article · Asian Journal of Research in Computer Science
This study examines how prompt injection and training data poisoning compromise artificial intelligence (AI) systems operating within PCI DSS–protected financial environments and evaluates the adequacy of existing compliance controls in addressing these emerging threats. A multi-phase quantitative research design was employed, integrating controlled convolutional neural network (CNN)–based poisoning simulation, logistic regression modeling using categorized breach variables, PCI DSS v4.0 compliance gap index construction, and Structural Equation Modeling (SEM) to validate a proposed AI security governance framework. Experimental results indicate that even minimal poisoning can produce substantial latent compromise: at a 5% poisoning rate, attack success reached 78.6% despite only a 4.6% decline in overall model accuracy. Logistic regression analysis further revealed that logging failures significantly reduce breach detection likelihood by 76% (OR = 0.24, p < .001), highlighting the central role of monitoring controls in compliance-based security architectures. Compliance coverage analysis identified a substantial governance gap, with only 33.3% of PCI DSS domains explicitly addressing prompt injection risks, producing an explicit coverage deficit of 66.7%. The largest control deficiencies were observed in domains related to transmission encryption, authentication, anti-malware protections, and secure model governance, which provide limited safeguards against AI-specific manipulation. Structural modeling results demonstrated strong explanatory power (R² = 0.74), with preventive lifecycle controls exerting the strongest influence on AI risk reduction (γ = 0.61). These findings highlight that financial institutions may remain technically compliant with PCI DSS while AI-driven systems remain vulnerable to adversarial manipulation. The study therefore recommends incorporating explicit AI lifecycle governance, continuous model integrity monitoring, and strengthened third-party AI oversight into PCI DSS revisions to improve resilience of AI-enabled financial infrastructures.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.9734/ajrcos/2026/v19i3836
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.