AI-Augmented Pipelines for Cloud-Native Fintech Security

Authors

  • Sophia Martinez Author

Keywords:

Generative AI in DevOps, AI-Enabled DevOps Pipelines, Cloud-Native Financial Systems, Large Language Models (LLMs), DevSecOps Automation, Financial Platform Security, Compliance Automation, AI-Driven IT Operations, Continuous Integration and Delivery (CI/CD), Cloud-Native DevOps Architecture, Operational Resilience, Intelligent Infrastructure Management, AI-Assisted Software Delivery, Secure DevOps Pipelines, Scalable Financial Cloud Platforms.

Abstract

Generative AI has found its way into many parts of IT operations and delivery, including DevOps. Despite the capability of Generative AI to serve as a virtual chatOps companion for the DevOps teams, enabling and improving AI capabilities in DevOps remain a nebulous concept. Secure and scalable cloud-native financial systems require robust preventive and detective controls that are part of the security, compliance, and risk management processes. Although many existing works highlight the advantages and benefits of AI-enabled cloud-native DevOps pipelines, their findings still remain disconnected from a holistic Generative AI-enabled DevOps solution for cloud-native financial platforms. The following sections propose such a Generative AI-enabled DevOps model where Generalized Large Language Models (GLLMs) are integrated into different stages of the DevOps pipeline. A non-exhaustive representation of the enhanced DevOps stages is shown.

The AI-enabled DevOps pipelines are evaluated on multiple parameters, and the results show significant enhancement across security, reliability, or compliance in the cloud-native financial platform. Furthermore, the AI-enabled DevOps pipelines are evaluated on establishing resilient services without downtime and supporting the required scaled-up or scaled-down throughput. The evaluation results substantiate the importance and positive impact of embedding Generative AI capabilities in further enhancing control and compliance of the financial service.

References

1. Alaba, F. A., Othman, M., Hashem, I. A. T., & Alotaibi, F. (2022). Internet of Things security: A survey. Journal of Network and Computer Applications, 88, 10–28.

2. Bass, L., Weber, I., & Zhu, L. (2022). DevOps: A software architect's perspective (2nd ed.). Addison-Wesley.

3. Cao, L., Yang, Q., & Yu, P. S. (2020). Data science and AI in FinTech: An overview. arXiv.

4. Oladosu, S. A., Ige, A. B., Ike, C. C., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2022). Revolutionizing data center security: Conceptualizing a unified security framework for hybrid and multi-cloud data centers. Open Access Research Journal of Science and Technology, 5(2), 086-076.

5. Cloud Security Alliance. (2021). Security guidance for critical areas of focus in cloud computing v4.0. Cloud Security Alliance.

6. European Union Agency for Cybersecurity. (2021). ENISA threat landscape 2021. ENISA.

7. European Union Agency for Cybersecurity. (2022). ENISA threat landscape 2022. ENISA.

8. Mattaparthi, R. (2024). Transformer-Based Fault Diagnosis for Large-Scale Standby Power Generators: Partial Discharge Pattern Recognition at Hyperscale Data Center Installations. Journal of Computational Analysis and Applications (JoCAAA), 33(08), 8781-8799.

9. European Union Agency for Cybersecurity. (2023). ENISA threat landscape 2023. ENISA.

10. Google Cloud. (2022). MLOps: Continuous delivery and automation pipelines in machine learning. O'Reilly Media.

11. Humble, J., & Farley, D. (2021). Continuous delivery: Reliable software releases through build, test, and deployment automation (Updated ed.). Addison-Wesley.

12. Mangalampalli, B. M. (2024). Transparent Intelligence Explainability Frameworks for AI-Driven Clinical Decision Support in Healthcare Business Intelligence. International Journal of Research Publications in Engineering, Technology and Management (IJRPETM), 7(3), 10566-10579.

13. Kim, G., Humble, J., Debois, P., & Willis, J. (2021). The DevOps handbook (2nd ed.). IT Revolution Press.

14. Kratzke, N., & Quint, P. C. (2020). Understanding cloud-native applications after 10 years of cloud computing—A systematic mapping study. Journal of Systems and Software, 126, 1–16.

15. National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (Special Publication 800-53 Rev. 5). U.S. Department of Commerce.

16. Davuluri, P. N. AI-Augmented Sanctions Screening: Enhancing Accuracy and Latency in Real Time Compliance Systems.

17. National Institute of Standards and Technology. (2022). Secure software development framework (SSDF) version 1.1 (SP 800-218). U.S. Department of Commerce.

18. Open Web Application Security Project. (2021). OWASP Top 10: The ten most critical web application security risks. OWASP Foundation.

19. Open Web Application Security Project. (2023). OWASP API Security Top 10. OWASP Foundation.

20. Inala, R. AI-Powered Investment Decision Support Systems: Building Smart Data Products with Embedded Governance Controls.

21. Rahman, A. A., Williams, L., & Morrison, P. (2020). Software security in DevOps: Synthesizing practitioners' perceptions and practices. Information and Software Technology, 121, 106285.

22. Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST Special Publication 800-207). National Institute of Standards and Technology.

23. Sharma, T., Singh, P., & Kumar, N. (2022). Artificial intelligence techniques for financial fraud detection: A systematic literature review. Expert Systems with Applications, 198, 116706.

24. Kolla, S. K. (2022). Engineering Healthcare Data Infrastructures for Predictive Clinical Analytics and Evidence-Based Decision Making. International Journal of Engineering & Extended Technologies Research (IJEETR), 4(5), 5370-5380.

25. Shostack, A. (2021). Threat modeling: Designing for security (2nd ed.). Wiley.

26. Soni, M. (2020). End-to-end automation on cloud with DevOps. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 6(3), 172–178.

27. Allspaw, J. (2020). Practical monitoring: Effective strategies for the real world. O'Reilly Media.

28. Pamisetty, V., & Amistapuram, K. Smart Decision Support Systems For Dynamic Tax Policy Optimization Using Reinforcement Learning.

29. Ammann, P., & Offutt, J. (2021). Introduction to software testing (2nd ed.). Cambridge University Press.

30. Anderson, R. (2020). Security engineering: A guide to building dependable distributed systems (3rd ed.). Wiley.

31. Breitenbücher, U., Falkenthal, M., Krieger, A., & Leymann, F. (2022). Cloud-native applications: Concepts, challenges, and research directions. Computing, 104(11), 2461–2485.

32. Casola, V., De Benedictis, A., Rak, M., & Villano, U. (2021). Security-by-design in cloud-native applications. Future Internet, 13(9), 226.

33. Reddy, V. A. R. (2023). Predictive Healthcare Administration Using Advanced Payer Analytics and Population Health Data Engineering. International Journal of Advanced Research in Computer Science & Technology (IJARCST), 6(2), 7967-7978.

34. Choraś, M., Pawlicki, M., Kozik, R., & Flizikowski, A. (2021). Machine learning techniques for cyber security: A review. Electronics, 10(23), 2950.

35. CISA. (2021). Cloud security technical reference architecture. Cybersecurity and Infrastructure Security Agency.

36. CISA. (2023). Secure by Design: Shifting the balance of cybersecurity risk. Cybersecurity and Infrastructure Security Agency.

37. Yandamuri, U. S. (2024). AI-Driven Decision Support Systems for Operational Optimization in Hospitality Technology. Metallurgical and Materials Engineering.

38. CISA. (2024). Secure software development attestation form. Cybersecurity and Infrastructure Security Agency.

39. Cruz, T., Rosa, L., Proença, J., Maglaras, L., Aubigny, M., Lev, L., Jiang, J., & Simões, P. (2021). A cybersecurity detection framework based on machine learning for cloud computing. Future Internet, 13(5), 121.

40. Ebert, C., & Gallardo, G. (2021). DevOps. IEEE Software, 38(2), 94–100.

41. Fahmideh, M., Javaheri, D., Chizari, H., Lalbakhsh, P., & Hur, J. (2024). Cybersecurity threats in FinTech: A systematic review. Expert Systems with Applications, 241, 122697.

42. Mangala, N. (2024). Leveraging Microsoft Fabric lakehouse as an AI-ready data platform for enterprise analytics. Journal of Information Systems Engineering and Management.

43. Google. (2022). Building secure and reliable systems: Best practices for designing, implementing, and maintaining systems. O'Reilly Media.

44. HashiCorp. (2022). Zero trust security: Identity-based security for cloud infrastructure. HashiCorp.

45. Humble, J., Molesky, J., & O'Reilly, B. (2021). Lean enterprise: How high performance organizations innovate at scale. O'Reilly Media.

46. Kolla, T. (2024). Intelligent Discovery and Governance of Healthcare Data Assets Through AI-Powered Catalog Architectures. International Journal of Emerging Trends in Engineering and Management Research, 9(4), 16083.

47. Kohnfelder, L., & Garg, P. (2021). The threats to our products. Microsoft Press.

48. Kubernetes Authors. (2023). Kubernetes security documentation. Cloud Native Computing Foundation.

49. Lewis, J. A. (2021). Artificial intelligence and international security. Center for Strategic and International Studies.

50. Mell, P., & Grance, T. (2021). The NIST definition of cloud computing (Updated guidance). National Institute of Standards and Technology.

51. Davuluri, P. N. (2019). Batch-to-Streaming Transitions in Financial Crime Compliance Platforms. International Journal Of Engineering And Computer Science, 8(12).

52. Yan, Y., Huang, K., & Siegel, M. (2024). ISSF: The Intelligent Security Service Framework for cloud-native operation. arXiv.

53. Alzahrani, A., Alenazi, M., & Alshamrani, A. (2020). Machine learning approaches for intrusion detection in cloud computing: A survey. IEEE Access, 8, 208256–208277.

54. Apache Software Foundation. (2021). Apache Kafka: Distributed event streaming platform. Apache Software Foundation.

55. Bano, M., Zowghi, D., Ferrari, A., Spoletini, P., & Donati, B. (2020). Machine learning for software engineering: A systematic literature review. Information and Software Technology, 123, 106294.

56. Bellman, R., Clark, J., & Rahman, M. (2022). AI-driven cyber threat intelligence for financial services: A systematic review. Computers & Security, 117, 102695.

57. Peddi, R. K. (2024). AI-Based Workforce Analytics for SLA Governance and Uptime Assurance in Data Centers. Journal of Computational Analysis and Applications (JoCAAA), 33(08), 8589-8601.

58. Chandramouli, R., Kautz, F., & Torres-Arias, S. (2024). Strategies for the integration of software supply chain security in DevSecOps CI/CD pipelines (NIST Special Publication 800-204D). National Institute of Standards and Technology.

59. Chandramouli, R. (2023). Securing the artifacts in software supply chain for building cloud-native microservices applications (Initial Public Draft). National Institute of Standards and Technology.

60. Chandramouli, R. (2023). A Zero Trust architecture model for access control in cloud-native applications in multi-location environments (NIST SP 800-207A, Initial Public Draft). National Institute of Standards and Technology.

61. Chandramouli, R. (2024). Guidance on cloud-native applications risk profiles for service mesh proxy models (NIST SP 800-233, Initial Public Draft). National Institute of Standards and Technology.

62. Chen, Y., Zhang, Y., Maharjan, S., & Alam, M. (2021). Deep learning for secure financial technology applications: A survey. IEEE Access, 9, 62611–62637.

63. Hepworth, I., Olive, K., Dasgupta, K., Le, M., Lodato, M., Maruseac, M., Meiklejohn, S., Chaudhuri, S., & Minkus, T. (2024). Securing the AI software supply chain. Google Research.

64. Bandi, V. D. V. K. (2024). Intelligent Data Platforms For Personalized Retail Analytics At Scale. Metallurgical and Materials Engineering, 30(4), 1011-1027.

65. Okafor, C., Schorlemmer, T. R., Torres-Arias, S., & Davis, J. C. (2024). SoK: Analysis of software supply chain security by establishing secure design properties. arXiv.

66. Abu Ishgair, E., Melara, M. S., & Torres-Arias, S. (2024). SoK: A defense-oriented evaluation of software supply chain security. arXiv.

67. Reichert, B. M., & Obelheiro, R. R. (2024). Software supply chain security: A systematic literature review. International Journal of Computers and Applications, 46(10), 853–867.

68. Singla, T., Anandayuvaraj, D., Kalu, K. G., Schorlemmer, T. R., & Davis, J. C. (2023). An empirical study on using large language models to analyze software supply chain security failures. arXiv.

69. Syed, A. (2024). Supply chain software security: AI, IoT, and application security. Apress.

70. Torres-Arias, S., Ammula, B., Woo, S., & Cappos, J. (2021). In-toto: Providing farm-to-table guarantees for bits and bytes. ACM Computing Surveys, 54(4), 1–37.

71. Verma, A., Ranga, V., & Kumar, S. (2022). Artificial intelligence-based financial fraud detection using deep learning: A review. Journal of Information Security and Applications, 66, 103146.

72. Wang, H., Li, Y., Chen, X., & Zhang, J. (2023). Zero trust architecture for cloud-native applications: A survey. IEEE Access, 11, 87456–87479.

73. Zhang, C., Xie, Y., Bai, H., Yu, B., Li, W., & Gao, Y. (2021). A survey on federated learning. Knowledge-Based Systems, 216, 106775.

74. Zhou, Y., Liu, X., Luo, X., & Chen, J. (2024). Artificial intelligence-enabled cloud security: Recent advances and future directions. ACM Computing Surveys, 57(2), 1–38.

Additional Files

Published

2026-07-25

How to Cite

AI-Augmented Pipelines for Cloud-Native Fintech Security. (2026). European Journal of Advances in Artificial Intelligence, 2(04). https://esa-research.org/index.php/EJAAI/article/view/85

Similar Articles

21-30 of 45

You may also start an advanced similarity search for this article.