Beyond the Pipeline Embedding Generative AI Risk Intelligence into Cloud-Native Financial Transaction Architectures
DOI:
https://doi.org/10.5281/zenodo.20443333Keywords:
DevOps, financial services, payments, security, cloud, microservices, infrastructure, continuous delivery, automation, generative AI.Abstract
The increasing frequency, sophistication, and financial impact of cyberattacks against financial institutions demand a proactive instead of a reactive approach. One current direction consists of the adoption of Cloud-Native Architecture principles supported by DevOps practices driven by Automation and AIOps tools supplied as-a-Service by cloud providers. Taking into consideration the property of security for the deployment of Payment Systems is paramount, it is proposed a Security-as-a-Service solution using Generative Artificial Intelligence techniques to induce Risk Models. This approach applied within the Design-and-Build phases of the DevOps Automation might link the application code with the risk/security posture of the Payment System and support effective decision-making regarding the acceptance/rejection of the software deployment or update.
Generative Artificial Intelligence techniques have been used for textual completion since the introduction of the Transformer architecture. It can be used to induce Risk Models since usually a Risk Model can be represented in a tabular structure summarized by its three fundamental components: Asset, Threat, and Vulnerability. Recent advances in confidential computing and secure enclaves enable the processing of sensitive information without exposing the input data.
References
[1] Almoras, M., Grundy, J., & Ibrahim, A. S. (2016). Collaboration-based cloud computing security management framework. Journal of Network and Computer Applications, 62, 31–44.
[2] Arora, S., Barak, B., & Brunner Meier, M. (2023). Measuring the macroeconomic impact of AI. Brookings Papers on Economic Activity, 2023(2), 1–49.
[3] Beyer, B., Jones, C., Petoff, J., & Murphy, N. R. (2016). Site reliability engineering: How Google runs production systems. O’Reilly Media.
[4] Burns, B., Grant, B., Oppenheimer, D., Brewer, E., & Wilkes, J. (2016). Borg, Omega, and Kubernetes. Communications of the ACM, 59(5), 50–57.
[5] Carillo, F., Dal Pozzolo, A., Le Borgne, Y.-A., Caelen, O., Mazdzer, Y., & Bontempi, G. (2019). Scarff: A scalable framework for streaming credit card fraud detection with Spark. Information Fusion, 41, 182–194.
[6] CNCF (Cloud Native Computing Foundation). (2025). Cloud Native 2024: Approaching a decade of code, cloud, and change (Annual survey report). Linux Foundation Research.
[7] Dal Pozole, A., Borachio, G., Caelen, O., Lippi, C., & Bontempi, G. (2018). Credit card fraud detection: A realistic modeling and a novel learning strategy. IEEE Transactions on Neural Networks and Learning Systems, 29(8), 3784–3797.
[8] Dragoni, N., Lanese, I., Larsen, S. T., Mazzara, M., Mustafin, R., & Safina, L. (2017). Microservices: How to make your application scale. In E. Di Nitto & M. Harman (Eds.), Lecture Notes in Computer Science (Vol. 10311). Springer.
[9] Forsgren, N., Humble, J., & Kim, G. (2018). Accelerate: The science of lean software and DevOps. IT Revolution Press.
[10] Geng, T., Xu, Z., Li, H., Liu, X., Zhang, N., & Xiao, C. (2025). Prompt injection attacks on large language models: A survey of attack methods, root causes, and defense strategies. Computers, Materials & Continua, 2025, Article 074081.
[11] Gong, N. Z., & Liu, B. (2024). Trustworthy AI in practice: Attack surfaces, evaluation, and governance. ACM Computing Surveys, 56(10), 1–38.
[12] Google. (2020). Beyond Prod: A new model for production change management in large-scale infrastructure. Google Research.
[13] He, L., Zhang, Y., Wang, H., & Chen, J. (2025). LPRAG: Locally private retrieval-augmented generation with formal privacy guarantees. Information Sciences, 677, 120–139.
[14] Humble, J., & Farley, D. (2010). Continuous delivery: Reliable software releases through build, test, and deployment automation. Addison-Wesley.
[15] International Organization for Standardization. (2022). ISO 20022: Financial services—Universal financial industry message scheme. ISO.
[16] International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection—Information security management systems—Requirements. ISO.
[17] Jaffal, N. O., Alkanofer, M., & Muheisen, D. (2025). Large language models in cybersecurity: A survey of applications, vulnerabilities, and defense techniques. AI, 6(9), 216.
[18] Kim, G., Humble, J., Debois, P., & Willis, J. (2016). The DevOps handbook. IT Revolution Press.
[19] Kreuz Berger, D., Kühl, N., & Hirschl, S. (2023). Machine learning operations (Mops): Overview, definition, and architecture. IEEE Access, 11, 31866–31879.
[20] Li, M. Q., Zhang, H., & Wu, J. (2025). Security concerns for large language models: A survey. arXiv.
[21] MITRE. (2024). SAFE-AI: A framework for securing AI-enabled systems (Technical report). MITRE.
[22] MITRE. (2025). MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems (Knowledge Base). MITRE.
[23] National Institute of Standards and Technology. (2020). Zero trust architecture (NIST Special Publication 800-207). U.S. Department of Commerce.
[24] National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 5). U.S. Department of Commerce.
[25] National Institute of Standards and Technology. (2022). Secure software development framework (SSDF) version 1.1: Recommendations for mitigating the risk of software vulnerabilities (NIST Special Publication 800-218). U.S. Department of Commerce.
[26] National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce.
[27] Newman, S. (2021). Building microservices (2nd ed.). O’Reilly Media.
[28] OWASP. (2023). OWASP Top 10 for Large Language Model Applications (v1.0). OWASP Foundation.
[29] Paleyes, A., Urma, R.-G., & Lawrence, N. D. (2020). Challenges in deploying machine learning: A survey of case studies. ACM Computing Surveys, 54(6), 1–36.
[30] Payment Card Industry Security Standards Council. (2024). Payment Card Industry Data Security Standard: Requirements and security assessment procedures (PCI DSS v4.0.1). PCI SSC.
[31] Rahman, M. A., & colleagues. (2024). Fine-tuned large language models (LLMs) for prompt injection vulnerability analysis. arXiv.
[32] Şaşal, S. (2025). Prompt injection attacks on large language models. In Proceedings of the International Conference on Security and Cryptography (SECRYPT). SCITEPRESS.
[33] Tabassi, E. (2023). Trustworthy and responsible AI: Risk management and measurement challenges. Journal of Information Policy, 13, 1–28.
[34] Xu, W., Liu, Y., & Chen, Z. (2025). A survey of attacks on large language models. arXiv.
[35] Yao, Y., Duan, J., Xu, K., Cai, Y., Sun, Z., & Zhang, Y. (2024). A survey on large language model (LLM) security and privacy: The good, the bad, and the ugly. High-Confidence Computing, 4, 100211.
[36] Zeng, S., Zhang, J., He, P., Xing, Y., Liu, Y., Xu, H., Ren, J., Wang, S., Yin, D., Chang, Y., & Tang, J. (2024). The good and the bad: Exploring privacy issues in retrieval-augmented generation (RAG). In Findings of the Association for Computational Linguistics: ACL 2024.
[37] Zhao, K., & colleagues. (2025). A survey on model extraction attacks and defenses for large language models. arXiv.
[38] Zhou, Y., Zhang, Z., & Chen, X. (2024). Cloud-native security for microservices: A systematic literature review. Journal of Systems and Software, 207, 111836.
[39] Zou, D., Wang, X., & Jin, H. (2023). Service mesh in production: Reliability, observability, and security for microservices. IEEE Software, 40(4), 52–60.
Additional Files
Published
Data Availability Statement
None