ESEIW 2025
Sun 28 September - Fri 3 October 2025
Thu 2 Oct 2025 12:12 - 12:26 at Kaiulani I - Safety, Security, and Threats Chair(s): Fabio Q. B. da Silva

As Large Language Models (LLMs) reshape software development across industries, they also reshape the associated threat landscape. Traditional threat modeling methods, which assume predictable system behavior, struggle to accommodate the inherent nondeterminism of LLMs. Paradoxically, LLMs themselves offer capabilities, such as pattern recognition, natural language understanding, and semi-structured reasoning, that may support the automation of threat elicitation and mitigation. This research project, ThreMoLIA, aims to design, develop, and empirically evaluate a threat modeling tool that leverages LLMs to assist practitioners in identifying and analyzing security threats in LLM-integrated applications (LIAs). To this end, we apply a mixed-methods exploratory case study to define and validate threat modeling metrics, and a comparative case study to evaluate the ThreMoLIA tool against existing threat modeling practices. The project is conducted in close collaboration with industry and contributes to the ESEM community by advancing Security-by-Design practices and sharing reproducible artifacts such as metrics, benchmarks, and threat models.

Thu 2 Oct

Displayed time zone: Hawaii change

11:30 - 12:40
11:30
14m
Talk
Toward Real-Time Intrusion Detection for Autonomous Vehicles: A Vision for Deep Learning-Based Security Frameworks
ESEM - Emerging Results and Vision Track
Damiano Torre University of Washington, Tacoma, Amirpasha Javid Quanser Consulting Inc
11:44
14m
Talk
Toward Enhancing Privacy Preservation of a Federated Learning CNN Intrusion Detection System in IoT: Method and Empirical Study
ESEM - Journal First Track
Damiano Torre University of Washington, Tacoma, Anitha Chennamaneni Texas A&M University - Central Texas, Jaeyun Jo Texas A&M University - Central Texas, Gitika Vyas Texas A&M University - Central Texas, Brandon Sabrsula Texas A&M University - Central Texas
11:58
14m
Talk
Secure software Engineering through Sensible AutoMation (SESAM)
ESEM - Research Projects Track
Davide Fucci Blekinge Institute of Technology
12:12
14m
Talk
Threat Modeling for Large Language Model-Integrated Applications (ThreMoLIA)
ESEM - Research Projects Track
Felix Viktor Jedrzejewski Blekinge Institute of Technology, Oleksandr Adamov Blekinge Institute of Technology, Davide Fucci Blekinge Institute of Technology
12:26
14m
Talk
SIExVulTS: Sensitive Information Exposure Vulnerability Detection System using Transformer Models and Static Analysis
ESEM - Technical Track
Kyler Katz University of Hawaii at Manoa, Sara Moshtari University of Hawaii at Manoa, Ibrahim Mujhid University of Hawaii at Manoa, Mehdi Mirakhorli University of Hawaii at Manoa