arXiv:2605.01892cs.AIcs.CR2026-05被引 1

用AI代理系统提升金融安全中心的推理能力,解决告警过剩与合规难题。

CyberAId: AI-Driven Cybersecurity for Financial Service Providers

论文配图:CyberAId: AI-Driven Cybersecurity for Financial Service Providers
图 1 · 摘自论文原文
  • 构建多智能体系统,让AI代理在传统安全数据上推理,不取代现有系统。
  • 支持跨机构隐私保护协作,可集成量子认证等增强能力。
  • 针对金融场景设计,适合需要高合规性与持续学习的机构使用。

欧洲金融机构面临日益严格的监管压力,但其安全运营中心的瓶颈并非数据或人力,而是推理能力不足:企业级SIEM仅覆盖少数MITRE ATT&CK技术,三分之二的安全团队无法跟上告警数量,多数入侵事件前已有告警却未被调查。前沿大语言模型在单一安全任务(如漏洞利用、代码修复、入侵检测)上表现优异,但尚无系统能跨功能协同、持久化多租户状态、映射至监管框架并经受审计。本文提出,应以混合多智能体系统为基本构建单元,由专业化LLM子代理在经典SIEM/XDR数据上推理,通过隐私保护联邦机制共享代理状态,并可接入量子认证、对抗性验证数字孪生、eBPF内核遥测等能力包。我们提出CyberAId平台——一个模型无关、可本地部署的系统,包含主代理协调层、报告模块及专业子代理,在有限人工干预下运行,遵循四个可验证的设计原则,符合相关法规。将在四类典型金融场景(客户冒充、支付服务商反洗钱、零售银行事件响应、高频交易韧性)中验证,并建议基于技能的代理自适应作为推动集体防御持续优化的关键方向。

原文摘要 · Abstract (English)

European financial institutions face mounting regulatory pressure while their security operations centres remain constrained not by data or staffing but by reasoning capacity: enterprise SIEMs cover only a fraction of MITRE ATT&CK techniques, two thirds of SOC teams cannot keep pace with alert volumes, and the majority of breaches are preceded by alerts that are generated but never investigated. Frontier large language models now achieve state-of-the-art results on isolated cybersecurity tasks (one-day vulnerability exploitation, code-level patching, intrusion detection) yet no narrow win constitutes a platform that can compose across functions, persist multi-tenant state, map findings to regulatory regimes and survive an audit. This position paper argues that the right unit of construction is a hybrid multi-agent system in which specialised LLM subagents reason over classical SIEM/XDR telemetry rather than replacing it, share accumulated agent state across institutions through privacy-preserving federation, and can connect to complementary capability packs such as quantum-based authentication, digital twins for adversarial validation, and eBPF-based kernel telemetry. We present CyberAId, a model-agnostic, on-premise-deployable platform in which a Main Agent coordination layer, a Reporting capability, and specialist subagents operate within a shared runtime under bounded human-in-the-loop autonomy, organised around four falsifiable design principles, and aligned with relevant regulations. CyberAId will be validated at four representative financial use cases (client impersonation, anti-money-laundering for payment service providers, retail-banking incident response, and high-frequency-trading resilience) and propose skill-based agent adaptation as the most promising research direction for turning each deployment into a contribution to a continuously refined collective defence.

AI安全多智能体金融风控

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。