ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jedrzejewski, Felix Viktor, Fucci, Davide, Adamov, Oleksandr
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909594311196672
author Jedrzejewski, Felix Viktor
Fucci, Davide
Adamov, Oleksandr
author_facet Jedrzejewski, Felix Viktor
Fucci, Davide
Adamov, Oleksandr
contents Large Language Models (LLMs) are currently being integrated into industrial software applications to help users perform more complex tasks in less time. However, these LLM-Integrated Applications (LIA) expand the attack surface and introduce new kinds of threats. Threat modeling is commonly used to identify these threats and suggest mitigations. However, it is a time-consuming practice that requires the involvement of a security practitioner. Our goals are to 1) provide a method for performing threat modeling for LIAs early in their lifecycle, (2) develop a threat modeling tool that integrates existing threat models, and (3) ensure high-quality threat modeling. To achieve the goals, we work in collaboration with our industry partner. Our proposed way of performing threat modeling will benefit industry by requiring fewer security experts' participation and reducing the time spent on this activity. Our proposed tool combines LLMs and Retrieval Augmented Generation (RAG) and uses sources such as existing threat models and application architecture repositories to continuously create and update threat models. We propose to evaluate the tool offline -- i.e., using benchmarking -- and online with practitioners in the field. We conducted an early evaluation using ChatGPT on a simple LIA and obtained results that encouraged us to proceed with our research efforts.
format Preprint
id arxiv_https___arxiv_org_abs_2504_18369
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications
Jedrzejewski, Felix Viktor
Fucci, Davide
Adamov, Oleksandr
Cryptography and Security
Software Engineering
Large Language Models (LLMs) are currently being integrated into industrial software applications to help users perform more complex tasks in less time. However, these LLM-Integrated Applications (LIA) expand the attack surface and introduce new kinds of threats. Threat modeling is commonly used to identify these threats and suggest mitigations. However, it is a time-consuming practice that requires the involvement of a security practitioner. Our goals are to 1) provide a method for performing threat modeling for LIAs early in their lifecycle, (2) develop a threat modeling tool that integrates existing threat models, and (3) ensure high-quality threat modeling. To achieve the goals, we work in collaboration with our industry partner. Our proposed way of performing threat modeling will benefit industry by requiring fewer security experts' participation and reducing the time spent on this activity. Our proposed tool combines LLMs and Retrieval Augmented Generation (RAG) and uses sources such as existing threat models and application architecture repositories to continuously create and update threat models. We propose to evaluate the tool offline -- i.e., using benchmarking -- and online with practitioners in the field. We conducted an early evaluation using ChatGPT on a simple LIA and obtained results that encouraged us to proceed with our research efforts.
title ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2504.18369