Mphasis AI & Cybersecurity Research Co-Lab for Financial Service

The rapid digitization of the Banking, Financial Services, and Insurance (BFSI) sector has introduced unprecedented efficiencies while simultaneously escalating risks in data privacy and cybersecurity. To address these challenges, IITB Trust Lab, in partnership with Mphasis, has established a dedicated research facility focused on advancing Privacy-Enhancing Technologies (PETs).

The digitization of India’s Banking, Financial Services, and Insurance (BFSI) sector has delivered speed and financial inclusion. This strong digital foundation has enabled remarkable growth in digital payments. The Unified Payments Interface (UPI) has emerged as the central pillar of India’s digital payment ecosystem. In December 2025 alone, UPI processed over 21 billion transactions valued at more than 27 lakh crore

With instant digital payments and open API networks scaling across the country, India now absorbs over 500 malware detections every minute, with CERT-In handling millions of cyber incidents annually and the financial sector remaining a primary target. Threat actors are deploying AI-driven credential theft that can bypass basic security.

Standard firewalls, antivirus software, or simple access controls are no longer enough. If an attacker breaches the perimeter today, the underlying data is instantly vulnerable. Closing this exposure requires shifting to mathematically provable, privacy-preserving architectures so that even if a network perimeter is compromised, the data remains cryptographically locked and unreadable.

Privacy-Enhancing Technologies (PETs)

Privacy-Enhancing Technologies (PETs) is the name given to mathematical frameworks and specialized techniques that allow systems to derive value from data—analyzing it, sharing it, training AI models on it, or verifying transactions—without ever exposing the underlying sensitive raw data.

Instead of hiding data behind walls or stripping names from a spreadsheet, PETs fundamentally alter how computation happens on sensitive data.

Legacy security technologies handled two states: Data at Rest (encrypted on a disk) and Data in Transit (encrypted across a network). However, to run fraud detection models, process credit risk, or perform cross-bank checks, legacy security required decrypting the data into memory. That created the Data in Use vulnerability gap:

  • Static Encryption (AES, TLS): Protects data stored in databases or moving across wires.
    Failure point: The moment a database processes a query, data must be decrypted in RAM, making it vulnerable.
  • Basic Anonymization & Masking: Removing names, Aadhaar numbers, or PAN IDs from datasets.
    Failure point:Re-identification attacks. Combining “anonymized” financial data with public datasets can reveal individual identities.
  • Access Control & Firewalls: Relying on permissions to block bad actors.
    Failure point: Once an attacker breaches the perimeter or compromises credentials, they get raw access to all cleartext data inside.

Modern PETs use the following tools and techniques to protect data while in use:

  • Homomorphic Encryption (HE): Computes mathematical operations directly on encrypted ciphertext without decrypting it first. The server processes data without ever seeing what the data actually is.
  • Federated Learning (FL) & Multi-Party Computation (MPC): AI models train locally at each bank; only cryptographically blinded parameters are combined. This helps banks jointly detect cross-institutional fraud without sharing raw customer files.
  • Zero-Knowledge Proofs (ZKP): Mathematically prove a statement is true — e.g., “income > 10L” — without revealing the underlying value. Proves things like creditworthiness without exposing exact account balances or credentials.
  • Differential Privacy (DP): Adds mathematically calibrated noise to query responses or models, thus guaranteeing that no single individual’s presence or absence can be inferred from aggregate outputs.

Research Domains

The research framework of the Co-Lab is built upon several strategically aligned domains that address the practical needs of the financial sector. Central to this work is the development of Privacy-Enhancing Technologies (PETs) and AI-enabled cybersecurity.

Research in Applied Cryptography and Secure Systems provides the technical bedrock for these tools, while dedicated efforts in Capacity Building and Industry Engagement ensure that the resulting knowledge is disseminated to professionals and translated into national policy.

The lab also prioritizes Data Protection and Regulatory Alignment, ensuring that all new tools and technologies meet evolving legal standards.

A New Dedicated Lab Space for Research

Earlier this year, we hosted an exclusive two-day workshop for senior officials from the BFSI sector. The forum served as a bridge between India’s premier academic researchers at IIT Bombay and industry leaders to address the intensifying cyber threat landscape.

A dedicated brainstorming session with Mphasis Leadership resulted in the evaluation of research proposals. These proposals, refined based on leadership feedback, address specific issues and pain points in the sector.

During the workshop, the Mphasis team visited the IIT Bombay campus for an exclusive walkthrough of the designated facility and proposed layout for the new collaborative lab. Establishing a dedicated physical space with specialized computing infrastructure is vital as it helps simulate complex real-world cyber threats, and test new tools and technologies. Once fully refurbished, this facility will serve as an advanced innovation hub for next-generation, BFSI-centric cybersecurity research, with the official inauguration set to take place soon.

We look forward to this strategic partnership with Mphasis and the journey ahead as we build the next generation of financial security. Mathematically provable, privacy-first infrastructure is an absolute necessity for national digital trust. Together, we are committed to translating frontier research into deployable, real-world solutions that will protect the future of the financial services sector.