Emerging Challenges in Threat Modeling for GenAI-Augmented Systems: A View from the Trenches

📅 2026-07-30
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Traditional threat modeling approaches, such as STRIDE, struggle to effectively identify security risks unique to generative artificial intelligence (GenAI) systems, exhibiting significant blind spots—particularly concerning software supply chain vulnerabilities and human-factor security. This study conducts a rapid literature review to identify three state-of-the-art GenAI-aware threat modeling methodologies and presents the first empirical evaluation of these techniques within real-world development environments of small and medium-sized enterprises. The findings reveal that current methods exhibit notable limitations in comprehensively covering GenAI-specific threats and demonstrate substantial divergence in the threats they identify. Furthermore, the study uncovers practical barriers to integrating these approaches into existing workflows and highlights critical usability challenges, offering actionable insights and directions for improvement to practitioners and tool developers.
📝 Abstract
Threat modeling remains a central task in secure software engineering, as it enables the identification of security issues from system architectures. As Generative Artificial Intelligence (GenAI) becomes increasingly pervasive across software systems, traditional threat modeling methods (e.g., STRIDE) are insufficient to assess emerging GenAI-specific risks. In this work, we present the first results from an exploratory assessment of GenAI-aware threat modeling methods in a Small and Medium Enterprise (SME) setting. For this, we conducted a rapid literature review to select relevant techniques and systematically applied three shortlisted methods to an industrial case study involving a GenAI-augmented system. The results highlight differences in the threats identified by each technique and reveal limited support for certain GenAI-specific risk categories, particularly those related to software supply chains and human-centered security issues. We further report practitioners' perceptions of the usability and integration of these methods in SME development workflows, including their perceived effort and adoption challenges.
Problem

Research questions and friction points this paper is trying to address.

Threat modeling
Generative AI
Security risks
Software supply chain
Human-centered security
Innovation

Methods, ideas, or system contributions that make the work stand out.

GenAI-aware threat modeling
STRIDE
software supply chain security
human-centered security
SME security practices
🔎 Similar Papers
No similar papers found.
Nicolás E. Díaz Ferreyra
Nicolás E. Díaz Ferreyra
Hamburg University of Technology, Institute of Software Security
Privacy EngineeringUsable SecurityHuman-Computer InteractionEmpirical Software Engineering
M
Manish Mahesh Kumar
Institute of Software Security, Hamburg University of Technology, Germany
N
Nohemí Villarreal
CREATUM GmbH, Germany
P
Pankaj Pantel
CREATUM GmbH, Germany
I
Immo Brueggemann
CREATUM GmbH, Germany
Riccardo Scandariato
Riccardo Scandariato
Head of the Institute of Software Security, Hamburg University of Technology (TUHH)
SecurityPrivacySoftware Engineering