Agent 与自动化 4.0 · 优秀 2026-09-17 · 论文

SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic...

FARSIGHT 框架从两条轴评估金融 LLM 交易 agent:市场动荡(含闪崩场景)下的鲁棒性,以及三类攻击面攻击信息源攻击 agent 本体agent 作为攻击者对 15 个代表性学术交易 agent 方案做 scheme 级评测:80% 至少挂掉一项核心鲁棒性指标,100% 存在安全漏洞作者强调两类失效不可分割:agent 的小误判可自行级联成全市场崩盘,攻击者也能以极低成本刻意触发同样的坍塌高风险领域里 agent 直接握有真实资本执行权,是 agentic security 的代表性场景(SoK,24 页)

打开原文回到归档

SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes

  • ID: d5d3f109
  • 原文链接: https://arxiv.org/abs/2609.19705
  • PDF: https://arxiv.org/pdf/2609.19705v1
  • 作者: Mengxiao Wang, Nitesh Saxena
  • 日期: 2026-09-17
  • 更新: 2026-09-17
  • 分类: agents
  • 来源类型: paper
  • 标签: llm-agent, agent-security, financial-agents, robustness, sok
  • 质量评分: 4/5
  • 抓取时间: 2026-09-19T04:21:30Z
  • arXiv 备注: 24 pages, 6 figures, 11 tables, 118 references. SoK paper. Evaluates 15 academic financial LLM trading agent schemes on robustness and security

中文导读

FARSIGHT 框架从两条轴评估金融 LLM 交易 agent:市场动荡(含闪崩场景)下的鲁棒性,以及三类攻击面攻击信息源攻击 agent 本体agent 作为攻击者对 15 个代表性学术交易 agent 方案做 scheme 级评测:80% 至少挂掉一项核心鲁棒性指标,100% 存在安全漏洞作者强调两类失效不可分割:agent 的小误判可自行级联成全市场崩盘,攻击者也能以极低成本刻意触发同样的坍塌高风险领域里 agent 直接握有真实资本执行权,是 agentic security 的代表性场景(SoK,24 页)

为什么值得关注

15 个学术金融交易 agent 全军覆没:80% 鲁棒性不达标,100% 有安全漏洞

关键信息

  • 论文标题:SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes
  • 作者:Mengxiao Wang, Nitesh Saxena
  • arXiv:https://arxiv.org/abs/2609.19705
  • 发布时间:2026-09-17
  • arXiv 分类:cs.CR, cs.AI, cs.MA
  • 关联标签:llm-agent, agent-security, financial-agents, robustness, sok

English Abstract

Autonomous large language model (LLM) agents are moving rapidly into high-stakes domains, yet existing agentic-AI security studies remain largely domain-agnostic and overlook the distinctive, high-consequence attack surface such settings create. We examine this gap through financial trading agents, a representative case of high-stakes agentic security, where a single compromised agent has direct execution authority over real capital in an adversarial, reflexive market. To this end, we present FARSIGHT (Financial Agent Robustness and Security Investigation and Global Holistic Testing), a framework that performs scheme-level evaluation of financial LLM agents on two axes: robustness under market turbulence (including flash-crash-like scenarios), and security against three attack types: attacks on information sources, attacks on agents, and agent-as-attacker behaviors. Applying FARSIGHT to 15 representative academic schemes, we find that most overlook robustness and realistic adversarial threats: 80% fail at least one core robustness metric and 100% exhibit security vulnerabilities. These two failure modes are inseparable: a small misjudgment can cascade into a market-wide crash on its own, while an adversary can deliberately trigger the same collapse at minimal cost.

English Summary

FARSIGHT is a framework for scheme-level evaluation of financial LLM agents along two axes: robustness under market turbulence (including flash-crash-like scenarios) and security against three attack types - attacks on information sources, attacks on agents, and agent-as-attacker behaviors. Applying it to 15 representative academic trading-agent schemes, the authors find 80% fail at least one core robustness metric and 100% exhibit security vulnerabilities. The two failure modes are inseparable: a small misjudgment can cascade into a market-wide crash on its own, and an adversary can deliberately trigger the same collapse at minimal cost. 24 pages, 6 figures, 11 tables; SoK paper (cs.CR, cs.AI, cs.MA).

Obsidian Notes

  • 内容由 opencli arxiv paper 拉取 arXiv 元数据与摘要生成。
  • 中文导读与价值判断均锚定在条目已有摘要、论文摘要、作者、日期与分类信息上;未补充论文摘要之外的实验细节。