software engineering

Emerging Challenges in Threat Modeling for GenAI-Augmented Systems: A View from the Trenches

arXiv:2607.28431

summary

The paper investigates how existing threat modeling methods cope with security risks introduced by generative AI components in software systems, presenting an exploratory study in an SME context.

Abstract

Threat modeling remains a central task in secure software engineering, as it enables the identification of security issues from system architectures. As Generative Artificial Intelligence (GenAI) becomes increasingly pervasive across software systems, traditional threat modeling methods (e.g., STRIDE) are insufficient to assess emerging GenAI-specific risks. In this work, we present the first results from an exploratory assessment of GenAI-aware threat modeling methods in a Small and Medium Enterprise (SME) setting. For this, we conducted a rapid literature review to select relevant techniques and systematically applied three shortlisted methods to an industrial case study involving a GenAI-augmented system. The results highlight differences in the threats identified by each technique and reveal limited support for certain GenAI-specific risk categories, particularly those related to software supply chains and human-centered security issues. We further report practitioners' perceptions of the usability and integration of these methods in SME development workflows, including their perceived effort and adoption challenges.

Accepted at the 2026 International Symposium on Empirical Software Engineering and Measurement (ESEM)

Topics & keywords

#threat modeling#generative ai#software security#risk assessment#smeGenAISTRIDEsupply chain riskhuman-centered securitycase study
Emerging Challenges in Threat Modeling for GenAI-Augmented Systems: A View from the Trenches · wovepaper