ThreMoLIA - Threat Modeling for LLM-Integrated Applications

The project aims to develop a threat modeling methodology for RAG-based LLM integrated applications (LIAs) and a tool driven by a specialized LLM that can generate and continuously maintain threat models.

The project results will provide new knowledge necessary to make best use of LLM technologies to improve threat modeling, especially of applications using RAG-based LLM components. The technical solution and accompanying methodology will enable stakeholders lacking expertise in AI, such as developers and architects, to perform threat modeling of such applications.

To achieve the project's goals, the consortium will collaborate to develop technical solutions and new knowledge. The AI and software security experts from BTH and Ericsson will adapt and refine a large language model (LLM) for threat modeling. Subsequently, BTH will develop an approach for continuous quality checks of the generated threat models. After that, the results will be evaluated at Ericsson using academic best practices. Ultimately, the tool should be ready for integration into Ericsson's operational environment and become an industrially viable product.

Financier: Vinnova

Status: Ongoing

Area: Software Engineering

Project start: 2024-01-01

Project end: 2026-12-31

Contact person: Oleksandr Adamov

Project partner: Ericsson

Project manager
Oleksandr Adamov

Senior Lecturer

Send email

View profile

Participants
Davide Fucci

Senior Lecturer/Docent

Send email

View profile

Felix Jedrzejewski

Doctoral Student

Send email

View profile