STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Cyrille, Tsafac Nkombong Regine, Schwarz, Franziska
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909052044312576
author Cyrille, Tsafac Nkombong Regine
Schwarz, Franziska
author_facet Cyrille, Tsafac Nkombong Regine
Schwarz, Franziska
contents Traditional cybersecurity methodologies target deterministic systems and fail to address the probabilistic nature of AI, leaving systems vulnerable to attack vectors such as model inversion, data poisoning, and prompt injection. Recent industry reports indicate that a majority of organizations deploying AI lack a dedicated security strategy, with adversarial attacks increasing rapidly year-over-year. We present \textit{STRIDE-AI}, a framework that bridges the gap between high-level risk standards (NIST AI RMF) and technical vulnerability taxonomies (OWASP LLM Top 10). The framework defines a six-phase assessment lifecycle, introduces a threat modeling adaptation of classical STRIDE for AI systems, and is operationalized through a purpose-built web tool. We provide an initial validation of the approach through a black-box assessment of a deployed LLM chatbot, which successfully reduced the attack success rate from 80\% to 15\% in our sandbox case study.
format Preprint
id arxiv_https___arxiv_org_abs_2605_17163
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment
Cyrille, Tsafac Nkombong Regine
Schwarz, Franziska
Cryptography and Security
Artificial Intelligence
Traditional cybersecurity methodologies target deterministic systems and fail to address the probabilistic nature of AI, leaving systems vulnerable to attack vectors such as model inversion, data poisoning, and prompt injection. Recent industry reports indicate that a majority of organizations deploying AI lack a dedicated security strategy, with adversarial attacks increasing rapidly year-over-year. We present \textit{STRIDE-AI}, a framework that bridges the gap between high-level risk standards (NIST AI RMF) and technical vulnerability taxonomies (OWASP LLM Top 10). The framework defines a six-phase assessment lifecycle, introduces a threat modeling adaptation of classical STRIDE for AI systems, and is operationalized through a purpose-built web tool. We provide an initial validation of the approach through a black-box assessment of a deployed LLM chatbot, which successfully reduced the attack success rate from 80\% to 15\% in our sandbox case study.
title STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2605.17163