FraudBench Stress-Tests Banking AI Agents Against Adaptive Fraud.

Dheeraj Mohandas Pai, Lu Xian· August 20, 2026 View original

Key takeaways

  • Existing fraud benchmarks are insufficient for conversational banking AI agents.
  • FraudBench stress-tests agents against adaptive, policy-grounded conversational fraud.
  • Initial tests show agents have 49-65% attack-security, with common weaknesses in money-mule and first-party fraud.
  • Safety in conversational AI is history-dependent, requiring contextual understanding.

Who benefits

BFSIFinTechCybersecurityAI DevelopmentCustomer Service

Summary

FraudBench is a new benchmark designed to stress-test policy-grounded banking conversational agents against adaptive fraud scenarios. It evaluates how agents handle identity manipulation, authorization, and trust over a conversation, revealing weaknesses in current AI security.

Conversational AI agents in banking are increasingly performing critical tasks like changing contact details or moving money, making their security against fraud paramount. Traditional fraud benchmarks focus on static transactions or generic prompt injections, failing to assess how agents handle sophisticated, conversational fraud attempts that manipulate identity, authorization, and trust. This research introduces FraudBench, a novel executable benchmark specifically designed to stress-test policy-grounded banking agents. FraudBench operates within a simulated banking environment, where both the agent and a simulated caller interact using tools and shared account states, with the agent referencing a 698-document internal policy corpus. The benchmark includes 150 adversarial scenarios, with 107 public tasks covering ten fraud mechanisms and chained adaptive attacks. Initial evaluations of four agents on these tasks showed attack-security rates between 49% and 65%, highlighting common vulnerabilities such as money-mule and first-party fraud. The benchmark emphasizes history-dependent safety, where a seemingly valid later request can become unsafe due to earlier conversational probes.

Why it matters

Financial institutions and AI developers must understand these advanced fraud vectors to build more resilient and secure AI agents, protecting both customers and company assets from sophisticated attacks.

How to implement this in your domain

  1. 1Integrate adversarial testing methodologies like FraudBench into the development lifecycle of banking AI agents.
  2. 2Prioritize training AI agents on robust policy adherence and contextual understanding of user intent.
  3. 3Develop real-time monitoring and intervention systems for suspicious conversational patterns.
  4. 4Collaborate with security experts to identify and mitigate new fraud mechanisms specific to conversational AI.
  5. 5Regularly update policy documents and agent training data to reflect evolving fraud tactics.

Original post by Dheeraj Mohandas Pai, Lu Xian

"arXiv:2608.18136v1 Announce Type: new Abstract: Conversational agents now act for end users through tools while holding access to customer databases and internal policy documents that a caller can reach through dialogue alone. Banking is the clearest case: the same agent that ans…"

View on X

Originally posted by Dheeraj Mohandas Pai, Lu Xian on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses