ADVERSARIALLY ROBUST AI FRAMEWORK FOR SECURING MACHINE LEARNING BASED CYBER DEFENSE SYSTEMS AGAINST EVASION AND POISONING ATTACKS IN FINANCIAL SERVICES
DOI:
https://doi.org/10.46121/pspc.53.4.41Keywords:
Adversarial Robustness, Machine Learning Security, Evasion Attacks, Poisoning Attacks, Financial Cyber Defence, Certified Defences.Abstract
Machine learning has become a foundational element of cyber defence in financial services, supporting fraud detection, intrusion identification, and risk scoring at scale. However, the same models that defend financial systems are themselves vulnerable to adversarial attacks, including evasion at inference time and poisoning during training. These vulnerabilities create a paradox in which security tools designed to protect financial institutions can be manipulated into producing harmful outcomes. This paper proposes an adversarially robust artificial intelligence framework specifically designed for machine learning based cyber defence systems in the financial sector. The framework combines adversarial training, input transformation defences, certified robustness through randomised smoothing, and continuous monitoring for poisoning indicators within an integrated architecture. Empirical evaluation was conducted on simulated financial cyber defence systems exposed to a portfolio of state-of-the-art evasion and poisoning attacks across fraud detection and intrusion detection tasks. Results show that the proposed framework improved adversarial robustness by an average of 41 percent across attack scenarios while maintaining clean accuracy within two percent of the undefended baseline. Poisoning detection achieved 92.7 percent identification rate with a false positive rate of 3.1 percent. The findings demonstrate that practical adversarial robustness is achievable for financial cyber defence systems without unacceptable degradation of operational performance, supporting the responsible deployment of machine learning in high-stakes financial environments.

