RBC-05: Context-Aware AI Security Testing Framework

Description of Organization

Royal Bank of Canada (RBC) is a global financial institution with a purpose-driven, principles-led approach to delivering leading performance. RBC’s success comes from the 98,000+ employees who leverage their imaginations and insights to bring the bank’s vision, values and strategy to life so it can help its clients thrive and communities prosper. As Canada’s biggest bank and one of the largest in the world, based on market capitalization, RBC has a diversified business model with a focus on innovation and providing exceptional experiences to its 19 million clients in Canada, the U.S. and 27 other countries. Learn more at rbc.com.


Problem area

Assess the evolving effectiveness of traditional jailbreaking and prompt injection testing tools against frontier models and develop context-specific security test cases that account for RBC's unique architecture, code, controls, and hosting infrastructure to ensure real-world threat validation.


Main objectives

Design and implement structured testing methodology using compositional complexity principles to assess guardrail effectiveness against real-world threat scenarios specific to RBC's LLM-based systems and infrastructure.


Scope of work

  1. Literature review
  2. Model + prototype development 
  3. Model performance testing
  4. Final Report

Deliverables 

  • Report
  • Resources
  • New protocols/procedures
  • MVP, demo video, code & documentation, performance measurements & analysis, and architecture diagram & description

Frequency

  • Bi-weekly

Skills and training required 

  1. Agile principles
  2. Research & analytical skills including leveraging GenAI
  3. Presentation skills

Resources required 

Simulated datasets, SME expertise provided by RBC project leaders, specific software, and more to be determined.


NDA or a commercialization agreement for this project?

Yes