| Title: | Repeatability of AI Assisted Threat Modeling |
| Subject: | Software engineering, Computer science |
| Level: | Basic |
| Description: |
Background Generative AI may produce different threat statements when the same system description is analysed more than once. A single generated threat model cannot show which findings are stable across runs. This thesis studies repeatability under documented and as-consistent-as-possible experimental conditions. Research questions RQ1: How much do generated threat statements vary across repeated analyses of the same system description? RQ2: Which types of threats or STRIDE categories appear more or less stable? Methodology 1. Review relevant work on AI output variation and threat modeling. 2. Select a manageable set of system descriptions and document the AI-assisted method and relevant settings. 3. Run repeated analyses of the same descriptions, preserve the outputs, and develop a justified way to identify equivalent or different threat statements. 4. Summarise variation across runs and discuss what it means for using a single AI-generated threat model. The number of cases and runs and the comparison measures will be decided during the thesis. Expected outcomes -An organised record of the inputs, experimental settings, and outputs from repeated runs, where sharing is permitted. -A comparison of threat statements across runs, including stable findings, variable findings, and the chosen measures of variation. -A thesis report describing the method, results, limitations, and practical implications for AI-assisted threat modeling. |
| Start date: | |
| End date: | |
| Prerequisites: |
Basic programming or data-analysis skills; interest in cybersecurity and STRIDE is helpful. |
| IDT supervisors: | Sara Abbaspour |
| Examiner: | |
| Comments: | |
| Company contact: |