Department of Financial Engineering, HEC Montréal, Montréal, Quebec, Canada.
International Journal of Science and Research Archive, 2026, 19(03), 1139-1153
Article DOI: 10.30574/ijsra.2026.19.3.1404
Received on 19 May 2026; revised on 28 June 2026; accepted on 30 June 2026
Machine learning models are now embedded across the operational core of financial infrastructure: trading and forecasting engines, credit-scoring pipelines, and fraud and anti-money-laundering screens. A decade of research on adversarial examples has shown that high-accuracy classifiers can be flipped by perturbations that are imperceptible or economically negligible, yet the implications for financial deployments—where inputs are partly attacker-controlled and decisions move money—remain unevenly understood. We characterise the adversarial threat surface of financial AI systems and quantify, in a controlled and fully reproducible setting, how much predictive accuracy degrades under gradient-based evasion attacks and how much of that loss adversarial training recovers. We formalise a threat model spanning white-box and black-box adversaries with a feature-space perturbation budget, and give self-contained derivations of the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). On the real, public UCI Adult income-classification dataset—a standard tabular credit-style benchmark—we attack several model families with FGSM and PGD across a range of ℓ∞ perturbation magnitudes and PGD step counts, then retrain with a min–max adversarial objective and re-measure robustness, including an adversarial-training-strength ablation and a cross-model transfer study. Clean test accuracy of the baseline model is high (85.3%) but degrades steadily under attack: PGD restricted to the six continuous features drives accuracy from 85.3% to 79.4% at ε = 0.10 and to 64.8% at ε = 0.30. Adversarial training recovers nearly all of the lost robust accuracy—raising PGD-attacked accuracy at ε = 0.10 from 79.4% to 83.9% and at ε = 0.30 from 64.8% to 81.3%—at a clean-accuracy cost of under half a point (85.3% → 84.9%). White-box perturbations transfer with reduced but non-negligible potency to independently trained models. We argue for robustness-aware evaluation, perturbation-budget reasoning grounded in market microstructure, and defence-in-depth that does not rely on adversarial training alone. All numbers are produced on the public Adult dataset by the included script; we make no measurements of any live system.
Adversarial robustness; Financial machine learning; Evasion attacks; Projected gradient descent; Adversarial training; Transferability.
Preview Article PDF
Samy El Amali. Adversarial robustness of AI systems in financial infrastructure: An empirical study of evasion attacks and defensive training on the Adult Dataset. International Journal of Science and Research Archive, 2026, 19(03), 1139-1153. Article DOI: https://doi.org/10.30574/ijsra.2026.19.3.1404.






