The Black Tuesday Attack: how to crash the stock market with adversarial examples to financial forecasting models
Thomas Hofweber, Jefrey Bergl, Ian Reyes, Amir Sadovnik
TL;DR
The paper addresses the risk that machine-learning based financial forecasting models could be manipulated via adversarial examples to trigger a self-fulfilling market crash. It introduces the Black Tuesday Attack, which realizess sparse, targeted perturbations to prices of manipulable stocks to steer a surrogate forecast toward predicting a steep index decline, with transferability enabling impact on deployed models. It discusses practical attack steps, feasibility, and potential defenses, concluding that while no defense is foolproof, adversarial training and detection warrant urgent exploration. The work highlights a neglected systemic risk to financial stability and corporate valuations, calling for collaboration among investors, firms, and regulators to develop robust defenses and risk mitigations.
Abstract
We investigate and defend the possibility of causing a stock market crash via small manipulations of individual stock values that together realize an adversarial example to financial forecasting models, causing these models to make the self-fulfilling prediction of a crash. Such a crash triggered by an adversarial example would likely be hard to detect, since the model's predictions would be accurate and the interventions that would cause it are minor. This possibility is a major risk to financial stability and an opportunity for hostile actors to cause great economic damage to an adversary. This threat also exists against individual stocks and the corresponding valuation of individual companies. We outline how such an attack might proceed, what its theoretical basis is, how it can be directed towards a whole economy or an individual company, and how one might defend against it. We conclude that this threat is vastly underappreciated and requires urgent research on how to defend against it.
