arXiv AI

Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System

The paper examines how a breach of a single AI vendor—used by banks for fraud screening, credit decisions, AML triage, customer analytics, and internal support—can spread through operational, informational, and financial links, ultimately causing losses that resemble a traditional banking crisis. It introduces a four‑layer heterogeneous network linking AI vendors, banks, interbank exposures, and customer accounts, and presents CFC‑Prop, a stochastic epidemic‑and‑clearing model that reproduces heavy‑tailed loss distributions and sensitivity to patch latency on a synthetic dataset of 60 vendors, 220 banks, and 1,400 interbank exposures. Additionally, the authors develop CFC‑GNN, an early‑warning graph‑based model that predicts high‑cascade‑risk vendors with AUROC 0.82 and AUPRC 0.60, and they release all code, data, and scripts for reproducibility.

arXiv AI
Aug 26

Quantifying System-Level Harms from AI Adoption in Complex Sociotechnical Systems

The paper proposes a framework that connects structured hazard analysis, component-level testing, and probabilistic system modelling to assess system-level harms from AI in complex sociotechnical systems. It demonstrates the approach using the UK's Real Time Gross Settlement system, showing how adversarial inputs to LLM-based trading can shift AI behaviour, reduce system resilience, and increase the likelihood of cascading bank failures. The framework aims to provide a traceable pathway from model behaviour to systemic outcomes, enabling evidence-based governance of AI in critical infrastructure.

By Paul Vautravers, Oliver Chalkley, Gabriel Downer, Kate S, Damian Ruck
arXiv AI
Jun 17

An AI Security Agent for Banking: Multi-Vector Fraud and AML Detection Across Retail and Corporate Accounts

arXiv:2606. 17555v1 Announce Type: cross Abstract: Banks simultaneously face signature-based fraud (card-not-present attacks, account takeover, ATM cloning) and behavioural financial crime (structuring, layering, mule networks, business email compromise) -- two threat families with fundamentally different detection requirements.

By Joseph Walusimbi, Joshua Benjamin Ssentongo