about
Manipulating Headlines in LLM-Driven Algorithmic Trading (arxiv.org)
3 points by m-hodges 93 days ago | hide | past | pdf | 1 comment on HN

In plain words: A trading bot that reads headline mood and pairs it with price forecasts faced invisible tricks, like lookalike letters and hidden text, that fool AI but not people. Tampering with headlines on one day cut annual returns by up to 17.7 percentage points.

Abstract · Adversarial News and Lost Profits: Manipulating Headlines in LLM-Driven Algorithmic Trading

Large Language Models (LLMs) are increasingly adopted in the financial domain. Their exceptional capabilities to analyse textual data make them well-suited for inferring the sentiment of finance-related news. Such feedback can be leveraged by algorithmic trading systems (ATS) to guide buy/sell decisions. However, this practice bears the risk that a threat actor may craft "adversarial news" intended to mislead an LLM. In particular, the news headline may include "malicious" content that remains invisible to human readers but which is still ingested by the LLM. Although prior work has studied textual adversarial examples, their system-wide impact on LLM-supported ATS has not yet been quantified in terms of monetary risk. To address this threat, we consider an adversary with no direct access to an ATS but able to alter stock-related news headlines on a single day. We evaluate two human-imperceptible manipulations in a financial context: Unicode homoglyph substitutions that misroute models during stock-name recognition, and hidden-text clauses that alter the sentiment of the news headline. We implement a realistic ATS in Backtrader that fuses an LSTM-based price forecast with LLM-derived sentiment (FinBERT, FinGPT, FinLLaMA, and six general-purpose LLMs), and quantify monetary impact using portfolio metrics. Experiments on real-world data show that manipulating a one-day attack over 14 months can reliably mislead LLMs and reduce annual returns by up to 17.7 percentage points. To assess real-world feasibility, we analyze popular scraping libraries and trading platforms and survey 27 FinTech practitioners, confirming our hypotheses. We notified trading platform owners of this security issue.

Advije Rizvani, Giovanni Apruzzese, Pavel Laskov
arXiv:2601.13082 · cs.CR, cs.LG · submitted Jan 19, 2026
abstract · pdf · html · This work has been accepted for publication at the IEEE Conference on Secure and Trustworthy Machine Learning (SaTML). The final version will be available on IEEE Xplore

add comment on HN

Fascinating article. Does the algo take into account issues like latency, order fill reality, and other real-time, real-world market conditions?