论文73°

AI供应商漏洞如何引发银行系统危机

Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System

精选理由

这篇论文揭示了AI供应商漏洞如何通过银行系统传播,并提供了量化风险评估工具。

该研究构建了一个包含60家AI供应商、220家银行、约2500条服务链和1400条银行间暴露关系的四层异构网络模型。研究提出了CFC-Prop随机传播模型,能重现与先前网络金融证据一致的重尾损失分布。研究还开发了CFC-GNN预警模型,在四个基线测试中达到AUROC 0.82和AUPRC 0.60的准确率。

原文 · arXiv cs.LG

Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System

The banking system now depends on a small set of shared artificial intelligence vendors for fraud screening, credit decisioning, anti-money-laundering triage, customer analytics, and internal decision support. This paper studies how a compromise inside one of those vendors can propagate along a chain of operational, informational, and financial linkages until it triggers losses that look, from the outside, like a classical banking crisis. We build a four-layer heterogeneous network that couples AI vendors, financial institutions, interbank exposures, and customer accounts, and we propose CFC-Prop, a stochastic epidemic-and-clearing model that runs on that network. On a synthetic dataset with 60 vendors, 220 banks, roughly 2,500 vendor-bank service edges, and 1,400 interbank exposures, CFC-Prop reproduces the heavy-tailed loss distributions and the sharp dependence on patch latency that are consistent with prior cyber-financial evidence. We also train an early-warning model, CFC-GNN, that uses vendor-side incident telemetry and graph structure to flag high-cascade-risk vendors before impact. Across four baselines the proposed model reaches AUROC 0.82 and AUPRC 0.60 while keeping calibration errors bounded. We release the full code, synthetic data, and reproducible scripts. The results argue that cyber concentration among AI vendors is a first-order financial-stability problem and give supervisors a concrete quantitative tool for reasoning about it.