LLM-Driven Compliance Copilot for FAPI 2.0 and SRC Specifications

Authors

  • Vijay Kumar Soni Discover Financial Services, USA Author
  • Naveen Kumar Siripuram NextEra Energy, USA Author
  • Lavanya Shanmugam Tata Consultancy Services, USA Author

Keywords:

FAPI 2.0, Secure Remote Commerce, OpenAPI, Terraform, proofs-of-possession, DevSecOps

Abstract

The objective of this article is to introduce a Large Language Model (LLM)-based compliance copilot for FAPI 2.0 and Secure Remote Commerce (SRC) standards. The proposed system fine-tunes a domain-specific LLM on OpenAPI standards and Terraform IaC stacks to automatically create red-line diffs and compliance artifacts that meet security, identity, and transaction assurance criteria. 

Downloads

Download data is not yet available.

References

OpenID Foundation, “Financial-grade API (FAPI) Part 2: Read and Write API Security Profile,” OpenID Foundation, Tech. Rep., Feb. 2018.

EMVCo, “EMV 3-D Secure Protocol and Core Functions Specification,” EMVCo, Version 2.1.0, Sep. 2017.

PCI Security Standards Council, “PCI DSS: Payment Card Industry Data Security Standard,” Version 3.2, Apr. 2018.

L. Chen et al., “OpenAPI Specification: A Standard for RESTful API Descriptions,” IEEE Software, vol. 34, no. 3, pp. 96–99, May/Jun. 2017.

H. Wang et al., “Terraform: Infrastructure as Code for Cloud Provisioning,” in Proc. IEEE International Conference on Cloud Engineering, 2017, pp. 119–125.

D. Bahdanau, K. Cho, and Y. Bengio, “Neural Machine Translation by Jointly Learning to Align and Translate,” in Proc. International Conference on Learning Representations, 2015.

T. Brown et al., “Language Models are Few-Shot Learners,” arXiv preprint arXiv:2005.14165, 2020.

A. Vaswani et al., “Attention Is All You Need,” in Proc. 31st Conference on Neural Information Processing Systems (NIPS), 2017, pp. 6000–6010.

R. S. Sutton and A. G. Barto, Reinforcement Learning: An Introduction, 2nd ed., Cambridge, MA: MIT Press, 2018.

M. Fowler, Continuous Integration: Improving Software Quality and Reducing Risk, Boston, MA: Addison-Wesley, 2006.

OWASP, “OWASP Top Ten: The Ten Most Critical Web Application Security Risks,” The Open Web Application Security Project, 2017.

F. Chollet, Deep Learning with Python, Shelter Island, NY: Manning Publications, 2017.

NIST, “Framework for Improving Critical Infrastructure Cybersecurity,” National Institute of Standards and Technology, Version 1.1, Apr. 2018.

T. M. Mitchell, Machine Learning, New York, NY: McGraw-Hill, 1997.

J. H. Saltzer and M. D. Schroeder, “The Protection of Information in Computer Systems,” Proc. IEEE, vol. 63, no. 9, pp. 1278–1308, Sep. 1975.

J. M. Wing, “Computational Thinking,” Communications of the ACM, vol. 49, no. 3, pp. 33–35, Mar. 2006.

J. An and S. Cho, “Variational Autoencoder Based Anomaly Detection Using Reconstruction Probability,” Special Lecture on IE, vol. 2, no. 1, pp. 1–18, 2015.

G. Klein et al., “Using Formal Methods to Validate Security Properties of Protocols,” IEEE Security & Privacy, vol. 2, no. 2, pp. 32–39, Mar./Apr. 2004.

B. Schneier, Applied Cryptography: Protocols, Algorithms, and Source Code in C, 2nd ed., New York, NY: Wiley, 1996.

R. Sandhu et al., “Role-Based Access Control Models,” Computer, vol. 29, no. 2, pp. 38–47, Feb. 1996.

Downloads

Published

01-04-2018

How to Cite

[1]
Vijay Kumar Soni, Naveen Kumar Siripuram, and Lavanya Shanmugam, “LLM-Driven Compliance Copilot for FAPI 2.0 and SRC Specifications”, American J Cognit Comput AI Syst, vol. 2, pp. 69–101, Apr. 2018, Accessed: Jul. 29, 2026. [Online]. Available: https://ajccai.org/index.php/publication/article/view/22