Adversarial Attacks Threaten Multi-Agent LLM Trading Systems.

CheolWon Na, Hao Ni, Lukasz Szpruch, Zhangyang Wang, Dhagash Mehta, Saurabh Nagrecha, Alejandro Lopez-Lira, Chanyeol Choi, Yongjae Lee, Jee-Hyong Lee· August 26, 2026 View original

Key takeaways

  • Multi-agent LLM trading systems are vulnerable to adversarial attacks via poisoned inputs.
  • Corrupted signals can propagate through inter-agent communication, causing financial loss.
  • No single architectural design is inherently robust against these threats.
  • Security measures must address role-specific vulnerabilities and communication topologies.

Who benefits

BFSIFinTechCybersecurityAI Development

Summary

This study reveals how adversarial signals can exploit inter-agent communication in LLM-based multi-agent trading systems, leading to financial losses. It systematically investigates vulnerabilities across different agent roles and communication architectures, finding no inherently robust design.

Multi-agent trading systems powered by Large Language Models (LLMs) are becoming increasingly sophisticated, with specialized agents collaborating through structured communication to make trading decisions. While this collaboration enhances effectiveness, it also introduces significant vulnerabilities. This research demonstrates that corrupted signals, introduced through accessible means like source data or agent prompts, can propagate through the system and result in real financial losses. The study is the first to empirically analyze how adversarial signals infiltrate these systems and their impact on final decisions within the financial domain. It decomposes a typical trading pipeline into roles like Analyst, Researcher, Trader, and Risk Manager, applying role-specific attacks. Furthermore, it evaluates four communication topologies under data and agent-level attacks, using a novel "Adversarial Signal Preservation Score" to understand design robustness. A key finding is that no single architecture is inherently immune to these threats, providing crucial insights for developing more secure agentic trading systems.

Why it matters

Financial institutions and anyone deploying LLM-based multi-agent systems must understand and mitigate the significant security risks posed by adversarial attacks that can lead to direct financial losses.

How to implement this in your domain

  1. 1Conduct thorough security audits of existing or planned multi-agent LLM trading systems.
  2. 2Implement robust input validation and sanitization mechanisms for all data consumed by agents.
  3. 3Develop and deploy monitoring systems to detect anomalous inter-agent communication patterns.
  4. 4Design agent architectures with redundancy and cross-verification steps to limit signal propagation.
  5. 5Train agents with adversarial examples to improve their resilience against poisoned inputs.

Original post by CheolWon Na, Hao Ni, Lukasz Szpruch, Zhangyang Wang, Dhagash Mehta, Saurabh Nagrecha, Alejandro Lopez-Lira, Chanyeol Choi, Yongjae Lee, Jee-Hyong Lee

"arXiv:2608.24069v1 Announce Type: new Abstract: LLM-based multi-agent trading systems, in which specialized agents collaborate through structured communication to produce trading decisions, are moving rapidly from research prototypes to live deployments that control real assets.…"

View on X

Originally posted by CheolWon Na, Hao Ni, Lukasz Szpruch, Zhangyang Wang, Dhagash Mehta, Saurabh Nagrecha, Alejandro Lopez-Lira, Chanyeol Choi, Yongjae Lee, Jee-Hyong Lee on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses