Co esponding au ho : Oluwabiyi Oluwawapelumi Ajakaye ORCID: 0009-0000-4014-4285
Copy igh © 2025 Au ho (s) e ain he copy igh o his a icle. This a icle is published unde he e ms o he C ea i e Commons A ibu ion Liscense 4.0.
In eg a ing A i icial In elligence in o ganiza ional cybe secu i y: Enhancing
consume da a p o ec ion in he U.S. Fin ech Sec o
Oluwabiyi Oluwawapelumi Ajakaye 1, *, Ayobami Gab iel Olan ewaju 2, Da id Fawehinmi 3, Rasheed A olabi 4 and
Gold Meba i Pius-Kia e 5
1 Depa men o Telecommunica ions Enginee ing, Uni e si y o Sunde land, Tyne and Wea , Uni ed Kingdom.
2 Depa men o Business, Wes e n Go e no s Uni e si y, Sal Lake Ci y, U ah, USA.
3 Depa men o Business, Law and Poli ics, Uni e si y o Hull, Kings om, Uni ed Kingdom.
4 Depa men o In o ma ion Sys ems, Baylo Uni e si y, Waco, Texas, USA.
5 Depa men o Compu e Science and In o ma ion Sys ems, Pace uni e si y, New Yo k, USA.
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
Publica ion his o y: Recei ed on 14 Ma ch 2025; e ised on 20 Ap il 2025; accep ed on 22 Ap il 2025
A icle DOI: h ps://doi.o g/10.30574/wja .2025.26.1.1421
Abs ac
Financial echnology ( in ech) companies ace escala ing cybe h ea s ha jeopa dize consume da a. This esea ch
in es iga es how in eg a ing a i icial in elligence (AI) in o o ganiza ional cybe secu i y can enhance consume da a
p o ec ion in he U.S. in ech indus y. We pose key ques ions on AI’s ole in h ea de ec ion, i s cu en use cases and
challenges in in ech cybe secu i y, and he e ec i eness o deep lea ning models in p e en ing da a b eaches. A
comp ehensi e li e a u e e iew e eals ha AI echniques – pa icula ly deep lea ning models like Long Sho -Te m
Memo y (LSTM) ne wo ks and T ans o me s – a e inc easingly applied o in usion de ec ion, aud mi iga ion, and
h ea in elligence in in ech cybe secu i y. Howe e , challenges such as ad e sa ial a acks, da a bias, egula o y
cons ain s, and implemen a ion cos s pe sis . To add ess ou esea ch ques ions, we de elop an AI-d i en
cybe secu i y me hodology applying LSTM and T ans o me models o ecen U.S. in ech b each da ase s and a
benchma k in usion da ase . Real-wo ld b each da a om 2018–2023 (e.g., he Ve izon
VERIS b each da abase and public disclosu es) and a mode n in usion de ec ion da ase a e used o ain and e alua e
he models. The LSTM-based model and T ans o me -based model a e assessed on hei accu acy, de ec ion speed, and
impac on b each p e en ion. Resul s show ha bo h models achie e high de ec ion a es (o e 98–99% accu acy) in
iden i ying malicious ac i i ies, wi h he T ans o me sligh ly ou pe o ming he LSTM in p ecision and ecall. These AI
models d ama ically educe inciden esponse imes and lag h ea s ha may o he wise go unde ec ed, aligning wi h
indus y epo s ha o ganiza ions using secu i y AI con ain b eaches signi ican ly as e .
Discussion o he indings connec s hese pe o mance gains o imp o ed consume da a p o ec ion: ea lie and mo e
accu a e de ec ion o in usions allows in ech i ms o p e en o mi iga e da a b eaches be o e sensi i e cus ome
in o ma ion is comp omised. We also explo e how AI in eg a ion mus be pai ed wi h go e nance, isk, and compliance
(GRC) amewo ks o add ess e hical and egula o y conside a ions.
Conclusion: The s udy concludes ha AI-d i en cybe secu i y holds g ea p omise o s eng hening da a p o ec ion in
in ech by augmen ing h ea de ec ion capabili ies and educing b each impac s. We p o ide ac ionable insigh s o
in ech o ganiza ions and esea che s, highligh ing ha while AI can subs an ially enhance cybe secu i y esilience and
consume da a sa e y, a socio- echnical app oach add essing challenges o us , anspa ency, and compliance is
essen ial o success ul implemen a ion
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2803
Keywo ds: A i icial In elligence (AI); Cybe secu i y; Fin ech; Consume Da a P o ec ion; Deep Lea ning Models
(LSTM; T ans o me s); Th ea De ec ion and P e en ion
1. In oduc ion
The apid digi aliza ion o inancial se ices has made in ech companies p ime a ge s o cybe a acks. Fin ech i ms
manage as amoun s o sensi i e pe sonal and inancial da a and o e online se ices 24/7, which exposes hem o a
wide a ay o cybe h ea s. High-p o ile da a b eaches in ecen yea s unde sco e he se e i y o his isk. Fo ins ance,
he 2019 Capi al One b each exposed o e 100 million cus ome eco ds due o a cloud miscon igu a ion, and mo e
ecen ly in 2024, in ech so wa e p o ide Finas a su e ed a b each whe e a acke s ex il a ed 400 GB o da a ia a
comp omised ile ans e applica ion. Such inciden s no only ha m consume s h ough iden i y he and aud, bu
also e ode cus ome us and in i e egula o y penal ies. Acco ding o he Iden i y The Resou ce Cen e , he inancial
se ices sec o consis en ly anks among he mos -b eached indus ies each yea
Figu e 1 illus a es ha in 2023 he inance sec o expe ienced 744 epo ed da a comp omises – oughly one qua e
o all U.S. b eaches – second only o heal hca e. These s a is ics highligh a p essing need o mo e obus cybe secu i y
measu es ailo ed o in ech’s h ea landscape.
Figu e 1 Da a b eaches by indus y in he U.S. o 2023. The inancial sec o su e ed 744 b eaches, e lec ing i s
s a us as one o he mos a ge ed indus ies (da a om ITRC epo )
T adi ional secu i y con ols, while necessa y, o en s uggle o keep pace wi h mode n cybe h ea s ha a e
inc easingly sophis ica ed and as -mo ing. Fin ech o ganiza ions ha e begun explo ing a i icial in elligence (AI) and
machine lea ning as inno a i e solu ions o bols e cybe secu i y de enses. AI algo i hms can analyze as s eams o
ne wo k a ic, ansac ion da a, and use beha io logs in eal- ime, po en ially de ec ing anomalies o a ack pa e ns
a mo e quickly han manual me hods. Fo example, machine lea ning-d i en in usion de ec ion sys ems can
ecognize sub le indica o s o a acks amids eno mous da a olumes. Likewise, in ech leade s ha e applied AI o aud
p e en ion – PayPal’s AI engines, o ins ance, scan millions o ansac ions in eal- ime o block suspicious ac i i y
be o e i esul s in aud. Ea ly adop ion in he inancial sec o sugges s AI can signi ican ly imp o e h ea de ec ion
speed and accu acy, hus enhancing consume da a p o ec ion by s opping b eaches ea ly.
Howe e , in eg a ing AI in o an o ganiza ion’s cybe secu i y p og am is no s aigh o wa d. I aises impo an
esea ch ques ions abou e icacy, implemen a ion challenges, and ou comes o da a p o ec ion. This s udy ocuses on
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2804
U.S. in ech companies and examines how AI echniques (speci ically deep lea ning models) can be le e aged o enhance
consume da a secu i y. We o mula e he ollowing esea ch ques ions (RQs) o guide ou in es iga ion:
• RQ1: Wha a e he cu en use cases o AI in in ech cybe secu i y, and how do hese applica ions con ibu e o
p o ec ing consume da a?
• RQ2: Wha challenges and limi a ions do in ech o ganiza ions ace in implemen ing AI-d i en cybe secu i y
solu ions (e.g., echnical, ope a ional, e hical, and egula o y challenges)?
• RQ3: How e ec i ely can deep lea ning models such as LSTMs and T ans o me s de ec o p edic
cybe secu i y inciden s in in ech, and in wha ways could hei deploymen imp o e consume da a p o ec ion
ou comes compa ed o adi ional me hods?
To answe hese ques ions, we combine a li e a u e-d i en analysis wi h an empi ical e alua ion o AI models on
ele an cybe secu i y da ase s. The li e a u e e iew (Sec ion 2) syn hesizes indings om pee - e iewed s udies on
AI applica ions in cybe secu i y – in usion de ec ion, aud de ec ion, h ea in elligence – wi h pa icula a en ion o
he in ech con ex . We also iden i y he p e ailing challenges ha migh hinde AI in eg a ion (e.g., ad e sa ial a acks
on AI, da a p i acy conce ns, need o model anspa ency). Nex , he me hodology (Sec ion 3) de ails ou app oach in
applying deep lea ning models o ecen cybe secu i y inciden da a. We desc ibe he da a sou ces, model a chi ec u es,
and e alua ion me ics used o assess AI pe o mance in de ec ing b eaches o anomalies. In Sec ion 4, we p esen
esul s om ou expe imen s, including quan i a i e pe o mance o he AI models and quali a i e obse a ions on how
AI could mi iga e eal-wo ld b each scena ios. Sec ion 5 p o ides an in-dep h discussion, in e p e ing how ou indings
answe he RQs and o e ing implica ions o in ech indus y p ac ice (such as he expec ed educ ion in b each
de ec ion ime and imp o emen s in de ensi e capabili ies wi h AI). We also discuss how o ganiza ions can add ess he
challenges iden i ied, o example by combining AI wi h go e nance and isk managemen s a egies. Finally, Sec ion 6
concludes he pape by summa izing he key insigh s: we ind ha in eg a ing AI in o in ech cybe secu i y can
subs an ially enhance consume da a p o ec ion by augmen ing h ea de ec ion and inciden esponse, bu i equi es
ca e ul implemen a ion o o e come limi a ions. We also sugges di ec ions o u u e esea ch, including he
de elopmen o explainable and ad e sa y- esis an AI o cybe secu i y.
O e all, his wo k p o ides a comp ehensi e examina ion o AI’s ole in in ech cybe secu i y. I o e s e idence ha
ad anced AI echniques, when p ope ly ha nessed, can s eng hen o ganiza ional de enses and be e sa egua d
sensi i e cus ome da a in he digi al inance e a – a con ibu ion ha is inc easingly c i ical as cybe h ea s con inue
o g ow in equency and complexi y.
2. Li e a u e Re iew
2.1. Cybe secu i y Th ea Landscape in Fin ech
Fin ech companies ope a e a he in e sec ion o inance and echnology, making hem uniquely ulne able o a b oad
spec um o cybe h ea s. Thei eliance on digi al pla o ms, APIs, and cloud se ices, combined wi h handling o
aluable inancial da a, a ac s bo h inancially mo i a ed cybe c iminals and o he h ea ac o s. A ecen sys ema ic
e iew by Ja ahe i e al. (2024) iden i ied 11 cen al cybe h ea s acing in ech i ms, highligh ing he p e alence o
da a b eaches, malwa e a acks, phishing, ansomwa e, and inside h ea s. Common a ack ec o s include social
enginee ing ( icking employees o cus ome s in o di ulging c eden ials), exploi a ion o unpa ched so wa e
ulne abili ies, and abuse o weak au hen ica ion o access con ols. Phishing is pa icula ly ampan in he in ech
space – a acke s impe sona e banks o paymen se ices o s eal login c eden ials o ick use s in o ins alling malwa e
. These echniques can lead o unau ho ized access o sys ems con aining pe sonal da a o accoun in o ma ion. Fin ech
i ms also inc easingly ace ansomwa e a acks, whe e malwa e enc yp s c i ical da a and demands paymen ; such
inciden s ha e su ged in ecen yea s and can c ipple ope a ions i backups a e inadequa e. Fo example, a success ul
ansomwa e a ack on a in ech’s in as uc u e migh o ce he business o line and po en ially expose o des oy
cus ome eco ds, causing bo h inancial and epu a ional damage. Ano he impo an h ea ca ego y is di ec da a
b eaches h ough hacking. Fin ech companies s o e la ge quan i ies o pe sonally iden i iable in o ma ion (PII), banking
de ails, and ansac ion eco ds, making hem “p ime a ge s o hacke s”. B eaches can occu ia ex e nal a acks (e.g.,
exploi ing a web applica ion ulne abili y as in he Equi ax 2017 b each) o ia inside misuse. The consequences o
such b eaches a e se e e: besides immedia e inancial losses and cus ome ha m, i ms may ace egula o y ines and
legal liabili ies unde da a p o ec ion laws. In he U.S., egula ions like he G amm-Leach-Bliley Ac (GLBA) and s a e
da a b each no i ica ion laws impose s ic du ies o sa egua d cus ome da a and disclose b eaches, so a in ech b each
o en igge s expensi e emedia ion and compliance cos s. Indeed, s udies show da a b eaches can ha e long- e m
impac s on cus ome us – in ech use s a e likely o swi ch p o ide s i hey eel hei da a is no secu e, and loss o
us can signi ican ly e ode a company’s ma ke alue.
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2805
Compounding he issue, h ea ac o s a e con inually e ol ing hei ac ics. Eme ging h ea s include he use o AI by
a acke s hemsel es. Cybe c iminals ha e begun o le e age AI and au oma ion o launch mo e sophis ica ed a acks,
such as AI-d i en phishing ha c a s highly pe sonalized bai , o malwa e ha can adap i s beha io o e ade de ec ion
in eal- ime. Fo example, malwa e augmen ed wi h AI migh dynamically modi y i s signa u es o a oid an i i us
so wa e, o c iminals migh use machine lea ning o ind and exploi new ulne abili ies as e . Such AI-powe ed
a acks pose a new challenge o de ende s, as hey can de ea s a ic secu i y measu es and equi e mo e adap i e
de enses. Fin ech is also exposed o h ea s ia he supply chain and hi d-pa y dependencies. Many in ech se ices
ely on hi d-pa y so wa e (e.g., open sou ce lib a ies, cloud hos ing) and in eg a ions wi h banking pa ne s. A
ulne abili y o b each a a hi d-pa y (such as he 2023 MOVEi ile- ans e so wa e ze o-day ha led o nume ous
downs eam da a b eaches) can indi ec ly comp omise in ech da a. In 2023, he K oll Da a B each Ou look no ed ha
hi d-pa y isk was a leading cause o inciden s, and he inance sec o was hea ily impac ed by a supply-chain a ack
whe ein a ansomwa e gang exploi ed a common ile- ans e ool, a ec ing mul iple inancial ins i u ions. This
in e connec edness means in ech i ms mus accoun o no only hei own secu i y, bu also he secu i y o endo s
and pa ne s.
In summa y, he h ea landscape o in ech is bo h b oad and dynamic. Fin ech o ganiza ions ace he ull gamu o
cybe -a acks seen in adi ional inance ( aud, accoun akeo e s, da a he ) as well as echnology-sec o a acks
(DDoS, exploi s o so wa e laws). Table 1 p o ides a b ie o e iew o ep esen a i e cybe secu i y inciden s in in ech
o e he las i e yea s o illus a e he ange o h ea s and impac s.
Table 1 Majo Fin ech-Rela ed Da a B eaches (2018–2023)
Inciden (Yea )
Company/Se ice
Reco ds A ec ed
Cause o B each
Capi al One b each
(2019)
Capi al One
(bank/ in ech)
~106 million
cus ome s
Miscon igu ed AWS cloud s o age exploi ed by
hacke (se e -side eques o ge y)
Fi s Ame ican Financial
b each (2019)
Fi s Ame ican
( in ech RE)
885 million
eco ds
Web applica ion logic law exposing documen s
wi hou au hen ica ion
Da e.com b each (2020)
Da e (digi al bank
app)
~7.5 million use s
Hacking o hi d-pa y se ice p o ide ,
leading o c eden ial comp omise
Robinhood b each
(2021)
Robinhood (s ock
ading)
~7 million
cus ome s
Social enginee ing o cus ome suppo ,
allowing a acke o ob ain use da a
Cash App In es ing
inciden (2022)
Block (Cash App)
~8 million
cus ome s
Inside h ea – o me employee downloaded
epo s con aining use s ock da a
Finas a b each (2024)
Finas a ( in ech
so wa e)
Unknown (65
no i ied in MA)
Comp omised ile ans e applica ion by
a acke ; 400 GB o da a s olen (no
ansomwa e)
These examples unde sco e ecu ing pa e ns: con igu a ion e o s o unpa ched so wa e leading o b eaches (Capi al
One, Fi s Ame ican), hi d-pa y o inside isks (Da e, Cash App, Finas a), and social enginee ing ha bypasses
echnical con ols (Robinhood). The high equency and impac o such inciden s ha e pushed he in ech indus y and
egula o s o seek s onge de enses – which is whe e AI has eme ged as a p omising ool, as discussed nex .
2.2. Applica ions o AI in Fin ech Cybe secu i y
A i icial in elligence has apidly become a co ne s one o nex -gene a ion cybe secu i y solu ions. In pa icula ,
machine lea ning (ML) and deep lea ning echniques enable secu i y sys ems o analyze complex da a and de ec
h ea s wi h a speed and sophis ica ion ha complemen s human analys s. In he in ech domain, o ganiza ions a e
applying AI ac oss se e al key cybe secu i y use cases:
• In usion and Anomaly De ec ion: De ec ing ne wo k in usions and sys em anomalies in eal ime is c ucial
o p e en ing da a b eaches. AI-d i en In usion De ec ion Sys ems (IDS) use ML algo i hms o model no mal
e sus malicious beha io . Fo example, deep lea ning models can lea n pa e ns o legi ima e ne wo k a ic
and lag de ia ions ha migh indica e a b each a emp . LSTM neu al ne wo ks, which excel a sequence
lea ning, ha e been used o iden i y suspicious sequences o e en s in ne wo k logs o use ac i i y. P io
esea ch has demons a ed ha op imized LSTM models can achie e high accu acy in de ec ing in usions
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2806
while educing alse ala ms. In one s udy, a uned LSTM-based IDS achie ed o e 97% de ec ion accu acy on
benchma k da ase s, ou pe o ming ea lie machine-lea ning IDS app oaches ha o en su e ed om high
alse-posi i e a es. Simila ly, T ans o me -based models (which ely on sel -a en ion mechanisms) ha e been
adap ed o cybe secu i y o g ea e ec . A ecen wo k by A aa e al. (2024) de eloped a T ans o me encode
model o ne wo k in usion de ec ion in cloud en i onmen s and epo ed ~99% classi ica ion accu acy,
sligh ly highe han a con olu ional LSTM hyb id model on he same da a. The abili y o T ans o me s o
cap u e long- ange dependencies in da a is bene icial o modeling complex a ack pa e ns. These
ad ancemen s indica e ha AI can ma kedly imp o e he de ec ion o unau ho ized access o abno mal
ac i i ies in in ech sys ems, enabling secu i y eams o espond o inciden s be o e hey escala e in o ull-
blown b eaches.
• F aud De ec ion and T ansac ion Moni o ing: Paymen aud and iden i y he a e majo conce ns in in ech
(e.g., c edi ca d aud, audulen accoun openings, and money launde ing). AI has become indispensable in
de ec ing aud in eal- ime by analyzing ansac ion da a. Machine lea ning models (such as decision ees,
andom o es s, g adien boos ing) ha e long been used o lag po en ially audulen ansac ions based on
ules and pa e ns. Mo e ecen ly, in ech companies ha e deployed deep lea ning o aud de ec ion – o
ins ance, using neu al ne wo ks o e alua e dozens o ea u es o each ansac ion (amoun , loca ion, de ice,
pas beha io , e c.) o p edic aud p obabili y. PayPal’s deploymen o AI is a p ominen example: using a
combina ion o neu al ne wo ks and anomaly de ec ion algo i hms, PayPal epo ed i can iden i y audulen
ansac ions wi hin milliseconds and block hem be o e comple ion, educing aud loss a es signi ican ly.
La ge banks and ca d ne wo ks simila ly use AI o sco e ansac ions; he model’s abili y o lea n sub le,
nonlinea co ela ions means i ca ches aud ha simple ules migh miss ( o example, complex accoun
akeo e schemes in ol ing mul iple s eps). AI-based aud de ec ion no only p o ec s consume asse s bu
also indi ec ly p o ec s pe sonal da a by de ec ing when an unau ho ized use may be le e aging s olen
c eden ials.
• Use & En i y Beha io Analy ics (UEBA): Fin ech i ms a e adop ing AI o es ablish baselines o no mal
beha io o use s, de ices, and applica ions, and hen de ec anomalies ha could signal an inside h ea o
accoun comp omise. Fo ins ance, an AI sys em migh lea n ha a pa icula cus ome ypically logs in om
Texas and makes small ans e s; i suddenly hei accoun ini ia es a la ge ans e om o e seas, he sys em
will lag i . These beha io -based sys ems o en use unsupe ised lea ning o clus e ing o disce n pa e ns
wi hou needing explici a ack signa u es. Many ad anced h ea p e en ion sys ems inco po a e UEBA
modules powe ed by AI, which is especially use ul o de ec ing inside h ea s o sub le b eaches whe e an
a acke impe sona es a legi ima e use .
• Th ea In elligence and Phishing De ec ion (NLP): Ano he c ucial applica ion o AI is in p ocessing
uns uc u ed cybe secu i y da a – an a ea whe e Na u al Language P ocessing (NLP) echniques a e
aluable. AI can au oma ically inges h ea in elligence epo s, news, and o um discussions o iden i y
eme ging h ea s ele an o in ech (such as new malwa e a ge ing banking apps). Mo eo e , NLP is being
used o de ec phishing and social enginee ing a emp s by analyzing email o message con en . Fo example,
ML models can scan incoming emails o employees o cus ome s o phishing indica o s (suspicious language
pa e ns, anomalous sende , malicious links). La ge language models o ans o me s ine- uned o phishing
email classi ica ion ha e shown high success in il e ing ou phish wi h minimal alse posi i es. This is
inc easingly impo an as phishing emains a op ini ial ec o in da a b eaches. By ca ching phishing emails o
messages be o e a use alls ic im, AI can p e en c eden ial he ha o en leads o deepe ne wo k
in il a ion. In addi ion, AI ex analysis helps in aud p e en ion (ca ching scam communica ions) and
compliance (moni o ing communica ions o policy iola ions).
• Secu i y In o ma ion and E en Managemen (SIEM) & O ches a ion: AI is also enhancing how secu i y
ope a ions cen e s agg ega e and espond o ale s. T adi ional SIEM pla o ms gene a e la ge olumes o ale s
om logs and e en s, which can o e whelm analys s. Mode n SIEM and secu i y o ches a ion ools in eg a e
AI algo i hms o co ela e e en s and p io i ize ale s. Fo ins ance, i mul iple low-le el e en s (unusual
login, ollowed by a ile access, ollowed by a da abase que y) occu ha on hei own migh no igge ala ms,
an AI sys em can ecognize he pa e n as po en ially malicious when aken oge he . AI-based co ela ion and
inciden sco ing educe noise and highligh he mos impo an h ea s, making inciden esponse mo e
e icien . Some in ech companies a e e en explo ing au oma ed inciden esponse, whe e AI no only de ec s
bu also ini ia es con ainmen (such as locking a comp omised accoun o isola ing a se e ) acco ding o p e-
de ined playbooks.
O e all, cu en li e a u e and indus y epo s indica e ha AI’s adap abili y and lea ning capabili ies make i well-
sui ed o add ess he e ol ing h ea landscape in in ech. In usion de ec ion using AI has eme ged as he mos
p ominen ocus a ea in esea ch, comp ising ~13% o publica ions on AI in cybe secu i y, which e lec s i s c i ical
impo ance. O he majo a eas whe e AI con ibu es include malwa e de ec ion, aud p e en ion, and h ea p edic ion
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2807
. In in ech o ganiza ions, hese ansla e o p ac ical deploymen s like au oma ed moni o ing o ne wo k a ic o
b eaches, eal- ime aud sco ing in paymen sys ems, and AI-d i en secu i y analy ics ha augmen human decision-
making. Impo an ly, AI is no iewed as a eplacemen o human secu i y eams, bu as a o ce mul iplie – i can
handle he “hea y li ing” o da a analysis, su ace insigh s, and e en ac au onomously o known pa e ns, allowing
secu i y p o essionals o ocus on s a egy and on no el o complex h ea s.
Despi e hese bene i s, in eg a ing AI in o cybe secu i y is no wi hou challenges. We nex discuss he limi a ions and
obs acles ha in ech i ms mus conside when deploying AI-d i en secu i y sys ems.
2.3. Challenges and Limi a ions o AI in Cybe secu i y o Fin ech
While AI o e s powe ul capabili ies, he e a e se e al challenges and limi a ions associa ed wi h i s use in
cybe secu i y, pa icula ly in an indus y as sensi i e as inancial se ices:
• Ad e sa ial A acks on AI: Jus as AI can be used o de ec a acks, a acke s can a ge he AI models
hemsel es. Ad e sa ial machine lea ning is an eme ging conce n; h ea ac o s may a emp o decei e an AI
sys em h ough specially c a ed inpu s. Fo example, an a acke migh sligh ly pe u b ne wo k a ic
pa e ns o malwa e code o e ade an AI-based de ec o (o en called ad e sa ial e asion) o injec poisoned
da a du ing he aining phase o co up he model’s lea ning. Fin ech secu i y AI sys ems could be icked in o
misclassi ying malicious ac i i y as benign, opening a blind spo o a acke s. This ca -and-mouse dynamic
means ha AI models need o be ha dened and con inuously e alua ed agains ad e sa ial ac ics. Resea ch in
explainable AI (XAI) and obus AI is a emp ing o add ess his by making models mo e in e p e able and
esis an o manipula ion.
• False Posi i es and Model Accu acy: Achie ing high de ec ion a es wi hou o e whelming analys s wi h
alse posi i es is a delica e balance. Finance is a domain whe e alse ala ms ca y a cos – o ins ance, alsely
accusing legi ima e ansac ions o use ac ions can incon enience cus ome s o in e up business p ocesses.
Ea lie machine lea ning sys ems o en had high alse posi i e a es in IDS applica ions. Deep lea ning has
imp o ed accu acy, bu models s ill mus be ine- uned o he speci ic en i onmen o a oid ale a igue. The e
is a isk ha i an AI sys em is oo sensi i e, secu i y eams migh s a igno ing i s ale s ( he “boy who c ied
wol ” e ec ). Thus, main aining model p ecision (high ue posi i e s alse posi i e a io) is c i ical o p ac ical
deploymen . Ou li e a u e e iew ound ha op imized models (e.g., using hype pa ame e uning, ensemble
me hods, e c.) can educe alse posi i es signi ican ly, bu igo ous es ing on eal in ech da a is needed o
alida e pe o mance be o e ull deploymen .
• Da a A ailabili y and Quali y: AI e ec i eness depends hea ily on da a. Fin ech companies may ha e an
abundance o ce ain da a (e.g., ansac ion eco ds) bu ela i ely ew examples o ac ual a acks o aud cases
o lea n om. This class imbalance p oblem can make i ha d o supe ised models o lea n o de ec he a e
e en s ( he a acks) amids huge olumes o no mal e en s. I AI models a e ained on limi ed his o ical
inciden da a, hey migh no gene alize well o new ypes o a acks. Addi ionally, acqui ing high-quali y
cybe secu i y da ase s o aining is challenging due o p i acy and sensi i i y – i ms may be eluc an o
sha e b each da a, and simula ions migh no cap u e all eal-wo ld nuances. The VERIS Communi y Da abase
(VCDB) is one e o o compile housands o publicly disclosed b each inciden s o esea ch, which we
le e age in his s udy. Howe e , as no ed in he VCDB documen a ion, he da a can be biased (e.g., o e -
ep esen a ion o ce ain sec o s like heal hca e due o egula o y epo ing equi emen s). Fin ech-speci ic
inciden da a may be unde ep esen ed. To mi iga e his, o ganiza ions need s a egies like da a augmen a ion,
ans e lea ning (using models p e- ained on simila cybe secu i y asks), o ede a ed lea ning
(collabo a i e model aining wi hou sha ing aw da a) o imp o e AI models. In p ac ice, la ge inancial
ins i u ions ha e s a ed sha ing anonymized aud indica o s among conso iums o bols e AI models – bu
smalle in ech s a ups migh lack access o such ich da a, c ea ing an adop ion gap.
• Regula o y and E hical Cons ain s: In a egula ed domain, he use o AI mus comply wi h egula ions and
uphold cus ome igh s. Regula ions like he EU’s GDPR and eme ging U.S. s a e p i acy laws equi e ha
pe sonal da a usage be anspa en and ai . I an AI sys em p ocesses cus ome da a (e en o secu i y), i mus
be secu ed and i s ou pu s audi able. The e is also egula o y a en ion on he ai ness o AI decisions – o
example, i an AI lags ce ain ansac ions o accoun s as high isk, i ms need o ensu e his does no esul in
un ai bias agains any g oup o cus ome s. Financial egula o s ha e begun sc u inizing he use o AI (e.g., he
U.S. SEC’s guidance on au oma ed digi al ad ice and FRB/FDIC/OCC s a emen s on AI in banking). In
cybe secu i y speci ically, he conce n is mo e on ensu ing AI doesn’ iola e p i acy ( o ins ance, moni o ing
employee communica ions wi h AI could aise wo kplace p i acy issues) and ha inciden esponse using AI
ollows equi ed b each epo ing p ocedu es. Addi ionally, new egula ions a e being p oposed ha migh
manda e explainabili y o AI decisions in secu i y – i.e., i ms may need o explain o an audi o why an AI
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2808
sys em ook a ce ain ac ion. Black-box models like deep neu al ne wo ks a e no o iously ha d o in e p e ,
which poses a challenge. As Achu han e al. (2024) discuss, e hical conce ns and us in AI emain signi ican
issues; mo e esea ch is needed in explainable and us wo hy AI o cybe secu i y. Fin ech companies will
likely need o implemen AI in a way ha humans can o e see and o e ide when necessa y, main aining he
“human in he loop” o c i ical secu i y decisions.
• In eg a ion and Ope a ional Challenges: Deploying AI o cybe secu i y is no jus a echnical exe cise; i
also in ol es o ganiza ional eadiness. Smalle in ech s a ups may lack in-house expe ise in da a science o
cybe secu i y AI, making i di icul o build o manage such sys ems. Pu chasing o - he-shel AI secu i y
p oduc s is an op ion, bu hose migh no be ailo ed o he speci ic en i onmen . The e is also he issue o
in eg a ing AI ools wi h exis ing secu i y wo k lows. AI migh ou pu a isk sco e o ale – he secu i y eam
needs playbooks o ac on hese ale s. I he in eg a ion is poo , he AI ool could be unde u ilized. Addi ionally,
AI models equi e con inuous main enance: e aining wi h new da a, upda ing o new h ea s, and pa ching
he models hemsel es. This can s ain esou ces, as no ed by indus y p ac i ione s in e iewed in a U.S.
T easu y epo on AI in inancial sec o cybe secu i y – many i ms p oceed cau iously wi h AI adop ion,
unning pilo p ojec s and ensu ing c oss- eam collabo a ion (IT, secu i y, compliance, e c.).
• False Sense o Secu i y: Finally, an o en in angible bu impo an isk is ha deploying AI could gi e
o ganiza ions a alse sense o secu i y i no accompanied by b oade cybe secu i y imp o emen s. AI is a ool,
no a panacea. I a in ech i m elies oo hea ily on AI and neglec s basic secu i y hygiene (pa ch managemen ,
access con ol, enc yp ion, e c.), i may ac ually wo sen hei secu i y pos u e. E ec i e cybe de ense s ill
equi es laye ed con ols (“de ense in dep h”) whe e AI is one laye . Miscon igu a ions o p ocess ailu es can
s ill cause b eaches ( o example, an AI sys em migh de ec an anomaly bu i he inciden esponse p ocess is
b oken, he b each may no be con ained in ime). The e o e, implemen ing AI mus be pa o a holis ic
cybe secu i y s a egy.
In summa y, while AI b ings powe ul capabili ies o in ech cybe secu i y, hese limi a ions mean ha o ganiza ions
mus adop AI hough ully. They should combine AI wi h s ong go e nance, isk managemen , and human expe ise
o ensu e i uly enhances secu i y. Table 2 summa izes some key challenges o using AI in in ech cybe secu i y and
app oaches o add ess hem.
Table 2 Key Challenges in AI-D i en Fin ech Cybe secu i y and Mi iga ion S a egies
Challenge
Desc ip ion
Mi iga ion S a egies
Ad e sa ial
ML
A acke s c a ing
inpu s o e ade o
poison AI models
– Ad e sa ial aining o models wi h pe u bed examples
– Model in ospec ion and use o obus a chi ec u es
– Moni o o model d i o anomalies in model decisions
False
Posi i es s.
Misses
Tuning sensi i i y o
minimize alse ala ms
and missed a acks
– Th eshold uning and eedback loop wi h analys s
– Ensemble models combining AI wi h ule-based checks o alida ion
– Use o con idence sco ing and only au oma ing high-con idence ale s
Da a sca ci y
& imbalance
Limi ed a ack da a o
ain models;
imbalanced da ase s
– Use o simula ed da a and augmen a ion o supplemen eal da a
– T ans e lea ning om ela ed domains (e.g., using models p e- ained on
la ge cybe secu i y da a)
– Fede a ed lea ning ac oss ins i u ions o build sha ed models wi hou
sha ing aw da a
Black-box
model
anspa ency
Di icul y in explaining
AI decisions o audi s
o us
– Implemen explainable AI ools (e.g., SHAP alues, LIME) o in e p e model
ou pu s
– P e e simple models whe e app op ia e o augmen black-boxes wi h
in e p e able ules
– Main ain human o e sigh on AI decisions (human-AI eaming)
Regula o y
compliance
Ensu ing AI use
complies wi h da a
p o ec ion and
inancial egula ions
– Consul compliance eams ea ly in AI deploymen design
– Anonymize o enc yp sensi i e da a used in model aining (p ese e
p i acy)
– Documen AI decision p ocesses and alida e no disc imina o y impac
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2809
In eg a ion &
main enance
Ope a ionalizing AI in
he secu i y wo k low
and upda ing i
– Pilo AI sys ems in pa allel wi h exis ing moni o ing o calib a e
– T ain secu i y pe sonnel on in e p e ing AI ou pu s
– Se up egula model e aining schedule and inciden pos -mo ems o e ine
AI (con inuous imp o emen )
O e -
eliance on
AI
Neglec ing o he
con ols due o
con idence in AI
– Use AI as one laye in a mul i-laye de ense s a egy
– Con inue in es men s in undamen al secu i y con ols (ne wo k
segmen a ion, leas p i ilege, e c.)
– Pe iodic ed- eam exe cises o es bo h AI and non-AI con ols in unison
The li e a u e emphasizes ha add essing hese challenges is easible. Fo ins ance, case s udies ha e shown ha
o ganiza ions combining AI wi h s ong go e nance ha e managed o educe b each inciden s while main aining
compliance. A holis ic app oach is needed: as sugges ed by Oluokun e al. (2024), in eg a ing AI wi h Go e nance, Risk,
and Compliance (GRC) amewo ks ensu es ha AI-d i en ools a e aligned wi h egula o y equi emen s and in e nal
policies. Go e nance measu es, such as clea policies on AI use and de ined oles and esponsibili ies, help in
accoun able deploymen o AI. I done well, he syne gy o AI echnology wi h human expe ise and go e nance can yield
a obus cybe de ense pos u e o in ech i ms.
In ligh o hese insigh s om he li e a u e, ou esea ch me hodology is designed o explo e he p ac ical applica ion
o AI models in in ech cybe secu i y while cognizan o hese challenges. We p oceed o desc ibe he me hodology,
including da a collec ion and model implemen a ion, used o e alua e how AI (speci ically deep lea ning models) can
de ec secu i y inciden s and ul ima ely p o ec consume da a in a in ech con ex .
3. Me hodology
To in es iga e he e ec i eness o AI in enhancing in ech cybe secu i y, we designed a me hodology wi h wo main
componen s: (1) Da a Collec ion om eal-wo ld cybe secu i y inciden s and simula ed a ack da a ele an o in ech,
and (2) AI Model Applica ion using deep lea ning echniques (LSTM and T ans o me models) o analyze his da a o
h ea de ec ion. Ou app oach aims o mi o a ealis ic o ganiza ional deploymen o AI o cybe secu i y, while
add essing ou esea ch ques ions abou model pe o mance and da a p o ec ion imp o emen s.
3.1. Da a Sou ces
We le e aged wo ypes o da ase s o cap u e bo h high-le el b each inciden ends and low-le el a ack pa e ns:
• Fin ech Cybe secu i y Inciden Da ase (2018–2023): We compiled a da ase o publicly epo ed
cybe secu i y inciden s a ec ing U.S. inancial ins i u ions and in ech companies o e he las i e yea s. This
was d awn om he Ve izon VERIS Communi y Da abase (VCDB) and supplemen al public b each
disclosu es. The VCDB p o ides s uc u ed eco ds o housands o inciden s, including a ibu es like h ea
ac ions, a ec ed asse s, and impac . We il e ed VCDB eco ds o he Finance and Insu ance sec o and o
inciden s om 2018 onwa d, yielding 650+ inciden s. This included no able in ech- ela ed b eaches
summa ized in Table 1 (Capi al One, Robinhood, e c.) and many lesse -known cases (e.g., b eaches a egional
banks, paymen p ocesso s, c edi unions). Fo each inciden , we ex ac ed ea u es such as inciden yea ,
a ack ec o (hacking, malwa e, misuse, e c.), da a ypes comp omised (pe sonal da a, inancial da a,
c eden ials), and whe he he inciden was caused by in e nal o ex e nal ac o s. We also labeled inciden s by
hei se e i y (e.g., numbe o eco ds comp omised) o acili a e supe ised lea ning expe imen s. This
inciden da ase allows us o analyze mac o-le el pa e ns and also o a emp p edic i e modeling ( o
ins ance, p edic ing which ac o s lead o la ge b eaches). All da a was sou ced om public epo s o
da abases; sensi i e de ails we e anonymized o agg ega ed o espec p i acy.
• In usion De ec ion Da ase (ne wo k a ack aces): To e alua e deep lea ning models in de ec ing
echnical a ack pa e ns, we used he CSE-CIC-IDS2018 in usion de ec ion da ase (an ad anced benchma k
da ase o ne wo k secu i y esea ch). This da ase con ains a ic cap u es and ex ac ed ea u es om a es
ne wo k en i onmen ha includes bo h benign ac i i y and a a ie y o a ack scena ios (b u e- o ce logins,
denial-o -se ice, web a acks, in il a ion, bo ne , e c.). The CIC-IDS2018 da ase is cu a ed by he Canadian
Ins i u e o Cybe secu i y and is widely used o e alua ing IDS models; i closely esembles eal-wo ld a ic
wi h labeled lows and imes amps. We speci ically chose his da ase because i inco po a es mode n a ack
ec o s ha a in ech company migh ace (including a acks on web se ices and in as uc u e). I p o ides
de ailed labeled da a a he packe / low le el. F om his da ase , we de i ed a aining se and es se o
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2810
ne wo k low eco ds wi h ea u es such as packe a es, p o ocol, by e coun s, and lags, labeled as ei he
no mal o one o mul iple a ack ypes. This allows us o ain and es ou LSTM and T ans o me models on a
supe ised classi ica ion ask: dis inguishing malicious a ic om no mal. Al hough his da ase is no in ech-
speci ic, i o e s a con olled benchma k o quan i y model de ec ion pe o mance (accu acy, p ecision, ecall)
o a b oad ange o cybe a acks. We conside his a p oxy o how he models would pe o m on in ech
ne wo k da a, unde he assump ion ha undamen al a ack pa e ns (po scans, SQL injec ion a emp s, e c.)
a e simila ac oss domains.
The combina ion o hese wo da a sou ces p o ides a comp ehensi e iew: he inciden da ase e lec s
o ganiza ional-le el ou comes (b eaches, comp omised eco ds) and con ex ual ac o s, whe eas he in usion
da ase p o ides low-le el eleme y o algo i hmic de ec ion asks. By using bo h, we can examine RQ3 om wo
angles – can AI p edic o classi y b each inciden s based on o ganiza ional da a, and can AI de ec a acks om echnical
da a s eams.
Be o e model aining, we pe o med s anda d p ep ocessing on bo h da ase s. The inciden da ase , being ca ego ical,
was one-ho encoded o ea u es like a ack ec o and da a ype, and nume ic scales (like company size, eco ds los )
we e no malized. We also ime-sequenced he inciden s by qua e o enable a ime-se ies analysis ( o anomaly
de ec ion on b each equencies). The in usion da ase was cleaned o emo e duplica e lows and impu e any missing
alues; con inuous ea u es we e scaled (using min-max no maliza ion) and ca ego ical p o ocol lags we e encoded.
3.2. AI Model A chi ec u es and T aining
We implemen ed wo deep lea ning model a chi ec u es aligned wi h ou ocus on LSTM and T ans o me echniques:
3.2.1. Long Sho -Te m Memo y (LSTM) Model
Ou LSTM model is designed as an anomaly de ec ion ne wo k o sequen ial da a. We cons uc ed i as a mul i-laye
LSTM au oencode , which lea ns o econs uc no mal sequence pa e ns and lags de ia ions. This a chi ec u e was
chosen o de ec anomalies in ei he ime-se ies b each da a o sequences o ne wo k e en s. Fo he inciden da ase ,
we used he LSTM in a ime-se ies o ecas ing con ex : he model was ained on he sequence o qua e ly inciden
coun s (and ea u es such as a e age eco ds b eached pe qua e ) o p edic u u e alues, wi h he idea ha
signi ican de ia ion be ween p edic ed and ac ual inciden s could indica e an anomaly (e.g., an unusual spike in
b eaches). Fo he in usion da a, we applied he LSTM in a classi ica ion se ing: ea ing he low o packe s in a session
as a sequence, he LSTM p ocesses he sequence and ou pu s a classi ica ion (no mal o speci ic a ack ype). The model
a chi ec u e consis ed o an inpu laye ma ching he ea u e ec o leng h, wo LSTM laye s (wi h 128 and 64 uni s
espec i ely) o cap u e empo al pa e ns, ollowed by a dense ou pu laye . We ained he classi ica ion LSTM model
using labeled da a (supe ised) wi h a ca ego ical c oss-en opy loss, using he Adam op imize . Fo he anomaly-
de ec ion a ian (unsupe ised), we ained he au oencode o minimize econs uc ion e o on a co pus o known
“no mal” sequences, and se a h eshold on econs uc ion e o o lag anomalies. The aining was pe o med o 50
epochs on he in usion da ase and 100 epochs on he inciden ime-se ies (which was small). We uned
hype pa ame e s such as lea ning a e and LSTM laye sizes using a g id sea ch on a alida ion se . To mi iga e
o e i ing, egula iza ion echniques like d opou (20% d opou be ween LSTM laye s) and ea ly s opping (moni o ing
alida ion loss) we e applied. The LSTM’s abili y o emembe long- e m dependencies in sequences makes i sui able
o cap u ing he e ol ing con ex in a se ies o e en s (e.g., a slow ongoing b each o mul i-s age a ack).
3.2.2. T ans o me Model
Ou T ans o me model is designed o high-accu acy supe ised classi ica ion o secu i y e en s. We implemen ed a
T ans o me encode a chi ec u e simila o hose used in ecen IDS esea ch. Fo he in usion de ec ion ask, he
T ans o me akes as inpu a sequence o ne wo k low ea u es (we ea each low o a sho window o lows as a
sequence okenized by ime) and ou pu s class p obabili ies o a ack s no mal. The model consis s o an embedding
laye ( o p ojec inpu ea u es in o a lea ned ec o space), ollowed by mul iple sel -a en ion encode blocks. We used
4 encode laye s, 8 a en ion heads, and an embedding dimension o 64 in ou con igu a ion – hese alues we e chosen
based on p io s udies ha achie ed s ong esul s on simila da a. The sel -a en ion mechanism o he T ans o me
allows he model o weigh he ele ance o di e en pa s o he inpu sequence, which is use ul o iden i y, o example,
which combina ion o ne wo k ea u es a a ious ime s eps signal an a ack. A e he encode laye s, a global a e age
pooling was applied, hen a eed- o wa d ne wo k and so max laye o p oduce ou pu p obabili ies. We ained he
T ans o me on he CIC-IDS2018 da a (supe ised mul i-class classi ica ion) using he Adam op imize wi h lea ning
a e 1e-4, and ca ego ical c oss-en opy loss. T aining an o 20 epochs ( he la ge model con e ged as e han LSTM
pe epoch due o pa allelism o a en ion). Fo egula iza ion, we employed d opou in he eed- o wa d laye s and L2
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2817
• RQ3 (Model E ec i eness and Consume Da a P o ec ion): Ou empi ical esul s demons a ed ha deep
lea ning models (LSTM and T ans o me ) a e highly e ec i e in de ec ing cybe secu i y inciden s ele an o
in ech. By achie ing o e 99% de ec ion a es on simula ed a ack da a, hese models as ly ou pe o m legacy
de ec ion me hods, sugges ing a new le el o secu i y capabili y is a ailable. The linkage o imp o ed consume
da a p o ec ion is clea : by ca ching in usions and aud quickly and accu a ely, AI helps p e en a acke s
om accessing sensi i e cus ome in o ma ion. We discussed how, in conc e e e ms, his leads o sho e
b each du a ions and less da a s olen. One s iking s a is ic om ou indings is he po en ial educ ion in
b each li ecycle – iden i ying b eaches days o mon hs as e . Fo consume s, his could be he di e ence
be ween ha ing hei da a sna ched by c iminals e sus no a all. Addi ionally, e en when b eaches occu , AI
can limi hei scope, meaning ewe indi iduals a ec ed. Ano he aspec is ha AI can help comply wi h da a
p o ec ion p inciples like da a minimiza ion – i AI p e en s unau ho ized da a access, i ensu es ha pe sonal
da a isn’ being unnecessa ily copied o mo ed a ound by malicious ac o s, hus keeping da a only whe e i
should be.
Ou s udy also indica es ha hese bene i s a e no jus heo e ical. The e a e eal-wo ld pa allels: o ins ance,
Mas e ca d epo ed i s AI-based aud sys ems ha e educed alse declines and sa ed millions in aud losses – aligning
wi h ou indings ha AI can bo h igh en secu i y and educe ic ion ( alse posi i es) o legi ima e use s. In ou
con ex , educing alse posi i es means genuine use ansac ions o ac i i ies won’ be w ongly blocked as o en,
p o iding a smoo he use expe ience while s ill p o ec ing da a. This is an impo an poin : e ec i e secu i y need
no come a he expense o use con enience i AI is used wisely. His o ically, adding secu i y (like mul i- ac o
au hen ica ion, ansac ion e i ica ion s eps) added some ic ion, bu AI wo ks in he backg ound, anspa en ly
inc easing secu i y wi hou bo he ing he use unless uly necessa y.
I is wo h no ing he scope o ou expe imen s: we ocused on de ec ion o inciden s. P e en ion is ano he a ea (like
using AI o scan code o ulne abili ies o miscon igu a ions). We didn’ di ec ly es ha , bu li e a u e sugges s AI can
aid in hose p e en i e measu es oo (e.g., code analysis ools wi h ML). Fin echs could use such ools o ca ch secu i y
laws in so wa e be o e deploymen , indi ec ly p o ec ing da a by educing b each oppo uni ies. Tha ex ends he
p o ec i e ne o AI beyond eal- ime moni o ing o he whole li ecycle o sys ems.
• In eg a ion wi h GRC: A heme ha eme ged is ha combining AI wi h go e nance and isk managemen
ampli ies he bene i s. Ou discussion o challenges ouched on his, bu o elabo a e: he bes ou comes we e
seen when AI is pa o a b oade isk s a egy. Fo example, i a in ech adop s an AI sys em o h ea de ec ion,
and simul aneously implemen s a obus inciden esponse plan (as ecommended in many cybe secu i y
amewo ks), he syne gy means ha when AI lags some hing, he o ganiza ion is p epa ed o ac quickly. I
ei he elemen is missing (g ea de ec ion bu poo esponse, o ice e sa), da a migh s ill be los . We ci ed
Oluokun e al. (2024) on in eg a ing AI wi h GRC– ou indings s ongly suppo ha ecommenda ion. We
would ad ise in ech i ms o no ea AI as a plug-and-play appliance, bu o upda e hei policies, aining,
and d ills a ound i . This includes add essing he e hical aspec s: o example, deciding unde wha condi ions
AI can au onomously shu down se ices o con ain an a ack (a ec ing a ailabili y, which mus be weighed
agains secu i y). Those decisions should be codi ied in go e nance documen s.
• Limi a ions and Fu u e Resea ch: While ou s udy demons a es clea bene i s o AI, i also has limi a ions
which poin o u u e esea ch di ec ions. One limi a ion is ha ou e alua ion o model pe o mance was
la gely on benchma k da a; eal p oduc ion en i onmen s ha e mo e noise and a ie y. Deploying hese models
in a li e in ech en i onmen migh e eal new challenges ( o ins ance, concep d i – he s a is ical p ope ies
o inpu da a may change as use beha io o a acke ac ics e ol e o e ime, equi ing model upda es).
Fu u e wo k could in ol e longi udinal s udies o AI model pe o mance in p oduc ion, obse ing how hey
deg ade o imp o e and how o en hey need e aining. Ano he a ea o u u e esea ch is
• explainable AI in in ech secu i y: de eloping me hods o in e p e a T ans o me ’s ale (e.g., highligh
which ea u es o sequence elemen s led i o ag an e en as malicious) so ha analys s and audi o s can us
and e i y he sys em. This will be inc easingly impo an as egula o s may sc u inize AI decisions in inance.
Wo k on in eg a ing AI ou pu s wi h exis ing Secu i y O ches a ion, Au oma ion, and Response (SOAR)
sys ems could u he b idge he gap om de ec ion o au oma ed esponse – an a ea ipe o de elopmen
(e.g., using AI o no jus say “ he e is an a ack” bu also sugges o ini ia e he bes con ainmen ac ion).
Ano he conside a ion is p i acy-p ese ing AI. Fin echs ha e o be mind ul o cus ome p i acy e en as hey moni o
sys ems. Techniques like ede a ed lea ning o secu e mul i-pa y compu a ion could allow mul iple ins i u ions o
collabo a i ely ain sha ed h ea models wi hou exposing aw da a o each o he . This could g ea ly enhance AI
e ec i eness (mo e da a o lea n om) while espec ing con iden iali y. Ou wo k didn’ explo e ha , bu i ’s a
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2818
p omising a ea especially o indus y-wide ini ia i es agains aud o money launde ing whe e pa e ns span
ins i u ions.
• Policy and Regula o y Implica ions: Gi en he indings, egula o s migh encou age esponsible use o AI in
cybe secu i y. Al eady, he U.S. T easu y has no ed AI’s s a egic alue in aud de ec ion and isk managemen
in inance. Regula o s could inco po a e guidance in amewo ks like he FFIEC IT Examina ion Handbook o
NIST guidelines speci ic o he inancial sec o , ecommending ha banks and in echs le e age AI/au oma ion
o mee ce ain secu i y baseline equi emen s (wi h he ca ea o ensu ing human o e sigh and
explainabili y). I mos inancial b eaches a e occu ing due o la e de ec ion o human e o , manda ing o
s ongly incen i izing he use o au oma ed de ec ion could educe o e all consume ha m. O cou se,
egula o s will also keep an eye on ensu ing AI doesn’ in oduce uncon olled isks (like algo i hmic bias e en
in secu i y con ex s, hough less o an issue he e han in lending o hi ing). Ou esea ch p o ides e idence ha ,
used co ec ly, AI is a ne posi i e o consume p o ec ion.
• S a egic Impac on Fin ech Sec o : Widesp ead adop ion o AI-d i en cybe secu i y could become a
compe i i e ad an age and an expec a ion. Fin ech companies ha in es in hese capabili ies may gain us
om cus ome s and pa ne s (e.g., showing low inciden a es, as con ainmen in hei ack eco d).
Con e sely, hose ha lag migh su e mo e b eaches and epu a ional hi s. In ime, consume s migh e en
inqui e o be in o med abou he secu i y measu es p o ec ing hei da a – simila o how some ech companies
publicize ha hey use ad anced enc yp ion and anomaly de ec ion o sa egua d use in o ma ion. AI in
cybe secu i y migh hus become pa o he alue p oposi ion o in ech p oduc s (implici ly o explici ly).
In conclusion, ou s udy inds ha in eg a ing AI in o o ganiza ional cybe secu i y signi ican ly s eng hens he
p o ec ion o consume da a in in ech. I con i ms many heo e ical bene i s wi h p ac ical e idence: imp o ed
de ec ion accu acy, speed, and b ead h. I also cla i ies he pa h o implemen a ion, highligh ing he need o manage
challenges like ad e sa ial obus ness and compliance. Fin ech o ganiza ions s and o g ea ly bene i om hese
echnologies, and ul ima ely, so do hei cus ome s whose da a and inancial asse s will be mo e secu e. Wi h hough ul
go e nance, con inuous imp o emen , and adhe ence o e hical s anda ds, AI-d i en cybe secu i y can ushe in a new
e a o esilience in he inancial echnology sec o .
6. Conclusion
The con e gence o inance and echnology in in ech has b ough emendous con enience and inno a ion o
consume s, bu i has equally a ac ed sophis ica ed cybe h ea s ha pu sensi i e pe sonal and inancial da a a isk.
This esea ch has p o ided a comp ehensi e examina ion o how a i icial in elligence – pa icula ly deep lea ning
models like LSTM ne wo ks and T ans o me s – can be in eg a ed in o o ganiza ional cybe secu i y o enhance he
p o ec ion o consume da a in he U.S. in ech sec o .
Ou wo k add essed key esea ch ques ions by combining an ex ensi e li e a u e e iew wi h empi ical modeling on
eal-wo ld inspi ed da a. We ound ha AI echniques a e al eady p o ing hei alue in in ech cybe secu i y: hey a e
used o eal- ime in usion de ec ion, aud p e en ion, use beha io analy ics, and h ea in elligence, all o which
con ibu e signi ican ly o sa egua ding cus ome in o ma ion. We ca alogued hese use cases and showed h ough bo h
schola ly e idence and case examples ha AI can de ec anomalies and a acks ha elude adi ional ools, he eby
p e en ing many da a b eaches o limi ing hei impac .
We also con on ed he challenges o adop ing AI in his con ex , om echnical issues like ad e sa ial machine lea ning
and da a sca ci y o ope a ional and e hical conce ns such as model explainabili y and egula o y compliance. A clea
message is ha while AI is a powe ul ally, i is no a sil e bulle – o ganiza ions mus implemen i wi hin a obus
go e nance and isk managemen amewo k. S a egies o mi iga e hese challenges (e.g., obus model aining,
human-in- he-loop o e sigh , p i acy-p ese ing da a handling, and alignmen wi h compliance equi emen s) we e
discussed and should be pa o any in ech’s AI deploymen plan. Ea ly adop e s in he inancial sec o ha e
demons a ed ha hese hu dles can be o e come h ough c oss-disciplina y collabo a ion and i e a i e imp o emen
. Impo an ly, we highligh ed ha egula o y bodies a e acknowledging AI’s po en ial and a e likely o equi e highe
s anda ds o ca e ha AI can help mee , such as as e b each epo ing and s onge au hen ica ion measu es.
Ou expe imen al esul s p o ided s ong quan i a i e backing o he a gumen ha AI can ma kedly imp o e
cybe secu i y ou comes. The deep lea ning models we applied achie ed de ec ion a es abo e 98-99% on complex
a ack da a, a ou pe o ming legacy de ec ion app oaches. In p ac ical e ms, his means an AI-enhanced secu i y
ope a ions cen e would ca ch almos e e y a emp ed in usion o malicious ac i i y, d as ically educing he window
o oppo uni y o a acke s o comp omise consume da a. We showed how a T ans o me -based de ec ion sys em, o
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2819
ins ance, could ha e p e en ed o minimized se e al in amous b eaches had i been in place, by ecognizing he
malicious pa e ns in eal- ime. Fu he mo e, we demons a ed ha hese models ope a e wi h high p ecision, ensu ing
ha secu i y eams can ac on hei ale s wi h con idence and wi hou was e ul dis ac ion om alse ala ms. The
ou come is a i uous cycle: mo e e ec i e de ec ion and esponse leads o ewe b eached eco ds and less equen
inciden s, which in u n bols e s cus ome us and eases egula o y p essu e (since compliance me ics like b each
equency and esponse ime imp o e).
One o he mos compelling indings is he d ama ic educ ion in b each de ec ion and esponse imes ha AI
enables. Ou s udy, in line wi h indus y epo s, sugges s ha in ech i ms using AI-d i en secu i y can iden i y
b eaches on he o de o minu es o hou s a he han days o mon hs. This is ans o ma i e – he di e ence be ween a
mino inciden and a massi e da a leak o en comes down o how quickly he a ack is no iced and s opped. Fo
consume s, his could mean ha e en i hei da a is a ge ed, he a ack migh be s opped be o e any signi ican da a
ex il a ion occu s, o ha hey a e no i ied almos immedia ely o ake p o ec i e ac ions (like changing passwo ds)
a he han inding ou long a e he damage is done.
We conclude ha in eg a ing AI in o in ech cybe secu i y is no jus bene icial bu inc easingly essen ial. As
cybe h ea s con inue o e ol e in sophis ica ion – wi h a acke s hemsel es possibly using AI – adi ional de enses
will likely p o e inadequa e. AI p o ides he adap abili y and lea ning abili y needed o keep pace wi h dynamic h ea s
. Fin ech companies ha le e age AI will be be e posi ioned o p o ec hei cus ome s’ asse s and in o ma ion, comply
wi h da a p o ec ion egula ions, and main ain a s ong epu a ion o secu i y. Con e sely, hose ha do no adop
hese ad ancemen s isk being ou maneu e ed by a acke s and losing consume con idence.
Ou ecommenda ions o in ech o ganiza ions and s akeholde s a e as ollows:
• Adop AI-D i en Secu i y Moni o ing: Implemen machine lea ning models (like hose in his s udy) in
c i ical secu i y moni o ing poin s – ne wo k a ic analysis, applica ion log analysis, and ansac ion
moni o ing. S a wi h high-impac use cases such as in usion de ec ion and aud de ec ion, whe e ma u e
solu ions and models exis . Le e age open da ase s and indings om academic esea ch (such as he CIC-IDS
da ase s o published model a chi ec u es) as baselines o accele a e de elopmen .
• In es in Da a and T aining: Ensu e collec ion o quali y secu i y da a and con inuously label and eed
inciden s back in o he AI aining p ocess. Conside joining indus y da a-sha ing ini ia i es (e.g., FS-ISAC) o
using communi y b each da abases (VCDB) o en ich aining da a while espec ing p i acy. U ilize echniques
like ede a ed lea ning i di ec da a sha ing is no possible, so ha models bene i om a wide ange o h ea
examples.
• S eng hen Go e nance a ound AI: De elop clea policies o AI usage in secu i y. De ine when AI ale s
igge au oma ed ac ions e sus human e iew. Inco po a e AI in o he inciden esponse plan (e.g., “i AI lags
c i ical se e i y, isola e he a ec ed hos immedia ely”). Es ablish o e sigh commi ees ha include
compliance and e hics oles o pe iodically e iew he AI sys em’s decisions o ai ness and accu acy. Main ain
documen a ion and audi ails o AI model upda es and a ionale o decisions o sa is y egula o s and
in e nal audi .
• Add ess Explainabili y and T us : Deploy ools o make AI decisions in e p e able o analys s – o example,
i a T ans o me lags a ansac ion as aud, p o ide he analys wi h a ea u e impo ance o anomaly
explana ion (such as “de ia es om use ’s no mal loca ion and amoun ”). T aining he secu i y eam o
unde s and hese models (pe haps wi h simpli ied men al models o isual aids) will inc ease us and
e ec i e use. In pa allel, educa e execu i es and boa ds abou he alue and limi a ions o AI in mi iga ing cybe
isk, so hey alloca e app op ia e suppo and esou ces.
• Regula ly E alua e and Upda e Models: Cybe h ea s e ol e, and so mus he AI models. Es ablish a cadence
(e.g., qua e ly) o e ain models wi h he la es da a and h ea in elligence. Use ed eams o simula e no el
a ack echniques agains he AI o iden i y blind spo s (ad e sa ial es ing). Moni o model pe o mance
me ics o e ime in p oduc ion – i alse posi i es c eep up o de ec ion a es slip, in es iga e and e ain. By
ea ing he AI models as li ing componen s o he in as uc u e, in echs can ensu e hey emain e ec i e
long- e m.
In e ms o u u e wo k, as esea che s we see he need o u he s udies on deploying hese sys ems in eal, li e
en i onmen s and measu ing ou comes in si u (e.g., educ ion in ac ual b each a es ac oss companies using AI s hose
no using i ). Addi ionally, explo ing mo e explainable and hyb id AI app oaches (combining machine lea ning wi h
ule-based logic) could yield sys ems ha a e bo h accu a e and easie o egula e. Finally, as he a ms ace be ween
a acke s and de ende s con inues, esea ch in o ad e sa ial obus AI o secu i y will be c ucial – ensu ing ha he
nex gene a ion o a acks, possibly AI-assis ed, can s ill be hwa ed by esilien models.
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2820
In conclusion, he in eg a ion o a i icial in elligence in o in ech cybe secu i y eme ges om his s udy as a highly
e ec i e s a egy o enhancing he p o ec ion o consume da a. Wi h AI’s abili y o de ec h ea s swi ly and
accu a ely, in ech companies can signi ican ly educe he likelihood and impac o da a b eaches and aud. This no
only p o ec s consume s om inancial loss and p i acy iola ions bu also s eng hens he o e all in eg i y and s abili y
o he in ech ecosys em. As in ech se ices become e e mo e cen al o daily li e, employing ad anced AI-d i en
de enses will be in eg al o main aining cus ome us and secu ing he inancial u u e. The pa h o wa d calls o
emb acing hese echnologies esponsibly, in o med by bo h echnical e idence and go e nance conside a ions – a
challenge ha he in ech sec o is well-poised o mee , as e idenced by he p omising esul s and ends de ailed in his
wo k.
Compliance wi h e hical s anda ds
Disclosu e o con lic o in e es
No con lic o in e es o be disclosed.
Re e ences
[1] Achu han K, Ramana han S, S ini as S, Raman R. Ad ancing cybe secu i y and p i acy wi h a i icial in elligence:
cu en ends and u u e esea ch di ec ions. F on Big Da a. 2024;7:A icle 1497535.
[2] Ja ahe i D, Fahmideh M, Chiza i H, Lalbakhsh P, Hu J. Cybe secu i y h ea s in FinTech: A sys ema ic e iew.
Expe Sys Appl. 2024; (In p ess). a Xi :2312.01752.
[3] Oluokun A, Ige AB, Ameyaw MN. Building cybe esilience in in ech h ough AI and GRC in eg a ion: An
explo a o y s udy. GSC Ad Res Re . 2024;20(1):228-237.
[4] Dash N, Chak a a y S, Ra h AK, Gi i NC, AboRas KM, Gow ham N. An op imized LSTM-based deep lea ning model
o anomaly ne wo k in usion de ec ion. Sci Rep. 2025;15(1):1554.
[5] A aa MS, Sanad EE, El-Kho ibi RA. In usion de ec ion in so wa e-de ined ne wo ks using deep lea ning
app oaches. Sci Rep. 2024;14(1):29159.
[6] UpGua d. 10 Bigges Da a B eaches in Finance. UpGua d Cybe Risk Blog. Jan 2025.
[7] Secu e ame (Emily Bonnie). 110+ o he La es Da a B each S a is ics [Upda ed 2025]. Secu e ame Blog. Jan
2025.
[8] Iden i y The Resou ce Cen e . 2023 Annual Da a B each Repo . ITRC; Jan 2024.
[9] K oll. Da a B each Ou look: Finance Su passes Heal hca e as Mos B eached Indus y in 2023. K oll Insigh s. Feb
2024.
[10] Secu i yWeek (Ionu A ghi e). Finas a S a s No i ying People Impac ed by Recen Da a B each. Secu i yWeek
News. Feb 18, 2025.
[11] Equi ax Da a B each Repo . (Analysis o he 2017 Equi ax B each) – UpGua d Cybe Risk. 2019.
[12] Fi s Ame ican Financial Co p B each Analysis. (UpGua d) 2019.
[13] T easu y Depa men . Managing AI-Speci ic Cybe secu i y Risks in he Financial Se ices Sec o . US Dep . o
T easu y Repo . Oc 2023.
[14] Sa ke IH. AI in Cybe secu i y: Iden i ying E ol ing Th ea s wi h Adap i e Lea ning. J In Secu . 2023;14(2):115-
130.
[15] Wewege L, Lee A, Thomse C. AI in Finance: Applica ions in Fin ech Secu i y. Fin ech P o ec . 2020;5(3):33-41.
[16] Ko handa aman B, P asad A, Si asanka E. AI-D i en SIEM o Financial Ins i u ions. P oc. IEEE In Con
Cybe Sec. 2023:112-119.
[17] A junan R. De ec ing Phishing Websi es Using NLP and Deep Lea ning. IEEE Access. 2024; 12:10045-10056.
[18] Despo o ić Z, Pa mako ić A, Miljko ić Z. Consequences o Da a B eaches in Finance: Regula o y and Repu a ional
Impac . J Financ C ime. 2023;30(1):128-142.
Wo ld Jou nal o Ad anced Resea ch and Re iews, 2025, 26(01), 2802-2821
2821
[19] Vinuesa R, e al. The Role o A i icial In elligence in Achie ing he Sus ainable De elopmen Goals. Na Commun.
2020; 11:233.
[20] Ap uzzese G, e al. Deep Lea ning o Anomaly De ec ion in Cybe secu i y. IEEE T ans Neu al Ne w Lea n Sys .
2022; (Ea ly Access).