ThreatLens: LLM-guided Threat Modeling and Test Plan Generation for Hardware Security Verification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Saha, Dipayan, Shaikh, Hasan Al, Tarek, Shams, Farahmandi, Farimah
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916731586347008
author Saha, Dipayan
Shaikh, Hasan Al
Tarek, Shams
Farahmandi, Farimah
author_facet Saha, Dipayan
Shaikh, Hasan Al
Tarek, Shams
Farahmandi, Farimah
contents Current hardware security verification processes predominantly rely on manual threat modeling and test plan generation, which are labor-intensive, error-prone, and struggle to scale with increasing design complexity and evolving attack methodologies. To address these challenges, we propose ThreatLens, an LLM-driven multi-agent framework that automates security threat modeling and test plan generation for hardware security verification. ThreatLens integrates retrieval-augmented generation (RAG) to extract relevant security knowledge, LLM-powered reasoning for threat assessment, and interactive user feedback to ensure the generation of practical test plans. By automating these processes, the framework reduces the manual verification effort, enhances coverage, and ensures a structured, adaptable approach to security verification. We evaluated our framework on the NEORV32 SoC, demonstrating its capability to automate security verification through structured test plans and validating its effectiveness in real-world scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2505_06821
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ThreatLens: LLM-guided Threat Modeling and Test Plan Generation for Hardware Security Verification
Saha, Dipayan
Shaikh, Hasan Al
Tarek, Shams
Farahmandi, Farimah
Cryptography and Security
Artificial Intelligence
Emerging Technologies
Current hardware security verification processes predominantly rely on manual threat modeling and test plan generation, which are labor-intensive, error-prone, and struggle to scale with increasing design complexity and evolving attack methodologies. To address these challenges, we propose ThreatLens, an LLM-driven multi-agent framework that automates security threat modeling and test plan generation for hardware security verification. ThreatLens integrates retrieval-augmented generation (RAG) to extract relevant security knowledge, LLM-powered reasoning for threat assessment, and interactive user feedback to ensure the generation of practical test plans. By automating these processes, the framework reduces the manual verification effort, enhances coverage, and ensures a structured, adaptable approach to security verification. We evaluated our framework on the NEORV32 SoC, demonstrating its capability to automate security verification through structured test plans and validating its effectiveness in real-world scenarios.
title ThreatLens: LLM-guided Threat Modeling and Test Plan Generation for Hardware Security Verification
topic Cryptography and Security
Artificial Intelligence
Emerging Technologies
url https://arxiv.org/abs/2505.06821