A LINDDUN-based Privacy Threat Modeling Framework for GenAI

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liao, Qianying, Bellemans, Jonah, Sion, Laurens, Jiang, Xue, Usynin, Dmitrii, Zhou, Xuebing, Van Landuyt, Dimitri, Desmet, Lieven, Joosen, Wouter
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917318084263936
author Liao, Qianying
Bellemans, Jonah
Sion, Laurens
Jiang, Xue
Usynin, Dmitrii
Zhou, Xuebing
Van Landuyt, Dimitri
Desmet, Lieven
Joosen, Wouter
author_facet Liao, Qianying
Bellemans, Jonah
Sion, Laurens
Jiang, Xue
Usynin, Dmitrii
Zhou, Xuebing
Van Landuyt, Dimitri
Desmet, Lieven
Joosen, Wouter
contents As generative AI (GenAI) systems become increasingly prevalent across various technological stacks, the question of how such systems handle sensitive and personal data flows becomes increasingly important. Specifically, both the ability to harness and process large swaths of information as well as their stochastic nature raise key concerns related to both security and privacy. Unfortunately, while some of the traditional security threat modeling can effectively identify certain violations, privacy-related issues are often overlooked. To respond to these challenges, we introduce a novel domain-specific privacy threat modeling framework to support the privacy threat analysis of GenAI-based applications. This framework is constructed through a two-pronged approach: (1) a systematic review of the emerging literature on GenAI privacy threats, and (2) a case-driven application to a representative Chatbot system. These efforts yield a foundational GenAI privacy threat modeling framework built on LINDDUN. The new framework affects three out of the seven privacy threat types of LINDDUN and introduces 100 new GenAI examples to the knowledge base. Its effectiveness is validated on an AI Agent system, which demonstrates that a comprehensive privacy analysis can be supported by the new framework.
format Preprint
id arxiv_https___arxiv_org_abs_2603_06051
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle A LINDDUN-based Privacy Threat Modeling Framework for GenAI
Liao, Qianying
Bellemans, Jonah
Sion, Laurens
Jiang, Xue
Usynin, Dmitrii
Zhou, Xuebing
Van Landuyt, Dimitri
Desmet, Lieven
Joosen, Wouter
Cryptography and Security
Software Engineering
As generative AI (GenAI) systems become increasingly prevalent across various technological stacks, the question of how such systems handle sensitive and personal data flows becomes increasingly important. Specifically, both the ability to harness and process large swaths of information as well as their stochastic nature raise key concerns related to both security and privacy. Unfortunately, while some of the traditional security threat modeling can effectively identify certain violations, privacy-related issues are often overlooked. To respond to these challenges, we introduce a novel domain-specific privacy threat modeling framework to support the privacy threat analysis of GenAI-based applications. This framework is constructed through a two-pronged approach: (1) a systematic review of the emerging literature on GenAI privacy threats, and (2) a case-driven application to a representative Chatbot system. These efforts yield a foundational GenAI privacy threat modeling framework built on LINDDUN. The new framework affects three out of the seven privacy threat types of LINDDUN and introduces 100 new GenAI examples to the knowledge base. Its effectiveness is validated on an AI Agent system, which demonstrates that a comprehensive privacy analysis can be supported by the new framework.
title A LINDDUN-based Privacy Threat Modeling Framework for GenAI
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2603.06051