Contagion on the Trading Floor: How Adversarial Signals Spread in Multi-Agent Trading Systems
cs.AI
Submitted: 2026-09-17
Updated: 2026-09-17
Comments: Published in ECML PKDD 2026. 25 pages, including 7 pages of supplementary material
Journal ref: Machine Learning and Knowledge Discovery in Databases. Research Track, ECML PKDD 2026, LNCS 16946, Springer (2027) 206-223
DOI: 10.1007/978-3-032-37673-2_12
License: http://creativecommons.org/licenses/by/4.0/
The gist: Multi-agent trading systems built on large language models (LLMs) are beginning to appear in quantitative finance, yet their robustness to adversarial inputs is largely unknown.
Terminology
Abstract
Multi-agent trading systems built on large language models (LLMs) are beginning to appear in quantitative finance, yet their robustness to adversarial inputs is largely unknown. We study the vulnerability of LLM trading stacks to black-box, input-only attacks that enter solely via admissible social-media feeds. We introduce the Generic Multi-Agent Trading System (GMATS), a framework that captures modern multiagent trading architectures and instantiate a class of black-box poisoning attackers that treat an LLM as a post generator and inject budget-constrained, plausibly benign social-media content into the analyst's evidence stream. We define contagion metrics that trace how adversarial content propagates through the stack, including belief-shift scores at analyst and coordinator layers and attack-clean deltas on standard backtest metrics. Experiments on a safe offline benchmark with historical market and social data show that even simple input-only attackers can materially degrade risk-return profiles, sharply reducing Sharpe ratios. At the same time, we find that suitably designed multi-agent topologies and coordinator prompts can dampen adversarial shocks and improve average robustness under identical poisoning budgets.
Sources
- Exploring Sentiment Manipulation by LLM-Enabled Intelligent Trading Agents
- Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast
- Large Language Model based Multi-Agents: A Survey of Progress and Challenges
- Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
- CAMEL: Communicative Agents for "Mind" Exploration of Large Language Model Society
- Can LLM-based Financial Investing Strategies Outperform the Market in Long Run?
- Prompt Injection attack against LLM-integrated Applications
- TradingGroup: A Multi-Agent Trading System with Self-Reflection and Data-Synthesis
- AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
- TradingAgents: Multi-Agents LLM Financial Trading Framework
- QuantHarness: Price-Driven Multi-Agent LLMs for High-Frequency Trading
- Qwen2.5 Technical Report
- InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
- ContestTrade: A Multi-Agent Trading System Based on Internal Contest Mechanism
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection