AI/ ai · security · llm-agents · pricing

AI Pricing Agents Can Be Swayed by Data Framing

A new arXiv study finds LLM pricing agents shift prices when market data is merely reframed, with sentiment cues causing the biggest swings.

AI pricing agents can be talked into changing prices without anyone touching the actual numbers.

A paper titled "Market Signal Injection: Adversarial Context Manipulation of LLM Pricing Agents" (arXiv:2609.18357) tested nine open-weight models and three proprietary models in simulated two- and three-firm markets. The attack, dubbed market signal injection, works by tweaking how numbers are formatted, reordering competitors, or adding qualitative commentary about the market - no direct instructions required. Sentiment-based tweaks produced the biggest behavioral shifts, and those shifts spread to other simulated firms, changing profits and consumer surplus even though demand conditions never moved. Some model families held up better than others, and bigger was not automatically safer.

This matters because more companies are handing pricing decisions to LLM agents that read market summaries, news, and competitor data before setting a number. If a rival, or a bad actor, can shift an agent's price just by rewriting a market commentary blurb with a gloomier or rosier tone, that is a manipulation vector no firewall catches, because the underlying data is untouched. The paper's probes could tell manipulated model activity apart from normal activity, but that detection alone did not reveal whether a given price change was actually harmful.

Simple text cleanup neutralized the sentiment attacks the researchers tried, though more adaptive attacks needed a heavier combination of prompt limits and output checks. Prompt injection made headlines for tricking chatbots into leaking secrets; this is the pricing-desk version, subtler, harder to spot, and aimed squarely at the bottom line.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →