AI Threat Modeling: Adapting STRIDE for LLM Systems

STRIDE wasn't written for agents that call tools and read untrusted documents — but the categories still map, once you know where to look.

"STRIDE wasn't written for agents that call tools and read untrusted documents — but the categories still map, once you know where to look."

Microsoft's STRIDE framework (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) predates LLM agents by two decades. It still applies — this piece maps each category onto an agent/RAG pipeline's actual components.

1. The Six Categories, Mapped to an Agent Pipeline

Each STRIDE category has a concrete, non-hypothetical analog in a typical agent/RAG system. Treating these as abstract categories rather than specific failure modes is how threat models end up too generic to act on.

STRIDE threat categories mapped to an LLM agent pipeline: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege, each with a specific agent-system failure mode
threat-model 路 stride.map LLM System Threats

Modeling Principle

Map each category to a specific component — not a generic "AI risk" bucket.

2. The Highest-Priority Categories for Agent Systems

3. Applying This to a Real Pipeline

ComponentPrimary STRIDE exposure
User input / promptSpoofing (identity), Tampering (injected instructions)
Retrieval / RAG documentsTampering (indirect prompt injection via retrieved content)
Tool-call executionElevation of Privilege, Denial of Service
Model outputInformation Disclosure (leaked secrets/context)
Audit / logging layerRepudiation (no record of what the agent actually did)

4. What This Is Not

This is not a replacement for a full security review — it's the structuring step that makes a review comprehensive instead of ad hoc. A threat model without a follow-up mitigation owner per finding is a document, not a control.

Skills Demonstrated: Threat Modeling · AI Agent Security · RAG Security · STRIDE Methodology

Related service: AI Agent Security · Related: RAG Security

Nazline Mwita

Nazline Mwita

CompTIA Security+ certified Cybersecurity Assurance Lead and Co-Founder at HarLyn Digital Partners. Specializing in authorized web & API security assessments, KDPA compliance reviews, and defensive cloud architecture in Nairobi, Kenya.

馃敆 LinkedIn 鈻讹笍 YouTube (@secured.by.lynmwita) 馃摳 Instagram (@lyn_mwita) 馃悪 GitHub
WhatsApp