arXiv:2601.13082cs.CRcs.LG2026-01中稿 · publication at the…被引 5

黑客用隐形文字骗大模型,让炒股系统亏17.7%年收益

Adversarial News and Lost Profits: Manipulating Headlines in LLM-Driven Algorithmic Trading

  • 用隐藏字符和同形字篡改新闻标题,骗过语言模型
  • 单日篡改可致年化收益下降17.7个百分点
  • 实测主流金融平台都可能被这类攻击影响

大型语言模型(LLMs)在金融领域应用日益广泛,其文本情感分析能力常被用于算法交易系统(ATS)的买卖决策。然而,攻击者可通过构造“对抗性新闻”误导模型——例如在新闻标题中加入人类无法察觉但模型能识别的恶意内容。现有研究虽关注文本对抗样本,但尚未量化其对基于LLM的算法交易系统的财务风险。本文研究一个无直接访问权限的对手,仅能修改单日股票相关新闻标题。我们测试两种人眼不可见的攻击方式:利用Unicode同形字干扰模型对股票名称的识别,以及嵌入隐藏文本改变新闻情感倾向。在Backtrader平台上构建融合LSTM价格预测与多款金融专用/通用大模型(FinBERT、FinGPT、FinLLaMA等)的仿真交易系统,通过组合投资回报率评估损失。实验基于14个月真实数据表明,仅一次日级攻击即可持续误导模型,使年化收益率下降最高达17.7个百分点。进一步调研27位金融科技从业者并分析主流爬虫工具与交易平台,验证了该攻击在现实中的可行性。研究结果已通知相关平台方。

原文摘要 · Abstract (English)

Large Language Models (LLMs) are increasingly adopted in the financial domain. Their exceptional capabilities to analyse textual data make them well-suited for inferring the sentiment of finance-related news. Such feedback can be leveraged by algorithmic trading systems (ATS) to guide buy/sell decisions. However, this practice bears the risk that a threat actor may craft "adversarial news" intended to mislead an LLM. In particular, the news headline may include "malicious" content that remains invisible to human readers but which is still ingested by the LLM. Although prior work has studied textual adversarial examples, their system-wide impact on LLM-supported ATS has not yet been quantified in terms of monetary risk. To address this threat, we consider an adversary with no direct access to an ATS but able to alter stock-related news headlines on a single day. We evaluate two human-imperceptible manipulations in a financial context: Unicode homoglyph substitutions that misroute models during stock-name recognition, and hidden-text clauses that alter the sentiment of the news headline. We implement a realistic ATS in Backtrader that fuses an LSTM-based price forecast with LLM-derived sentiment (FinBERT, FinGPT, FinLLaMA, and six general-purpose LLMs), and quantify monetary impact using portfolio metrics. Experiments on real-world data show that manipulating a one-day attack over 14 months can reliably mislead LLMs and reduce annual returns by up to 17.7 percentage points. To assess real-world feasibility, we analyze popular scraping libraries and trading platforms and survey 27 FinTech practitioners, confirming our hypotheses. We notified trading platform owners of this security issue.

大模型安全算法交易对抗攻击金融风控

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。