Bachelor and Master Theses

To apply for conducting this thesis, please contact the thesis supervisor(s).
Title: Repeatability of AI Assisted Threat Modeling
Subject: Software engineering, Computer science
Level: Basic
Description:

Background

Generative AI may produce different threat statements when the same system description is analysed more than once. A single generated threat model cannot show which findings are stable across runs. This thesis studies repeatability under documented and as-consistent-as-possible experimental conditions.

Research questions

RQ1: How much do generated threat statements vary across repeated analyses of the same system description?

RQ2: Which types of threats or STRIDE categories appear more or less stable?

Methodology

1. Review relevant work on AI output variation and threat modeling.

2. Select a manageable set of system descriptions and document the AI-assisted method and relevant settings.

3. Run repeated analyses of the same descriptions, preserve the outputs, and develop a justified way to identify equivalent or different threat statements.

4. Summarise variation across runs and discuss what it means for using a single AI-generated threat model. The number of cases and runs and the comparison measures will be decided during the thesis.

Expected outcomes

-An organised record of the inputs, experimental settings, and outputs from repeated runs, where sharing is permitted.

-A comparison of threat statements across runs, including stable findings, variable findings, and the chosen measures of variation.

-A thesis report describing the method, results, limitations, and practical implications for AI-assisted threat modeling.

Start date:
End date:
Prerequisites:

Basic programming or data-analysis skills; interest in cybersecurity and STRIDE is helpful.

IDT supervisors: Sara Abbaspour
Examiner:
Comments:
Company contact: