Search papers, labs, and topics across Lattice.
This paper explores the inadequacies of traditional threat modeling methods, like STRIDE, in addressing the unique security challenges posed by Generative AI (GenAI) in software systems. Through a systematic application of three GenAI-aware threat modeling techniques in a Small and Medium Enterprise (SME) context, the study reveals significant gaps in identifying GenAI-specific risks, particularly concerning software supply chains and human-centered security. Practitioners reported challenges in usability and integration of these methods into existing development workflows, underscoring the need for tailored approaches to enhance security in GenAI-augmented systems.
Traditional threat modeling methods fall short in identifying critical GenAI-specific risks, exposing vulnerabilities in software supply chains and human-centered security.
Threat modeling remains a central task in secure software engineering, as it enables the identification of security issues from system architectures. As Generative Artificial Intelligence (GenAI) becomes increasingly pervasive across software systems, traditional threat modeling methods (e.g., STRIDE) are insufficient to assess emerging GenAI-specific risks. In this work, we present the first results from an exploratory assessment of GenAI-aware threat modeling methods in a Small and Medium Enterprise (SME) setting. For this, we conducted a rapid literature review to select relevant techniques and systematically applied three shortlisted methods to an industrial case study involving a GenAI-augmented system. The results highlight differences in the threats identified by each technique and reveal limited support for certain GenAI-specific risk categories, particularly those related to software supply chains and human-centered security issues. We further report practitioners'perceptions of the usability and integration of these methods in SME development workflows, including their perceived effort and adoption challenges.