Skip to content
Research Article Open access CC BY 4.0

Prompt Injection and Training Data Poisoning as Emerging Threats to PCI DSS–Protected Financial Data

Suleiman S. Abba, Temitope Ibrahim Lawal, Pelumi Damola Adeyinka, Akinde Michael Ogunmolu, Abayomi Titilola Olutimehin

Asian Journal of Research in Computer Science · pp. 53–75 · Published 21 Mar 2026

10.9734/ajrcos/2026/v19i3836

Abstract

This study examines how prompt injection and training data poisoning compromise artificial intelligence (AI) systems operating within PCI DSS–protected financial environments and evaluates the adequacy of existing compliance controls in addressing these emerging threats. A multi-phase quantitative research design was employed, integrating controlled convolutional neural network (CNN)–based poisoning simulation, logistic regression modeling using categorized breach variables, PCI DSS v4.0 compliance gap index construction, and Structural Equation Modeling (SEM) to validate a proposed AI security governance framework. Experimental results indicate that even minimal poisoning can produce substantial latent compromise: at a 5% poisoning rate, attack success reached 78.6% despite only a 4.6% decline in overall model accuracy. Logistic regression analysis further revealed that logging failures significantly reduce breach detection likelihood by 76% (OR = 0.24, p < .001), highlighting the central role of monitoring controls in compliance-based security architectures. Compliance coverage analysis identified a substantial governance gap, with only 33.3% of PCI DSS domains explicitly addressing prompt injection risks, producing an explicit coverage deficit of 66.7%. The largest control deficiencies were observed in domains related to transmission encryption, authentication, anti-malware protections, and secure model governance, which provide limited safeguards against AI-specific manipulation. Structural modeling results demonstrated strong explanatory power (R² = 0.74), with preventive lifecycle controls exerting the strongest influence on AI risk reduction (γ = 0.61). These findings highlight that financial institutions may remain technically compliant with PCI DSS while AI-driven systems remain vulnerable to adversarial manipulation. The study therefore recommends incorporating explicit AI lifecycle governance, continuous model integrity monitoring, and strengthened third-party AI oversight into PCI DSS revisions to improve resilience of AI-enabled financial infrastructures.

Prompt injection attacks training data poisoning PCI DSS compliance gap adversarial machine learning in finance AI governance controls

Cited by 0

No indexed citations yet.

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

0

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.