arXiv:2608.24069cs.AIcs.CE2026-08

研究多智能体交易系统中攻击如何通过角色接口传播并导致损失

Poisoning Agentic Alpha: Adversarial Vulnerabilities Across Roles and Architectures in Multi-Agent Trading Systems

论文配图:Poisoning Agentic Alpha: Adversarial Vulnerabilities Across Roles and Architectures in Multi-Agent Trading Systems
图 1 · 摘自论文原文
  • 设计角色特异性攻击,仅操纵输入数据和提示
  • 发现所有架构均非天然抗攻击,信号可沿通信链传播
  • 适合关注AI交易安全的开发者与风控研究人员

基于大模型的多智能体交易系统正从研究走向真实资产部署。其智能体间结构化通信虽提升效率,却也带来安全隐患:恶意信号可传播至最终决策并造成实际金融损失。本文将攻击者限制在可实际接触的范围——智能体所接收的源数据和提示,构建低门槛、普适性的威胁模型。首次在金融领域系统性研究攻击信号如何渗入多智能体系统,并评估其在决策链中的存活程度。按功能分解为分析师、研究员、交易员、风险经理四角色,针对各接口设计匹配攻击;在四种通信拓扑下测试数据级与代理级攻击,使用对抗信号保留率(APS)作为分析工具。实验覆盖五种资产、两种骨干模型、两个目标方向。核心发现:无任一架构天生具备鲁棒性。研究成果为未来更安全的智能体交易系统设计提供关键启示。

原文摘要 · Abstract (English)

LLM-based multi-agent trading systems, in which specialized agents collaborate through structured communication to produce trading decisions, are moving rapidly from research prototypes to live deployments that control real assets. The same inter-agent communication that makes them effective also exposes them: a corrupted signal can propagate to the final decision and translate into realized financial loss. Unlike prior attacks that presume privileged access to system internals, we restrict the adversary to what is practically reachable---the source data and prompts agents consume---yielding a low-barrier, and thus democratized threat model instantiated as role-specific adversaries. We present the first systematic empirical study in the financial domain to characterize how an adversarial signal enters a multi-agent trading system and how far it survives toward the decision. Along the role axis, we decompose a widely-used trading pipeline into four functional roles---Analyst, Researcher, Trader, and Risk Manager---and pair each with an attack matched to its interface. Along the structural axis, we evaluate four communication topologies under data- and agent-level attacks, using the Adversarial Signal Preservation Score (APS) as a post-hoc lens on why some designs are more robust than others. We conduct experiments across five assets, two backbones, and two target directions. A central finding is that no architecture is inherently robust. These findings provide insights for the future design of safer and more robust agentic trading systems.

多智能体攻击防御交易系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。