A LINDDUN-based Privacy Threat Modeling Framework for GenAI
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866917318084263936 |
|---|---|
| author | Liao, Qianying Bellemans, Jonah Sion, Laurens Jiang, Xue Usynin, Dmitrii Zhou, Xuebing Van Landuyt, Dimitri Desmet, Lieven Joosen, Wouter |
| author_facet | Liao, Qianying Bellemans, Jonah Sion, Laurens Jiang, Xue Usynin, Dmitrii Zhou, Xuebing Van Landuyt, Dimitri Desmet, Lieven Joosen, Wouter |
| contents | As generative AI (GenAI) systems become increasingly prevalent across various technological stacks, the question of how such systems handle sensitive and personal data flows becomes increasingly important. Specifically, both the ability to harness and process large swaths of information as well as their stochastic nature raise key concerns related to both security and privacy. Unfortunately, while some of the traditional security threat modeling can effectively identify certain violations, privacy-related issues are often overlooked. To respond to these challenges, we introduce a novel domain-specific privacy threat modeling framework to support the privacy threat analysis of GenAI-based applications. This framework is constructed through a two-pronged approach: (1) a systematic review of the emerging literature on GenAI privacy threats, and (2) a case-driven application to a representative Chatbot system. These efforts yield a foundational GenAI privacy threat modeling framework built on LINDDUN. The new framework affects three out of the seven privacy threat types of LINDDUN and introduces 100 new GenAI examples to the knowledge base. Its effectiveness is validated on an AI Agent system, which demonstrates that a comprehensive privacy analysis can be supported by the new framework. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2603_06051 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | A LINDDUN-based Privacy Threat Modeling Framework for GenAI Liao, Qianying Bellemans, Jonah Sion, Laurens Jiang, Xue Usynin, Dmitrii Zhou, Xuebing Van Landuyt, Dimitri Desmet, Lieven Joosen, Wouter Cryptography and Security Software Engineering As generative AI (GenAI) systems become increasingly prevalent across various technological stacks, the question of how such systems handle sensitive and personal data flows becomes increasingly important. Specifically, both the ability to harness and process large swaths of information as well as their stochastic nature raise key concerns related to both security and privacy. Unfortunately, while some of the traditional security threat modeling can effectively identify certain violations, privacy-related issues are often overlooked. To respond to these challenges, we introduce a novel domain-specific privacy threat modeling framework to support the privacy threat analysis of GenAI-based applications. This framework is constructed through a two-pronged approach: (1) a systematic review of the emerging literature on GenAI privacy threats, and (2) a case-driven application to a representative Chatbot system. These efforts yield a foundational GenAI privacy threat modeling framework built on LINDDUN. The new framework affects three out of the seven privacy threat types of LINDDUN and introduces 100 new GenAI examples to the knowledge base. Its effectiveness is validated on an AI Agent system, which demonstrates that a comprehensive privacy analysis can be supported by the new framework. |
| title | A LINDDUN-based Privacy Threat Modeling Framework for GenAI |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2603.06051 |