LLM-based Vulnerability Discovery in Business Process Documentation

📅 2026-08-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the prevalence of logical flaws in business process documentation—often stemming from conflicting requirements, ambiguous phrasing, and insufficient quality assurance—which frequently lead to product defects, project delays, and cost overruns. It presents the first systematic exploration of end-to-end applications of large language models (LLMs) in this domain: automatically extracting business logic from unstructured sources such as ISO standards and user manuals, constructing attributed logic graphs, and integrating graph-based analysis with formal verification techniques to detect latent vulnerabilities. Empirical evaluation demonstrates the effectiveness of multiple LLMs across critical tasks including grammatical error correction, identification of technical inaccuracies, and reconstruction of process structures, substantially advancing the automation of flaw detection in business process specifications.
📝 Abstract
Just like software and hardware, business processes are susceptible to vulnerabilities that can lead to product quality issues, delays, and increased costs. Business process vulnerabilities can arise from a variety of sources, including conflicting requirements, ambiguous documentation, invalid measurement spec-ifications, omission of quality checks, or implementations that differ from speci-fications. MIRABELLE is a system that identifies and characterizes business logic (BL) vulnerabilities from available business process representations, in-cluding ISO 9000/9001 documentation, user guides, work instructions, and pro-cess execution logs. MIRABELLE leverages recent advances in AI/ML to pro-cess available business process documentation and generate attributed graph rep-resentations of the business logic that can be processed using both graph and for-mal logic approaches for identifying potential vulnerabilities. However, extract-ing the business logic (e.g., operation execution sequences, decisions, input/out-put resources) from mostly natural language artifacts is challenging due to the required domain expertise, inherent process complexity, and the sometimes very large volumes of information. This paper focuses on our experimentation with Large Language Models (LLMs) and their role within MIRABELLE. We report on the performance of several LLMs across vital stages of vulnerability detection, from grammatical and technical error-flagging in short phrasings, to complete process structure recovery and extraction.
Problem

Research questions and friction points this paper is trying to address.

business process vulnerabilities
natural language documentation
business logic extraction
vulnerability discovery
LLM-based analysis
Innovation

Methods, ideas, or system contributions that make the work stand out.

Large Language Models
Business Logic Vulnerability
Attributed Graph Representation
Process Documentation Analysis
Formal Logic Verification
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Ben Falchuk
Ben Falchuk
Peraton Labs
Human Computer InteractionMultimediaGraphicsDesignMobile Computing
H
Himanshu Garg
Peraton Labs, Basking Ridge, USA
E
Euthimios Panagos
Peraton Labs, Basking Ridge, USA
S
Sioan Zohar
Peraton Labs, Basking Ridge, USA