Threat Modeling with LLMs: Two Years In – Hype, Hope, and a Look at Gemini 2.5 Pro
After two years of exploring AI for threat modeling, the author evaluates Gemini 2.5 Pro using a deliberately vague architecture for a fictional project called “AI Nutrition Pro.” Employing the open-source AI Security Analyzer tool with a STRIDE-based prompt, the model generates a comprehensive threat model. Gemini 2.5 Pro demonstrates strong reasoning capabilities, accurately identifying assets, data flows, and specific threats like prompt injection and API key misuse. However, it shows limitations in defining trust boundaries. The author notes the potential bias due to publicly available prior models and plans to use unpublished datasets in future evaluations. Overall, the post highlights the advancements and remaining challenges in integrating LLMs into the threat modeling process
Comments
Post a Comment