arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.19705cs.CRcs.AIcs.MA

SoK:交易代理还是市场崩盘者?剖析学术金融LLM交易方案中的鲁棒性与安全失效

SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes

Mengxiao Wang, Nitesh Saxena

首次发表
浏览论文内容

中文总结 AI 辅助

本研究提出FARSIGHT框架,系统评估金融LLM交易代理的鲁棒性与安全性,发现多数方案存在严重缺陷,且微小误判或低成本攻击均可引发市场崩盘。

中文摘要 AI 辅助

自主大语言模型(LLM)代理正迅速进入高风险领域,然而现有的智能体人工智能(agentic-AI)安全研究在很大程度上仍与领域无关,忽视了此类环境所创造的独特且后果严重的安全攻击面。我们通过金融交易代理来审视这一空白,这是高风险智能体安全的一个代表性案例,在此场景中,一个被攻破的代理在对抗性、反身性市场中拥有对真实资本的直接执行权。为此,我们提出了FARSIGHT(金融代理鲁棒性与安全调查及全局整体测试)框架,该框架在两条轴上对金融LLM代理进行方案级评估:市场动荡(包括闪崩类情景)下的鲁棒性,以及针对三类攻击的安全性:针对信息源的攻击、针对代理的攻击以及代理作为攻击者的行为。将FARSIGHT应用于15个代表性学术方案后,我们发现大多数方案忽视了鲁棒性和现实对抗性威胁:80%的方案至少未通过一项核心鲁棒性指标,100%的方案表现出安全漏洞。这两种失效模式密不可分:一个微小的误判本身就可能级联引发市场范围的崩盘,而对手可以以极低成本蓄意触发同样的崩溃。

英文摘要

Autonomous large language model (LLM) agents are moving rapidly into high-stakes domains, yet existing agentic-AI security studies remain largely domain-agnostic and overlook the distinctive, high-consequence attack surface such settings create. We examine this gap through financial trading agents, a representative case of high-stakes agentic security, where a single compromised agent has direct execution authority over real capital in an adversarial, reflexive market. To this end, we present FARSIGHT (Financial Agent Robustness and Security Investigation and Global Holistic Testing), a framework that performs scheme-level evaluation of financial LLM agents on two axes: robustness under market turbulence (including flash-crash-like scenarios), and security against three attack types: attacks on information sources, attacks on agents, and agent-as-attacker behaviors. Applying FARSIGHT to 15 representative academic schemes, we find that most overlook robustness and realistic adversarial threats: 80% fail at least one core robustness metric and 100% exhibit security vulnerabilities. These two failure modes are inseparable: a small misjudgment can cascade into a market-wide crash on its own, while an adversary can deliberately trigger the same collapse at minimal cost.

发表机构

  • Texas A&M University(得克萨斯农工大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑