Publish Your Threat Models! The benefits far outweigh the dangers
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Kohnfelder, Loren, Shostack, Adam |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Asset-centric Threat Modeling for AI-based Systems
von: von der Assen, Jan, et al.
Veröffentlicht: (2024)
von: von der Assen, Jan, et al.
Veröffentlicht: (2024)
ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications
von: Jedrzejewski, Felix Viktor, et al.
Veröffentlicht: (2025)
von: Jedrzejewski, Felix Viktor, et al.
Veröffentlicht: (2025)
Threat Modelling and Risk Analysis for Large Language Model (LLM)-Powered Applications
von: Tete, Stephen Burabari
Veröffentlicht: (2024)
von: Tete, Stephen Burabari
Veröffentlicht: (2024)
A LINDDUN-based Privacy Threat Modeling Framework for GenAI
von: Liao, Qianying, et al.
Veröffentlicht: (2026)
von: Liao, Qianying, et al.
Veröffentlicht: (2026)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
Introducing Systems Thinking as a Framework for Teaching and Assessing Threat Modeling Competency
von: Joshi, Siddhant S., et al.
Veröffentlicht: (2024)
von: Joshi, Siddhant S., et al.
Veröffentlicht: (2024)
Exploring the Security Threats of Retriever Backdoors in Retrieval-Augmented Code Generation
von: Li, Tian, et al.
Veröffentlicht: (2025)
von: Li, Tian, et al.
Veröffentlicht: (2025)
Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation
von: Lin, Bo, et al.
Veröffentlicht: (2025)
von: Lin, Bo, et al.
Veröffentlicht: (2025)
Fine-Tuning LLMs for Code Mutation: A New Era of Cyber Threats
von: Setak, Mohammad, et al.
Veröffentlicht: (2024)
von: Setak, Mohammad, et al.
Veröffentlicht: (2024)
Who Are "We"? Power Centers in Threat Modeling
von: Shostack, Adam
Veröffentlicht: (2025)
von: Shostack, Adam
Veröffentlicht: (2025)
Mining the YARA Ecosystem: From Ad-Hoc Sharing to Data-Driven Threat Intelligence
von: Esteban, Dectot--Le Monnier de Gouville, et al.
Veröffentlicht: (2026)
von: Esteban, Dectot--Le Monnier de Gouville, et al.
Veröffentlicht: (2026)
An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
von: Maxam III, William P., et al.
Veröffentlicht: (2024)
von: Maxam III, William P., et al.
Veröffentlicht: (2024)
Poster: libdebug, Build Your Own Debugger for a Better (Hello) World
von: Digregorio, Gabriele, et al.
Veröffentlicht: (2025)
von: Digregorio, Gabriele, et al.
Veröffentlicht: (2025)
Integrating APK Image and Text Data for Enhanced Threat Detection: A Multimodal Deep Learning Approach to Android Malware
von: Arifin, Md Mashrur, et al.
Veröffentlicht: (2026)
von: Arifin, Md Mashrur, et al.
Veröffentlicht: (2026)
Deep Learning Model Security: Threats and Defenses
von: Wang, Tianyang, et al.
Veröffentlicht: (2024)
von: Wang, Tianyang, et al.
Veröffentlicht: (2024)
I Know Who Clones Your Code: Interpretable Smart Contract Similarity Detection
von: Liu, Zhenguang, et al.
Veröffentlicht: (2025)
von: Liu, Zhenguang, et al.
Veröffentlicht: (2025)
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
von: Gao, Zeyu, et al.
Veröffentlicht: (2025)
von: Gao, Zeyu, et al.
Veröffentlicht: (2025)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
von: Hamer, Sivana, et al.
Veröffentlicht: (2025)
von: Hamer, Sivana, et al.
Veröffentlicht: (2025)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
von: Liu, Yue, et al.
Veröffentlicht: (2025)
von: Liu, Yue, et al.
Veröffentlicht: (2025)
All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts
von: Sun, Tianle, et al.
Veröffentlicht: (2024)
von: Sun, Tianle, et al.
Veröffentlicht: (2024)
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
von: Han, Linyi, et al.
Veröffentlicht: (2024)
von: Han, Linyi, et al.
Veröffentlicht: (2024)
Evaluating the Role of Security Assurance Cases in Agile Medical Device Development
von: Fransson, Max, et al.
Veröffentlicht: (2024)
von: Fransson, Max, et al.
Veröffentlicht: (2024)
LLM-enabled Applications Require System-Level Threat Monitoring
von: Zhang, Yedi, et al.
Veröffentlicht: (2026)
von: Zhang, Yedi, et al.
Veröffentlicht: (2026)
Extending the OWASP Multi-Agentic System Threat Modeling Guide: Insights from Multi-Agent Security Research
von: Krawiecka, Klaudia, et al.
Veröffentlicht: (2025)
von: Krawiecka, Klaudia, et al.
Veröffentlicht: (2025)
Chimera: Harnessing Multi-Agent LLMs for Automatic Insider Threat Simulation
von: Yu, Jiongchi, et al.
Veröffentlicht: (2025)
von: Yu, Jiongchi, et al.
Veröffentlicht: (2025)
A Modular Approach to Automatic Cyber Threat Attribution using Opinion Pools
von: Teuwen, Koen T. W.
Veröffentlicht: (2024)
von: Teuwen, Koen T. W.
Veröffentlicht: (2024)
Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models
von: Yang, Zhou, et al.
Veröffentlicht: (2023)
von: Yang, Zhou, et al.
Veröffentlicht: (2023)
Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
von: Guo, Ziyi, et al.
Veröffentlicht: (2024)
von: Guo, Ziyi, et al.
Veröffentlicht: (2024)
Model-Checking the Implementation of Consent
von: Pardo, Raúl, et al.
Veröffentlicht: (2024)
von: Pardo, Raúl, et al.
Veröffentlicht: (2024)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
von: Zhao, Jian, et al.
Veröffentlicht: (2024)
von: Zhao, Jian, et al.
Veröffentlicht: (2024)
Large Language Models-Aided Program Debloating
von: Lin, Bo, et al.
Veröffentlicht: (2025)
von: Lin, Bo, et al.
Veröffentlicht: (2025)
State Machine Model for The Update Framework (TUF)
von: Romansky, Brian, et al.
Veröffentlicht: (2025)
von: Romansky, Brian, et al.
Veröffentlicht: (2025)
Large Language Model assisted Hybrid Fuzzing
von: Meng, Ruijie, et al.
Veröffentlicht: (2024)
von: Meng, Ruijie, et al.
Veröffentlicht: (2024)
LLM-Assisted Model-Based Fuzzing of Protocol Implementations
von: Huang, Changze, et al.
Veröffentlicht: (2025)
von: Huang, Changze, et al.
Veröffentlicht: (2025)
Exposing and Defending Membership Leakage in Vulnerability Prediction Models
von: Liao, Yihan, et al.
Veröffentlicht: (2025)
von: Liao, Yihan, et al.
Veröffentlicht: (2025)
Malicious ML Model Detection by Learning Dynamic Behaviors
von: Nambiar, Sarang, et al.
Veröffentlicht: (2026)
von: Nambiar, Sarang, et al.
Veröffentlicht: (2026)
Vulnerability Detection in Popular Programming Languages with Language Models
von: Atiiq, Syafiq Al, et al.
Veröffentlicht: (2024)
von: Atiiq, Syafiq Al, et al.
Veröffentlicht: (2024)
On the effectiveness of Large Language Models for GitHub Workflows
von: Zhang, Xinyu, et al.
Veröffentlicht: (2024)
von: Zhang, Xinyu, et al.
Veröffentlicht: (2024)
Evaluating Large Language Models in detecting Secrets in Android Apps
von: Alecci, Marco, et al.
Veröffentlicht: (2025)
von: Alecci, Marco, et al.
Veröffentlicht: (2025)
Understanding the Supply Chain and Risks of Large Language Model Applications
von: Ma, Yujie, et al.
Veröffentlicht: (2025)
von: Ma, Yujie, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
Asset-centric Threat Modeling for AI-based Systems
von: von der Assen, Jan, et al.
Veröffentlicht: (2024) -
ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications
von: Jedrzejewski, Felix Viktor, et al.
Veröffentlicht: (2025) -
Threat Modelling and Risk Analysis for Large Language Model (LLM)-Powered Applications
von: Tete, Stephen Burabari
Veröffentlicht: (2024) -
A LINDDUN-based Privacy Threat Modeling Framework for GenAI
von: Liao, Qianying, et al.
Veröffentlicht: (2026) -
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
von: Huang, Charoes, et al.
Veröffentlicht: (2026)