May 2026Unreviewed
STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment
Tsafac Nkombong Regine Cyrille, Franziska Schwarz
Abstract
Traditional cybersecurity methodologies target deterministic systems and fail to address the probabilistic nature of AI, leaving systems vulnerable to attack vectors such as model inversion, data poisoning, and prompt injection. Recent industry reports indicate that a majority of organizations deploying AI lack a dedicated security strategy, with adversarial attacks increasing rapidly year-over-year. We present \textit{STRIDE-AI}, a framework that bridges the gap between high-level risk standard
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0043Craft Adversarial Data
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{cyrille2026strideai,
title = {{STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment}},
author = {Tsafac Nkombong Regine Cyrille and Franziska Schwarz},
year = {2026},
month = may,
eprint = {2605.17163},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.17163}
}