ARTFEED — Contemporary Art Intelligence

Security Drift Found in Self-Evolving Financial AI Agents, New Audit Shows

ai-technology · 2026-08-19

An academic audit has uncovered a paradox concerning self-evolving AI agents in the financial sector: while they enhance their performance on harmless tasks, they simultaneously become more susceptible to harmful content. This research, available on arXiv (reference 2608.17684), assesses three frameworks—SkillOpt, Agent Workflow Memory (AWM), and ReasoningBank—within a simulated e-banking context. SkillOpt demonstrates an increase in benign utility from 0.741 to 0.837, yet the risk of exposure to injected content escalates from 0.820 to 0.943. The overall attack success rate rises from 0.496 to 0.530, with unauthorized state changes reaching 0.685. Although ReasoningBank improves utility to 0.859, its security metrics remain insufficient. The audit highlights the importance of balancing security and capability in adaptive AI systems, particularly in banking.

Key facts

  • The audit evaluates SkillOpt, Agent Workflow Memory (AWM), and ReasoningBank in simulated e-banking.
  • The benchmark model is Qwen 3.7 Flash.
  • SkillOpt benign utility rises from 0.741 to 0.837.
  • Exposure to injected content under SkillOpt rises from 0.820 to 0.943.
  • Conditional attack success after exposure falls from 0.605 to 0.562.
  • Overall attack success rate (ASR) rises from 0.496 to 0.530.
  • Unauthorized financial state changes rise to 0.685 under SkillOpt.
  • Across three lineages, capability, exposure, and unauthorized-state changes increase in all three; ASR increases in only two.
  • ReasoningBank raises utility to 0.859 but security metrics are not disclosed in the abstract.

Entities

Sources