First Field Assessment of GenAI-Aware Threat Modeling Finds STRIDE Insufficient and Supply-Chain Risk Poorly Covered
Researchers ran a rapid literature review to shortlist three GenAI-aware threat modeling methods, then systematically applied all three to an industrial case study of a GenAI-augmented system inside a small-to-medium enterprise — the first exploratory assessment of its kind. The three techniques surfaced materially different threat sets, and all showed limited support for certain GenAI-specific risk categories, particularly software supply chain and human-centered security issues. The paper also reports practitioner perceptions of usability, integration into SME workflows, perceived effort, and adoption barriers, which is the part most teams evaluating a threat-modeling process upgrade will care about.
Source
↳ Follow the thread