Cyber Threat Modeling of an LLM-Based Healthcare System

Neha Nagaraja, Hayretdin Bahsi

Research output: Contribution to journalConference articlepeer-review

1 Scopus citations

Abstract

With the rapid advancement of large language models (LLMs) and their integration into the healthcare system, it is critical to understand their resiliency against cyber-attacks since sensitive data handling is paramount. Threat modeling is most important, as addressing cyber security early in system development is essential for safe and reliable deployment. While traditional threat modeling practices are well-established, applying these frameworks to systems integrating LLM, especially in healthcare, presents unique challenges. It is essential to examine conventional cyber threats, adversarial threats, and threats specific to LLM in tandem to build robust defense mechanisms. This paper adapts the STRIDE methodology to assess threats in LLM-powered healthcare systems holistically, identifying components and their data flows and mapping potential threats introduced by each component. It provides practical guidance for understanding the threats early in development and demonstrates effective system modeling tailored to healthcare settings.

Original languageEnglish (US)
Pages (from-to)325-336
Number of pages12
JournalInternational Conference on Information Systems Security and Privacy
Volume1
DOIs
StatePublished - 2025
Externally publishedYes
Event11th International Conference on Information Systems Security and Privacy, ICISSP 2025 - Porto, Portugal
Duration: Feb 20 2025Feb 22 2025

Keywords

  • Adversarial Attacks
  • Conversational Attacks
  • Cyber Threats
  • Healthcare
  • Large Language Models
  • Threat Modeling

ASJC Scopus subject areas

  • Computer Science (miscellaneous)
  • Information Systems

Fingerprint

Dive into the research topics of 'Cyber Threat Modeling of an LLM-Based Healthcare System'. Together they form a unique fingerprint.

Cite this