投毒智能体Alpha:多智能体交易系统中跨角色与架构的对抗性漏洞
Poisoning Agentic Alpha: Adversarial Vulnerabilities Across Roles and Architectures in Multi-Agent Trading Systems
- Sungkyunkwan University(成均馆大学)
- University College London(伦敦大学学院)
- University of Edinburgh(爱丁堡大学)
- University of Texas at Austin(德克萨斯大学奥斯汀分校)
- BlackRock, Inc.(贝莱德集团)
- Google(谷歌公司)
- University of Florida(佛罗里达大学)
- LinqAlpha
- UNIST(蔚山国家科学技术研究院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
该研究针对多智能体交易系统,将敌手限制为仅可访问源数据与提示,分解交易角色并评估通信拓扑,发现无架构具内在鲁棒性,为安全交易系统设计提供见解。
AI中文摘要:
基于大语言模型(LLM)的多智能体交易系统中,专用智能体通过结构化通信协作生成交易决策,正从研究原型快速向控制真实资产的实际部署推进。使这些系统有效的智能体间通信也暴露了它们:被篡改的信号可传播至最终决策,转化为实际财务损失。与假设能特权访问系统内部的现有攻击不同,我们将敌手限制在实际可触及的范围内——智能体使用的源数据和提示,形成了低门槛、因此大众化的威胁模型,实例化为角色特定的敌手。我们开展了金融领域首个系统的实证研究,以表征对抗性信号如何进入多智能体交易系统、以及其能在多大程度上留存至决策阶段。在角色维度,我们将广泛使用的交易流水线分解为四个功能角色——分析师(Analyst)、研究员(Researcher)、交易员(Trader)和风险经理(Risk Manager),并为每个角色匹配了与其接口适配的攻击。在结构维度,我们在数据级和智能体级攻击下评估四种通信拓扑,使用对抗性信号保留得分(Adversarial Signal Preservation Score, APS)作为事后视角,解释为何部分设计比其他设计更具鲁棒性。我们在五种资产、两种主干模型和两个目标方向上开展实验。核心发现是,没有任何架构具有内在鲁棒性。这些发现为未来设计更安全、更鲁棒的智能体交易系统提供了见解。
英文摘要:
LLM-based multi-agent trading systems, in which specialized agents collaborate through structured communication to produce trading decisions, are moving rapidly from research prototypes to live deployments that control real assets. The same inter-agent communication that makes them effective also exposes them: a corrupted signal can propagate to the final decision and translate into realized financial loss. Unlike prior attacks that presume privileged access to system internals, we restrict the adversary to what is practically reachable---the source data and prompts agents consume---yielding a low-barrier, and thus democratized threat model instantiated as role-specific adversaries. We present the first systematic empirical study in the financial domain to characterize how an adversarial signal enters a multi-agent trading system and how far it survives toward the decision. Along the role axis, we decompose a widely-used trading pipeline into four functional roles---Analyst, Researcher, Trader, and Risk Manager---and pair each with an attack matched to its interface. Along the structural axis, we evaluate four communication topologies under data- and agent-level attacks, using the Adversarial Signal Preservation Score (APS) as a post-hoc lens on why some designs are more robust than others. We conduct experiments across five assets, two backbones, and two target directions. A central finding is that no architecture is inherently robust. These findings provide insights for the future design of safer and more robust agentic trading systems.