhanced Financial Trading Performance
- AutoRedTrader: Autonomous Red Teaming of Trading Agents through Synthetic Misinformation Injection
- GPT-4 Technical Report
- Adversarial News and Lost Profits: Manipulating Headlines in LLM-Driven Algorithmic Trading
- BloombergGPT: A Large Language Model for Finance
- TradeTrap: Are LLM-based Trading Agents Truly Reliable and Faithful?
- FinVault: Benchmarking Financial Agent Safety in Execution-Grounded Environments
- NetSafe: Exploring the Topological Safety of Multi-agent Networks
- A Multimodal Foundation Agent for Financial Trading: Tool-Augmented, Diversified, and Generalist
- AlphaAgents: Large Language Model based Multi-Agents for Equity Portfolio Constructions
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection