SecBPMN-GPT: A Hybrid LLM & Rule-Based Framework for Automating Security Annotation in Business Process Models

Fuente: Zenodo
Saved in:
Bibliographic Details
Main Authors: Islam, Md. Kamrul, Henry, Tiphaine, Souihi, Sami
Format: Recurso digital
Published: Zenodo 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866901998786314240
author Islam, Md. Kamrul
Henry, Tiphaine
Souihi, Sami
author_facet Islam, Md. Kamrul
Henry, Tiphaine
Souihi, Sami
contents <div>Secure-by-design business process modeling requires the explicit integration of security requirements into process models, yet this remains largely manual. The Security Business Process Model and Notation (SecBPMN) standard provides a formal means of expressing such constraints but lacks scalable automation methods. This thesis presents an end-to-end hybrid framework that combines rule-based and large language models (LLMs) to automate the extraction and generation of SecBPMN annotations from natural-language process descriptions. The proposed pipeline integrates process normalization, LLM-driven constraint extraction, LLM-based schema mapping, and reconstruction into valid SecBPMN XML models, effectively bridging the gap between unstructured text and formal security representations. The framework was evaluated on 27 text–SecBPMN pairs using three annotation strategies such as Prompt Engineering, Retrieval-Augmented Generation (RAG), and STS-ML guidance extraction across GPT-4.1-mini and Mistral-small models. Post-mapping schema enforcement improved both accuracy and structural validity, increasing average F1-scores by 8–12% and reducing spurious annotations by nearly 50%. GPT-4.1-mini achieved the highest accuracy (F1 = 0.715 for simple processes), while Mistral-small demonstrated superior efficiency and lower latency. Correlation analysis between objective metrics and LLM-as-Judge evaluations revealed strong alignment, indicating that language models can act as consistent evaluators of annotation quality. Compared with human experts, the SecBPMN-GPT framework achieved higher annotation accuracy (F1 = 0.516) while reducing annotation time by 95%. Overall, the results demonstrate that the proposed hybrid LLM– and rule-based framework advances the automation of security annotation in business process models, offering a scalable foundation for secure-by-design process engineering and opening pathways toward intelligent, regulation-aware workflow generation in future systems.</div>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_17493855
institution Zenodo
language
publishDate 2025
publisher Zenodo
record_format zenodo
spellingShingle SecBPMN-GPT: A Hybrid LLM & Rule-Based Framework for Automating Security Annotation in Business Process Models
Islam, Md. Kamrul
Henry, Tiphaine
Souihi, Sami
Security Business Porcess Modeling
SecBPMN
Large Language Models
Information Extraction
Schema Mapping
Secure-by-Design
<div>Secure-by-design business process modeling requires the explicit integration of security requirements into process models, yet this remains largely manual. The Security Business Process Model and Notation (SecBPMN) standard provides a formal means of expressing such constraints but lacks scalable automation methods. This thesis presents an end-to-end hybrid framework that combines rule-based and large language models (LLMs) to automate the extraction and generation of SecBPMN annotations from natural-language process descriptions. The proposed pipeline integrates process normalization, LLM-driven constraint extraction, LLM-based schema mapping, and reconstruction into valid SecBPMN XML models, effectively bridging the gap between unstructured text and formal security representations. The framework was evaluated on 27 text–SecBPMN pairs using three annotation strategies such as Prompt Engineering, Retrieval-Augmented Generation (RAG), and STS-ML guidance extraction across GPT-4.1-mini and Mistral-small models. Post-mapping schema enforcement improved both accuracy and structural validity, increasing average F1-scores by 8–12% and reducing spurious annotations by nearly 50%. GPT-4.1-mini achieved the highest accuracy (F1 = 0.715 for simple processes), while Mistral-small demonstrated superior efficiency and lower latency. Correlation analysis between objective metrics and LLM-as-Judge evaluations revealed strong alignment, indicating that language models can act as consistent evaluators of annotation quality. Compared with human experts, the SecBPMN-GPT framework achieved higher annotation accuracy (F1 = 0.516) while reducing annotation time by 95%. Overall, the results demonstrate that the proposed hybrid LLM– and rule-based framework advances the automation of security annotation in business process models, offering a scalable foundation for secure-by-design process engineering and opening pathways toward intelligent, regulation-aware workflow generation in future systems.</div>
title SecBPMN-GPT: A Hybrid LLM & Rule-Based Framework for Automating Security Annotation in Business Process Models
topic Security Business Porcess Modeling
SecBPMN
Large Language Models
Information Extraction
Schema Mapping
Secure-by-Design
url https://doi.org/10.5281/zenodo.17493855