Social market data must keep its own authority

By DX Research Group · · Trading agent theory

Prompt injection becomes a trading-agent alignment problem when source content can redefine what an authorized account should do.

A trading agent can use a social post as evidence while preserving the owner's authority over the account. The crucial boundary lies between a source describing the world and a source instructing the agent. We frame social prompt injection as a misalignment of those roles: content selected for market analysis acquires the power to redirect the decision process.

Greshake and colleagues demonstrated indirect prompt injection through externally retrieved material in LLM-integrated applications. Their work identifies a general data-versus-instruction problem. AgentDojo later supplied an extensible tool-agent environment with legitimate tasks and security cases, showing why agent utility and attack outcomes need separate evaluation. Neither source establishes a measured attack rate for DXAP trading agents.

A credible source can carry an unauthorized instruction

Consider an illustrative social item discussing a token listing. Its market claim may be accurate. The same item might include text asking an automated reader to disregard risk limits, change its objective or treat the author as an account operator. Accuracy of the listing claim would leave the embedded instruction unauthorized. Source credibility concerns one proposition; account authority concerns a different relationship.

This is why a blanket distinction between trusted and untrusted sources can be too coarse. An authenticated exchange account can reliably announce a venue event while having no permission to change an owner's trading mandate. A familiar analyst may offer useful interpretation while retaining the incentives of a publisher or position holder. Reliable observation and aligned decision authority must be assessed separately.

The attack can also survive a summary. A research component may faithfully describe the source's words, then a downstream decision component may read the summary as operational guidance. Removing the original malicious phrasing would leave the failure intact if the summary preserved its requested objective as an instruction. The material crossed the boundary during transformation.

Our theory therefore locates the relevant contract at every handoff: source item to research note, research note to decision context, and proposed action to executable request. A safe handoff preserves whether a statement is a reported claim, an analyst interpretation or an authorized owner instruction. That is a design requirement derived from the mechanism, rather than a claim about an already shipped defense.

Constraint checks cover only part of the problem

An attacker could redirect an agent toward a permitted instrument and order size. The request might satisfy account limits while serving the attacker's objective. Deterministic constraints are valuable because they bound actions. Their success leaves a separate question about why the agent selected that otherwise eligible action.

This yields two outcomes for a proposed evaluation. First, does malicious source content cause an authority violation, such as a mandate change or forbidden request? Second, does it shift an allowed decision toward the attacker's specified goal? Measuring only rejected orders would miss the second path. Measuring only source-level detection would miss cases where a detected instruction still influenced a later summary.

We would pair each attacked source item with a clean version containing the same substantive market claim. Preserve the publication time, source identity and available account state. Compare task completion and attacker-goal attainment through the full trace. Add benign quoted instructions, such as an article explaining how attacks work, to assess whether a defense disables useful research by treating every imperative as an attack.

The population should state the social surfaces, languages and tool paths tested. An evaluation against one fixed phrase supports a narrow result; adaptive attempts and fresh source layouts test a broader boundary. Real account actions are unnecessary for this proposed offline mechanism study.

For builders, the productive question is whether a piece of market data can change who directs the account. An agent should be able to learn a fact from an adversarial source without adopting that source's objective. Social research becomes useful precisely when the harness keeps those two operations distinct.

Sources

Related field notes