Security Risk Assessment and Layered Protection Strategies for Large Language Model Banking Chatbots with Privacy Considerations
Abstract
Abstract But now, given the AI revolution and increased interest in bringing virtual agents and assistants to life banks too are testing LLM-powered AI agents that may assist customers, explain and customize products as well as simplify operational work done by bank employees in the background. But similar systems are susceptible to prompt injection, insecure output handling, and other LLM-specific threats that had only become more prevalent since these publications. Existing surveys and frameworks survey the generic security space of LLMs but do not propose reach an end-to-end, banking-specific threat model nor deployable defense architecture for assistants in line with systems from core into the edge. We also present a data-privacy-aware threat model and a learnable multi-layer defense framework for LLM-based banking assistants. We showcase a reference architecture for an omnichannel banking chatbots built using an instruction-tuned, medium-scale commercial LLM and also access to tools for accessing customer data, payments and knowledge bases. Assets, trust boundaries, adversary capabilities, and a banking-related threat taxonomy based on OWASP LLM guidance in combination with the NIST AI Risk Management Framework and recent sector-wide reports are defined. We then present a defense-in-depth framework with which we employ: governing inputs, prompt level controls, policy enforcement in the orchestration layer, safety guards at the tool-layer, structured output filtering along with response-risk scoring and constant monitoring and governance. We introduce a prototype framework for an effective LLM API designed to mimic digital banking assistant responses and evaluate against synthesized and real-world banking dialogues. This analysis will comprise 48 attack models based on the use of SMS injection techniques, leaking data or other misuses or abuses of authenticated tools. The framework decreases the overall success rates of attacks from 68–79% to between 14–24% across three common styles of attack, while introducing an average response time overhead of less than 11.8%, a modest increase in token consumption and maintaining false alarm rates below 7%. We, too, explore how the results dovetail with the growing regulatory landscape for AI in financial services and how banks can choose to tailor the framework according to their risk appetite and legacy infrastructure constraints Keywords:Artificial intelligence, machine learning, deep learning, natural language processing systems, data privacy, network security