arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

GenAI增强系统威胁建模的新挑战:一线视角

Emerging Challenges in Threat Modeling for GenAI-Augmented Systems: A View from the Trenches

Nicolás E. Díaz Ferreyra, Manish Mahesh Kumar, Nohemí Villarreal, Pankaj Pantel, Immo Brueggemann, Riccardo Scandariato

arXiv 2607.28431首次发表:更新:

AI 中文总结

针对GenAI增强系统,本研究通过在SME环境下应用3种GenAI感知威胁建模方法开展工业案例研究,发现传统方法不足,且现有方法对部分GenAI特定风险支持有限,还报告了从业者对这些方法的看法。

AI 中文摘要

威胁建模仍是安全软件工程的核心任务,可从系统架构识别安全问题。随着生成式人工智能(GenAI)在软件系统中日益普及,传统威胁建模方法(如STRIDE)已不足以评估新兴的GenAI特定风险。本研究报告了中小企业(SME)环境下GenAI感知威胁建模方法探索性评估的首批结果:为此,我们开展快速文献综述以筛选相关技术,并将3种入围方法系统应用于涉及GenAI增强系统的工业案例研究。结果显示,各方法识别的威胁存在差异,且对部分GenAI特定风险类别(尤其是软件供应链和以人为中心的安全问题)的支持有限。我们还报告了从业者对这些方法在SME开发工作流中的可用性与集成度的看法,包括其感知的工作量和采用挑战。

英文摘要

Threat modeling remains a central task in secure software engineering, as it enables the identification of security issues from system architectures. As Generative Artificial Intelligence (GenAI) becomes increasingly pervasive across software systems, traditional threat modeling methods (e.g., STRIDE) are insufficient to assess emerging GenAI-specific risks. In this work, we present the first results from an exploratory assessment of GenAI-aware threat modeling methods in a Small and Medium Enterprise (SME) setting. For this, we conducted a rapid literature review to select relevant techniques and systematically applied three shortlisted methods to an industrial case study involving a GenAI-augmented system. The results highlight differences in the threats identified by each technique and reveal limited support for certain GenAI-specific risk categories, particularly those related to software supply chains and human-centered security issues. We further report practitioners' perceptions of the usability and integration of these methods in SME development workflows, including their perceived effort and adoption challenges.

CommentsAccepted at the 2026 International Symposium on Empirical Software Engineering and Measurement (ESEM)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑