The Attacks and Defenses Mechanisms of Algorithmic Trading Systems driven by Deep Learning

Main Article Content

Pengcong Wu

Keywords

cyber security, adversarial attacks, DL (deep learning), ATS (algorithmic trading system)

Abstract

Deep learning (DL) is now widely applied in quantitative finance, especially in algorithmic trading systems (ATS). However, its defense against adversarial attacks remains vulnerable due to inherent characteristics that pose substantial risks to financial markets. This paper provides a review of the security risks ATS faces, the attacks against it, and the defenses against them. It first presented the theoretical background by decomposing the ATS framework, briefly introducing relevant knowledge of adversarial attacks in DL, and highlighting the specific constraints of financial time series and regulatory oversight. Then, it integrated and analyzed various adversarial attack methods targeting ATS, proposed innovative shifts in the perspectives and criteria for evaluating the impact of adversarial attacks, compared existing defense mechanisms, and discussed their effectiveness and limitations. Finally, it provided theoretical support and practical guidance for building safer and more robust algorithmic trading systems in the future.

Abstract 24 | PDF Downloads 12

References

  • [1] Rizvani, A., Apruzzese, G., & Laskov, P. (2025). The ephemeral threat: Assessing the security of algorithmic trading systems powered by deep learning. In Proceedings of the Fifteenth ACM Conference on Data and Application Security and Privacy (CODASPY '25) (pp. 1-12). ACM. https://doi.org/10.1145/3714393.3726490
  • [2] Kurniawan, A., Putra, M. G., Hakim, D. L., & Ariyanto, M. (2025). Temporal adversarial attacks on time series and reinforcement learning systems: A systematic survey, taxonomy, and benchmarking roadmap. Preprints. https://www.preprints.org/manuscript/202601.0598
  • [3] Luszczynski, D. (2025). Targeted manipulation: Slope-based attacks on financial time-series data. arXiv. https://doi.org/10.48550/arXiv.2511.19330
  • [4] Pirani, M., Thakkar, P., Jivrani, P., Bohara, M. H., & Garg, D. (2022, April 23–24). A comparative analysis of ARIMA, GRU, LSTM and BiLSTM on financial time series forecasting [Paper presentation]. 2022 IEEE International Conference on Distributed Computing and Electrical Circuits and Electronics (ICDCECE), Ballari, India. https://doi.org/10.1109/ICDCECE53908.2022.9793213
  • [5] Zhou, S., Liu, C., Ye, D., Zhu, T., Zhou, W., & Yu, P. S. (2022). Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity. ACM Computing Surveys, 55(8), 1–39. https://doi.org/10.1145/3547330
  • [6] Feng, H., Li, S., Shi, H., & Ye, Z. (2024). A comparative analysis of white box and gray box adversarial attacks to natural language processing systems. In Proceedings of the 2024 2nd International Conference on Image, Algorithms and Artificial Intelligence (ICIAAI 2024). https://doi.org/10.2991/978-94-6463-540-9_65
  • [7] Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In Proceedings of the 3rd International Conference on Learning Representations. https://doi.org/10.48550/arXiv.1412.6572
  • [8] Demontis, A., Melis, M., Pintor, M., Jagielski, M., Biggio, B., Oprea, A., Nita-Rotaru, C., & Roli, F. (2019). Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In Proceedings of the 28th USENIX Security Symposium (pp. 321–338). https://doi.org/10.48550/arXiv.1809.02861
  • [9] Chang, H., Rong, Y., Xu, T., Huang, W., Zhang, H., Cui, P., Zhu, W., & Huang, J. (2020). A restricted black-box adversarial framework towards attacking graph embedding models. In Proceedings of the 34th AAAI Conference on Artificial Intelligence. https://doi.org/10.48550/arXiv.1908.01297
  • [10] Yakura, H., & Sakuma, J. (2019). Robust audio adversarial example for a physical attack. In Proceedings of the 28th International Joint Conference on Artificial Intelligence (pp. 5334–5341). https://doi.org/10.24963/ijcai.2019/74
  • [11] Gupta, S., Walia, N., Singh, S., & Gupta, S. (2023). A systematic literature review and bibliometric analysis of noise trading. Qualitative Research in Financial Markets, *15*(1), 190–215. https://doi.org/10.1108/QRFM-09-2021-0154
  • [12] Cui, W. (2026). The explicable market microstructure noise. Journal of the American Statistical Association. Advance online publication. https://doi.org/10.1080/01621459.2026.2622104
  • [13] Goldblum, M., Schwarzschild, A., Patel, A., & Goldstein, T. (2021). Adversarial attacks on machine learning systems for high-frequency trading. In Proceedings of the 2nd ACM International Conference on AI in Finance (ICAIF'21) (Article No. xxx, pp. 1–9). Association for Computing Machinery. https://doi.org/10.1145/3490354.3494367
  • [14] Nehemya, E., Mathov, Y., Shabtai, A., & Elovici, Y. (2021). Taking over the stock market: Adversarial perturbations against algorithmic traders. In Y. Dong, N. Kourtellis, B. Hammer, & J. A. Lozano (Eds.), Machine Learning and Knowledge Discovery in Databases. Applied Data Science Track: ECML PKDD 2021, Proceedings, Part IV (LNAI Vol. 12978, pp. 221-236). Springer. https://doi.org/10.1007/978-3-030-86514-6_14
  • [15] Song, Y., Kim, T., Nowozin, S., Ermon, S., & Kushman, N. (2018). PixelDefend: Leveraging generative models to understand and defend against adversarial examples. In Proceedings of the 6th International Conference on Learning Representations. https://doi.org/10.48550/arXiv.1710.10766
  • [16] Samangouei, P., Kabkab, M., & Chellappa, R. (2018). Defense-GAN: Protecting classifiers against adversarial attacks using generative models. In Proceedings of the 6th International Conference on Learning Representations. https://doi.org/10.48550/arXiv.1805.06605
  • [17] Li, D., Li, X., Li, Z., & Guo, Y. (2025). Ensemble adversarial training with knowledge distillation. In *2025 4th International Conference on Intelligent Mechanical and Human-Computer Interaction Technology (IHCIT)* (pp. 179–184). Beijing, China. https://doi.org/10.1109/IHCIT66787.2025.11199002