A method for threat modeling and detection and related electronic device

The electronic device uses LLM and RAG models to analyze software architectures, improving threat detection and mitigation accuracy and adaptability in complex systems, addressing scalability and dynamic threat landscapes.

WO2026073539A1PCT designated stage Publication Date: 2026-04-09MAERSK AS
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-10-03
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing techniques for software and network deployment lack scalability and accuracy in identifying vulnerabilities and threats, particularly in complex, interconnected systems, and are not adaptable to dynamic threat landscapes.

Method used

An electronic device utilizing a Large Language Model (LLM) and Retrieval Augmented Generation (RAG) model to analyze image and textual data from software architectures, generating threat data and providing recommendations for mitigation techniques.

Benefits of technology

Enhances threat detection accuracy, adaptability, and efficiency in identifying and visualizing vulnerabilities across software systems, reducing computational and communication resource consumption while providing context-specific threat mitigation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure DK2025050175_09042026_PF_FP_ABST
    Figure DK2025050175_09042026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is a method, performed by an electronic device, for providing recommendations associated with a software deployment scenario, the method comprising obtaining image data and / or textual data associated with a scenario for software deployment. The method comprises generating input data by analysing, using a Large Language Model, LLM, the image data and / or textual data. The method comprises determining candidate image and / or textual data by querying, based on the input data, a Retrieval Augmented Generation (RAG) model. Optionally, the RAG model is configured to store and retrieve, based on the querying, the candidate image and / or textual data for a candidate software architecture. The method comprises generating, based on the candidate image and / or textual data, a threat data indicative of one or more threats associated with the candidate software architecture. The method comprises determining, based on the threat data, one or more recommendations.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A METHOD FOR THREAT MODELING AND DETECTION AND RELATED

[0002] ELECTRONIC DEVICE

[0003] The present disclosure pertains to the field of information security and software. The present disclosure relates to a method for providing recommendations associated with a software deployment scenario and related electronic device.

[0004] BACKGROUND

[0005] Software and network deployment sometimes carry vulnerabilities that may lead to threats and security breaches, that may not be foreseen. It is difficult to predict or anticipate all possible vulnerabilities and threats in software and network deployment. Existing techniques are not scalable and lack in accuracy.

[0006] SUMMARY

[0007] Advanced threat modelling involves identifying potential vulnerabilities and threats specific to software products within a shipping and logistics company. In advanced threat modelling for shipping and logistics software, challenges include accurately identifying vulnerabilities across complex, interconnected systems.

[0008] Accordingly, there is a need for an electronic device and a method that may address identification of threats and associated recommendations, which mitigate, alleviate, or address the shortcomings existing and provide recommendations and mitigation solutions for the threats detected.

[0009] Disclosed is a method, performed by an electronic device, for providing recommendations associated with a software deployment scenario. The method comprises obtaining image data and / or textual data associated with a scenario for software deployment. The method comprises generating input data by analysing, using a Large Language Model, LLM, the image data and / or textual data. The method comprises determining candidate image and / or textual data by querying, based on the input data, a Retrieval Augmented Generation (RAG) model. Optionally, the RAG model is configured to store and retrieve, based on the querying, the candidate image and / or textual data for a candidate software architecture. The method comprises generating, based on the candidate image and / or textual data, a threat data indicative of one or more threats associated with the candidate software architecture. The method comprises determining, based on the threat data, one

[0010] P24-052PCT1 or more recommendations. Optionally, the one or more recommendations are indicative of respective mitigation techniques for corresponding one or more threats. The method comprises providing the one or more recommendations, e.g. to a user.

[0011] Disclosed is an electronic device comprising memory circuitry, processor circuitry, and an interface, wherein the electronic device is configured to perform any of the methods disclosed herein.

[0012] Disclosed is a computer readable storage medium storing one or more programs, the one or more programs comprising instructions, which when executed by an electronic device (optionally with a display and a touch-sensitive surface) cause the electronic device to perform any of the methods disclosed herein.

[0013] It is an advantage of the present disclosure that the disclosed electronic device and method provide enhanced accuracy in threat detection, for example, including identifying and visualizing vulnerabilities across software systems and architectures, such as shipping and logistics software systems.

[0014] An additional advantage of the present disclosure is the provision of dynamic adaptability of the software system to prevent detected threat(s), which may enable updates and fine- tuning, which allows the electronic device to adapt to the evolving threat of landscapes and attacks. In one or more examples, the dynamic adaptability may provide additional protection against emerging security risks, which may in turn protect against and / or mitigate risks, such as security risks.

[0015] It may also be advantageous of the present disclosure that the electronic device may provide for more effective and efficient analysis of software and / or network architecture via image generation using RAG and other techniques (such as artificial intelligence (Al) methods), which may provide enhanced analysis while not increasing consumption of computational and communication resources, due to effective generation and proliferation of visual representations of risks and solutions.

[0016] It may be appreciated that the capability to identify patterns and / or threats can be tailored or customized to the context, and application at hand. For example, threats may have been occurring in various other parts of an architecture, and if mitigated, may prevent cascaded attacks that exploit common components or misconfigurations in the

[0017] P24-052PCT1 architecture. The ability of the disclosed technique to identify context-specific threats (e.g. for a particular architecture, and / or a particular application and / or a particular domain or company) improves the overall security of a system, e.g. for an organization and / or an architecture.

[0018] Further advantageously, the scalability of the solution(s) disclosed herein allows for effective handling and processing of large and interconnected datasets of images, resulting in facilitating efficient retrieval and utilization of relevant visual data to enhance threat assessment and risk mitigation techniques.

[0019] BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The above and other features and advantages of the present disclosure will become readily apparent to those skilled in the art by the following detailed description of exemplary embodiments thereof with reference to the attached drawings, in which:

[0021] Fig. 1A is a diagram illustrating an exemplary system for providing a threat detection and mitigation recommendation from a user input, according to the disclosure.,

[0022] Fig. 1 B is a diagram illustrating an exemplary visual representation of a recommendation, according to the disclosure,

[0023] Fig. 2 is an example user interface associated with a scenario for software deployment, according to the disclosure,

[0024] Figs. 3A-3B shows a flow chart of an exemplary method, performed by an electronic device, for providing a threat recommendation, according to the disclosure,

[0025] Fig. 4 is a block diagram illustrating an exemplary electronic device according to this disclosure, and

[0026] Fig. 5 is an illustration of an exemplary user interface for receiving user input, according to this disclosure.

[0027] DETAILED DESCRIPTION

[0028] Various exemplary embodiments and details are described hereinafter, with reference to the figures when relevant. It should be noted that the figures may or may not be drawn to scale and that elements of similar structures or functions are represented by like reference numerals throughout the figures. It should also be noted that the figures are P24-052PCT1 only intended to facilitate the description of the embodiments. They are not intended as an exhaustive description of the disclosure or as a limitation on the scope of the disclosure.

[0029] In addition, an illustrated embodiment needs not have all the aspects or advantages shown. An aspect or an advantage described in conjunction with a particular embodiment is not necessarily limited to that embodiment and can be practiced in any other embodiments even if not so illustrated, or if not so explicitly described.

[0030] The figures are schematic and simplified for clarity, and they merely show details which aid understanding the disclosure, while other details have been left out. Throughout, the same reference numerals are used for identical or corresponding parts.

[0031] Advanced threat modelling, such as for a software deployment scenario, involves for example identifying potential vulnerabilities and threats specific to software products. In one or more examples, the context for a software may be within a shipping and logistics company. The advanced threat modelling aims e.g. to create detailed threat models that provide insightful information about risks and threats through visual representations. For example, the advanced thread modelling also includes a set of mitigation strategies accompanying the identified threats and / or risks.

[0032] In advanced threat modelling for shipping and logistics software, as well as for threat modelling software in other contexts, challenges may include accurately detecting and identifying vulnerabilities across complex, interconnected systems, adapting to a dynamic threat landscape with evolving attack vectors, and ensuring effective visual representations in threat models.

[0033] It may be appreciated that the complexities require updates (e.g. consistent, periodic, and / or continuous) to threat models and the integration of comprehensive mitigation techniques. For example, the mitigation techniques may be directed toward protecting against security breaches, which may result in a system being unavailable, data theft, etc.

[0034] Fig. 1A is a diagram illustrating an example system for providing a threat recommendation from a user input, according to the disclosure. Fig. 1A illustrates an example scenario where the user input is the system diagram 50. The system diagram 50 may be provided to an electronic device, such as electronic device 300, via user input.

[0035] In other words, in one or more examples, a user may upload a software architecture (such as a visual representation with information regarding a block or set of blocks and the

[0036] P24-052PCT1 logical connections between the blocks, where blocks may represent software entities and / or hardware entities). The system diagram 50 may be received from a user, e.g. via an adjacent system, or from other source and may be considered “input”. As depicted here, the user input obtained by the electronic device, (such as system diagram 50) may comprise image data and / or textual data. In one or more examples, such as in system diagram 50, the image data and textual data may be associated with a scenario for software deployment. In other words, the system diagram 50 represent a scenario for software deployment, such as for the deployment of a software and / or a software architecture.

[0037] In one or more examples, the electronic device 300 may process the input data, using a RAG model and / or an LLM, as described herein, and provide an output, such as output 60. Output 60 may comprise recommendation(s), such as image and / or textual recommendations, including one or more example software architectures with threats identified, one or more identified risks, one or more identified mitigations, and / or other relevant information associated with the software deployment scenario and / or the received input (such as system diagram 50). In other words, in one or more examples, the electronic device 300 may provide data indicative of a threat analysis for potential threats, and recommendations on how to mitigate the threats, as described herein. In one or more examples, the threats may be generic threats, industry and / or domain-specific threats, company-specific threats, or scoped in another way.

[0038] Fig. 1 B is a diagram illustrating an exemplary visual representation 60 of a recommendation, according to the disclosure. In one or more examples, a recommendation may be provided, such as via a user interface, to provide threats and / or mitigation technique(s). In one or more examples, the recommendation may comprise a combination of images and / or text. As depicted at 60, the recommendation may include a software architecture (such as a candidate software architecture, as described herein). An example software architecture may be depicted at the series of interconnected boxes, including 602, 604, 606, 608, 610, and 612. In one or more examples, the software architecture may comprise a series of textual labels; for ease of understanding, only two textual labels have been included, one for 602 indicating an “Domain Name System service” module and 610 indicating a “Data Volume” module.

[0039] In one or more examples, the electronic device 300 may identify, through use of the LLM and / or RAG model, that module 604 which was labelled “Lead Balancing” should actually

[0040] P24-052PCT1 be labelled “Load Balancing” in the architecture diagram. Thus, for example, the label in the representation 60 is corrected using the LLM model disclosed herein and the appropriate label is used when, for example, querying the RAG model, thus increasing the likelihood of correctly identifying the appropriate threat model and / or mitigation strategy.

[0041] In one or more examples, the provided representation of the recommendation may comprise a set of one or more user interface objects which depict one or more threats. For examples, at representation 60, a first, second, third, and fourth identified threat, 614, 616, 618, and 620 respectively are illustrated by a black starburst. In one or more examples, a shorthand or abbreviation briefly explaining the threat, such as “content delivery vulnerabilities”, “misconfiguration leading to data leaks”, or another identified risk. For example, alternative or additional risks can be provided by the electronic device 300, such as risks regarding unauthorized access, tampering, exposure of customer sensitive data, potential system manipulation, operational disruptions, denial of service etc.

[0042] In one or more examples, the recommendation illustrated by 60 may also include one or more recommended risk mitigation techniques. An example display of risk mitigation recommendations is illustrated at Fig. 2. However, in one or more examples, the risk mitigation recommendations may be illustrated in the same representation as 60, e.g. integrated with the software architecture diagram (such as via a selectable option, a textual display, or in another suitable way).

[0043] Fig. 2 is an example user interface associated with a scenario for software deployment, according to the disclosure. Fig. 2 shows an example user interface comprising user interface objects representative of a set of mitigation recommendations, such as a set of user interface objects depicting a set of threats and associated mitigation recommendations, according to the disclosure.

[0044] In one or more examples, the user interface (III) objects may comprise several columns and rows of information, where each column contains a particular set of information, and each row contains a particular example (such as a single row per identified threat). In one or more examples, column 22 may comprise a set of III objects representative of a threat type, as depicted at 22. In one or more examples, column 24 comprises a set of III objects representative of a particular scenario associated with each threat, as depicted at 24. In one or more examples, column 26 may comprise a set of III objects representative of a suggested mitigation (for example a mitigation technique recommendation), as

[0045] P24-052PCT1 depicted at 26. In one or more examples, column 28 may comprise a set of III objects, the text contained within which is representative of a reference, such as a title, page number and / or another indicator which could be helpful to determine a location or identification of a particular threat, as depicted at 28.

[0046] Figs. 3A-3B shows a flow-chart of an exemplary method 100, performed by an electronic device, for providing a threat recommendation, according to the disclosure.

[0047] The method 100 comprises obtaining (such as retrieving, receiving, and / or generating) S102 image data and / or textual data associated with a scenario for software deployment. In one or more examples, image data may be seen as data associated with an image and / or visual representation, such as data associated with a software architecture diagram. In one or more examples, textual data may be seen as data associated with and / or depicted as text, such as a set of text labels accompanying a software architecture diagram. In one or more examples, image data and / or textual data may be obtained, e.g. from user input. For example, a user provides (e.g. inputs, uploads, sends etc..) a diagram representing a scenario for software deployment to the electronic device disclosed herein. In one or more examples, a scenario for software deployment may be seen as an operational context for deploying a software solution, such as a software deployed, such as a software and / or hardware architecture, e.g. by and used for shipping and logistics management. In one or more example methods, the image data and / or the textual data is indicative of a software architecture to be analysed.

[0048] The method 100 comprises generating S106 input data by analysing, using a Large Language Model, LLM, the image data and / or textual data. In one or more examples, input data may be seen as a set of data, e.g. analysed, extracted, generated from e.g. one or more of a software architecture diagram, a set of responses to pre-determined questions (such as answers received via a drop-down menu), a set of textual or visual inputs provided without a prompt (such as into a free text box), or received in another way. In one or more examples, input data may be generated using an LLM applied to image data and / or textual data, received from a user input providing via one or more user interfaces, such as user interface 70 if Fig. 5, a software diagram such as diagram 60 of Fig. 1A. In one or more examples, the LLM may be selected based on its capabilities, including capabilities in natural language understanding and generation, as well as its ability to integrate with a retrieval mechanism, e.g. to enhance image generation.

[0049] P24-052PCT1 In one or more example methods, the method 100 comprises selecting S104 the LLM according to one or more intended capabilities. In one or more examples, the method 100 includes a model selection amongst a plurality of LLMs. In one or more examples, a Large Language Model (LLM) may be seen as a computational model capable of language generation and / or other natural language processing tasks, for example artificial neural networks. In one or more examples, the LLM may be self-supervised, semi-supervised, or unsupervised in the training process. In one or more examples, the one or more intended (e.g. desired, and / or targeted) capabilities, such as a summarisation capability, a capability for building up a RAG model to avoid and / or reduce hallucination (such as using an embedding technique), and / or having training data that is matched to the current specific scenario. In one or more examples, a generative Al model (including a model such as a large language model (LLM)) may be selected as a base for integration with a retrieval technique.

[0050] The method 100 comprises determining S112 candidate image and / or textual data by querying, based on the input data, a Retrieval Augmented Generation, RAG, model. In one or more examples, the RAG model is configured to store and retrieve, based on the querying, the candidate image data and / or textual data for a candidate software architecture. In one or more examples, a software architecture may be seen as a set of structures needed to reason about a software system, such as an architecture of a particular software scenario. In one or more examples, a candidate software architecture may be seen as one or more software architectures identified by the results of the RAG query, that may detect threats in the scenario for software deployment and prevent the threats.

[0051] In one or more examples, candidate image and / or textual data may be seen as a set of candidate image data and / or candidate textual data associated with the candidate software architecture. In one or more examples, the candidate image and / or candidate textual data may be seen as a set of data indicative of a particular software architecture that is generated for remedying to the threat(s), a configuration, a particular scenario, or another relevant dataset associated with the input data. In one or more examples, an LLM may be used without a RAG model, for example, the method comprises, for example, determining the candidate image data using an LLM. In one or more examples the LLM is trained using external data (such as data that is scraped, such as passively accessed from the internet), rather than using user-provided models for training and / or building the models.

[0052] P24-052PCT1 In one or more example methods, generating S114, based on the candidate image and / or textual data, the threat data comprises querying S114A the RAG model using the input data. In one or more examples, the RAG model may take, as input (such as input data), the data provided by the LLM. For example, the RAG model may involve a query, e.g. a user query where a user inputs a prompt, a question and / or a request, e.g. including a software diagram. For example, the RAG model provides a data retrieval where data is retrieved based on the user query in an indexed data structure built when the RAG model was generated. For example, this can include structured data from databases. For example, the RAG model may include a module for prompt augmentation where the retrieved information is combined with the original query to create a more informative prompt for the LLM. For example, the response generation from RAG provides the candidate image data and / or candidate textual data of a candidate software architecture. For example, the LLM of RAG generates a response based on the augmented prompt, utilizing both its pre-trained knowledge and the newly retrieved data for providing a candidate software architecture for threat analysis.

[0053] The method 100 comprises generating S114, based on the candidate image data and / or candidate textual data, a threat data indicative of one or more threats associated with the candidate software architecture. In one or more examples, the threat data may be seen as data associated with, such as indicative of or reflective of, a threat, such as a cybersecurity threat or other threat to a software indicated in the software architecture. The threat can be seen as a technical vulnerability of the software that leads to a security breach when exploited by an attacker. In one or more examples, the electronic device may access data (such as image and / or textual data), from the RAG model determined to be candidate image and / or textual data, which may indicate the data to be relevant to the candidate software architecture. In one or more examples, based on the candidate image and / or textual data, threat data for the particular candidate architecture (such as candidate architecture associated with a particular software scenario) may be generated.

[0054] The method 100 comprises determining S116, based on the threat data, one or more recommendations, wherein the one or more recommendations are indicative of respective mitigation techniques for corresponding one or more threats. In one or more examples, one or more recommendations may be seen as one or more of: a threat, a scenario, a potential input, and a mitigation technique. The recommendation can be represented by recommendation data. In one or more examples, a recommendation may include a set of P24-052PCT1 identified threats, and corresponding mitigation techniques, a single threat and a set of corresponding mitigation techniques, or another combination. In one or more examples, the format and / or the content of the recommendation may be generated based on a database of mitigation technique curated by a system, or in another way. In one or more examples, the mitigation techniques may be seen as tools, and workflows used to identify, prevent, and minimize threats to company data or networks. In one or more example, the mitigation techniques that may address and / or mitigate one or more identified threats and may protect against potential financial, reputational, or other damage from security breaches.

[0055] In one or more example methods, determining S116, based on the threat data, the one or more recommendations comprises querying S116A the RAG model using the threat data. In other words, for example, the electronic device queries the RAG model by inputting a query that specifies one or more threats provided in the threat data. This may be seen as a content-based Image Retrieval via RAG where the disclosed techniques enable the RAG model to retrieve images based on visual similarities and / or content descriptors. For example, the threat data can be generated based on extracted text and / or summarized text from a software architecture diagram, and provided to the RAG. For example, the RAG model can take as input images and text of historical diagrams for generating the RAG model, which is described later herein.

[0056] The method 100 comprises providing S118, e.g. to a user, the one or more recommendations. In one or more examples, a user may be seen as an entity interacting with and / or controlling the electronic device. As described herein, in one or more examples, a recommendation may be the output of the electronic device and may comprise one or more of: a threat, a scenario, a potential input, and a suggested mitigation.

[0057] In one or more example methods, the method 100 comprises generating S108 a RAG model. In one or more examples, generating the RAG model comprises building the RAG model. In one or more examples, a Retrieval Augmented Generation (RAG) model may be seen as a model implementing a RAG technique for enhancing accuracy and reliability of a generative Al model, often using data fetched or input from internal and / or external sources. In one or more examples, a RAG model may be generated built via training the model on a set of training data, as disclosed herein. In one or more examples, the RAG model is based on an architecture that augments the capabilities of the LLM by adding an information retrieval system that provides grounding data, such as data from an appropriate or relevant context.

[0058] P24-052PCT1 In one or more example methods, generating S108 the RAG model comprises obtaining S108A a first set of training data, wherein the training data comprises training image data and / or training textual data. In one or more examples, a first set of training data may be seen as a set off data comprised of image data and / or textual data to be used to train the RAG model. In one or more example methods, the first set of training data comprises historical training data indicative of one or more of: historical threat scenarios associated with historical scenarios for software deployments, historical mitigations, and / or historical scenarios represented in one or more historical architectures. In one or more examples, historical training data may be seen as a set of data comprising historical (such as past or previous) threat identifications, past architecture, and / or past mitigation techniques. The historical training data may be obtained in one of or a combination of ways, including from internal sources, from external sources, and / or from previous user input. In one or more examples, historical threat scenarios associated with historical scenarios for software deployments may be seen as visual and / or textual representations of threat scenarios (including, in one or more examples, software architectures), identified threats, and associated context. In one or more examples, threats may be seen as areas or instances of vulnerability and / or potential vulnerabilities for a particular software deployment scenario. In one or more examples, historical mitigations may be seen as a set of mitigations (such as techniques or approaches to apply to reduce the risk and / or address or neutralize the threat) that have been applied in the past or in historical incidents. In one or more examples, historical mitigations may be a set of mitigations provided as recommendations to historical identified threats and / or a set of mitigations sourced from external scenarios. In one or more examples, historical scenarios represented in one or more historical architectures may be seen as a set of one or more software scenarios represented by textual and / or image data, indicated a set of components, structure, and / or connections in a software scenario.

[0059] In one or more example methods, generating S108 the RAG model comprises processing S108B the training data to detect a set of threats and / or a set of mitigation techniques.

[0060] In one or more example methods, generating S108 the RAG model comprises storing and / or indexing S108C the processed training data. In one or more examples, a retrieval mechanism may be integrated. In one or more examples, the integration of the retrieval mechanism may include content-based image retrieval. In one or more examples using content-based image retrieval, a set of techniques enabling the model to retrieve images based on visual similarities or content descriptors may be implemented, for examples, using P24-052PCT1 the LLM. In one or mor examples, the integration of retrieval mechanisms may include establishing an indexing system that stores and retrieves images based on queries generated during the image generation process, as described herein. In one or more examples, the RAG model may then be generated (such as set up) using datasets that have been pre-processed. In one or more examples, generating the RAG model may comprise obtaining, processing, and storing training data, as described herein. In one or more examples, setting up the RAG model may include designing an architecture where the generative Al model (such as the LLM model) interacts seamlessly with a query mechanism (such as a retrieval mechanism) to fetch and utilize relevant images and / or text as well as to facilitate effective image generation.

[0061] In one or more example methods, processing S108B the training data comprises preprocessing S108B-1 the training data. In one or more example methods, pre-processing S108B-1 the training data comprises applying S108B-1A one or more of: a noise reduction technique, a chunking technique, a vectorization technique, and a word embedding technique. In one or more examples, pre-processing the training data (such as the data used for building the RAG) comprises data collection, cleaning (such as applying a noise reduction technique), and chunking (such as dividing the training data in chunks or segments of information that maintain semantic coherence (e.g., phrases, sentences, or paragraphs)). In one or more examples, processing and / or pre-processing of the data comprises vectorization and / or generating embeddings for the data (e.g. converting text into numerical representation for embedding of words with similar meanings).

[0062] In one or more example methods, generating S108 the RAG model comprises adapting S108D the RAG model using one or more few-shot learning techniques. In one or more examples, the techniques may enhance the capabilities of models, such as an LLM, by combining a retrieval mechanism with a generation model. Thus, the techniques require only a data sets that are fewer or smaller than for LLMs (such as, for building the RAG and for fine tuning and / or retraining the model), and thus may be considered conceptually similar to a few-shot learning technique. In one or more examples, a few-shot learning technique may be seen as a technique for improving the accuracy, reliability and / or context of the model by using only a limited (such as several) number of instances or training examples to train and / or update a model. In one or more examples, a few-shot learning technique may be used to improve a model’s ability to generalize from a limited number of examples and adapt to a new image generation task and / or style.

[0063] P24-052PCT1 In one or more example methods, adapting S108D the RAG model comprises obtaining S108D-1 a second set of training data. In some examples, the second set of training data is smaller than the first set. In one or more examples, a second set of training data may be seen as a set of training data to be used to train and / or fine tune a model.

[0064] In one or more examples, the second set of training data is considered smaller than the first set of training data in that the cardinality of the second set is lower than the cardinality of the first set. In one or more examples, a second set of training data may be used to adapt the RAG model, such as adapting it to a new context. For example, if the first set of training data built the RAG model primarily on data in a shipping context, the second set of training data may adapt the model by providing training data for a travel context, thus allowing the model to be used for a new context.

[0065] In one or more example methods, adapting S108D the RAG model comprises updating S108D-2, based on the second set of training data, the threat model and / or the RAG model. In one or more examples, the updating, based on the second set of training data can serve to improve the performance of the LLM by integrating external information retrieved from the second set of training data (such as a corpus) to provide more accurate and contextually relevant responses during inference. Updating may be seen as learning, re-training, and / or fine-tuning. In one or more examples, the RAG model may be evaluated and / or fine-tuned as described herein. In one or more examples, this evaluation may be against the expected output and the evaluation of the fine-tuned RAG model may be judged against any number of metrics including visual fidelity, relevance to the query, diversity in outputs, overall coherence, and mitigation details. The evaluation may be structured to evaluate for fairness, correctness, context precision, hallucination, human evaluation, answer relevancy, correctness, faithfulness, and precision / context recall.

[0066] In one or more example methods, the method 100 comprises fine-tuning S110 the RAG model for a cyber-security context. In one or more examples, the RAG model, such as a multi-modal and / or multi-lingual transformer may be fine-tuned. In one or more examples, the fine-tuning may occur using a prepared dataset of images and / or text. In one or more examples, the fine-tuning may include training the model to generate high-quality images that are contextually relevant to the retrieved image data, such as to the particular threat, software environment, or other. In one or more examples, the model may be fine-tuned using one or more transfer learning techniques to adjust the model’s weights and P24-052PCT1 parameters. In one or more examples, the fine-tuning may be directed toward improvements regarding image generation based on retrieved images.

[0067] In one or more examples, fine tuning may be seen as applying one or more techniques to improve and / or refine the model for the particular context, such as a cybersecurity context. In one or more examples, the fine tuning the pre-trained LLM comprises retraining the LLM with a new set of training data. In one or more examples, a small (such as a minimal) set of data may be used, thus qualifying the fine-tuning as a few shot learning technique application. In one or more examples, a technique may be used to improve the model such as a few shot prompting, wherein a model is prompted to solve a new task while providing only a few examples of how the task should be solved.

[0068] In one or more example methods, the method 100 comprises testing S120 one or more performance parameters of the RAG model based on a testing set of image data and / or textual data. In one or more examples, a testing set of image and / or textual data may be seen as a set of image and or text data generated and / or accessed for use of training and or testing the model, such a identifying the effectiveness in meeting one or more performance parameters. In one or more example methods, the testing set is indicative of a variety of types of images and texts. In one or more example methods, the one or more performance parameters comprise one or more of: a visual accuracy parameter, a visual fidelity parameter, a fairness parameter, a correctness parameter, a context accuracy parameters, a hallucination grade parameter, a faithfulness parameter, and a context recall parameter. In one or more examples, a performance parameter may be seen as one or more measures of an effectiveness of a model, such as one or more of: a visual accuracy parameter, a visual fidelity parameter, a fairness parameter, a correctness parameter, a context accuracy parameters, a hallucination grade parameter, a faithfulness parameter, and a context recall parameter. For example, the testing S120 can include prompts and queries where the RAG model for image generation is evaluated using various prompts or queries requiring different types of images. For example, the assessment of the quality of generated images is performed based on performance parameters or metrics such as visual fidelity, relevance to the query, diversity in outputs, overall coherence, and mitigation details.

[0069] In one or more example methods, providing S118, to a user, the one or more recommendations comprises displaying S118A one or more user interface objects P24-052PCT1 indicative of the one or more recommendations respectively. In one or more examples, a user interface object may be seen as one or more interactive elements like icons, widgets, buttons, and / or menus, on a digital interface that users can interact with to perform tasks.

[0070] In one or more example methods, each of the one or more user interface objects are respectively representative of the one or more threats, the one or more recommendations, and the candidate software architecture. In one or more examples, the user interface may be generated using one or more III building capabilities, such as an open-source Python library. In one or more examples, the III may be developed to be an ‘intuitive Ul’, such as a user interface that provides for user interaction to enable a user to interact with the RAG, input prompts, adjust application options (such as providing more information, security features, additional controls, and the like), visualize real-time outputs, and enhance user control and accessibility.

[0071] Fig. 4 is a block diagram illustrating an exemplary electronic device 300 according to this disclosure.

[0072] The electronic device 300 comprises memory circuitry 301, processor circuitry 302, and an interface 303. The electronic device 300 is configured to perform any of the methods disclosed in Fig. 3A-3B. In other words, the electronic device 300 is configured for providing recommendations associated with a software deployment scenario. The electronic device can be seen as a software security device, a security device, and / or a threat monitoring device.

[0073] The electronic device 300 is configured to obtain (e.g. via the interface 303 and / or the processor circuitry 302) image data and / or textual data associated with a scenario for software deployment.

[0074] The electronic device 300 is configured to generate (e.g. via the processor circuitry 302) input data by analysing, using a Large Language Model, LLM, the image data and / or textual data.

[0075] The electronic device 300 is configured to determine (e.g. via the processor circuitry 302) candidate image and / or textual data by querying, based on the input data, a Retrieval Augmented Generation, RAG, model, wherein the RAG model is configured to store and

[0076] P24-052PCT1 retrieve, based on the querying, the candidate image and / or textual data for a candidate software architecture.

[0077] The electronic device 300 is configured to generate (e.g. via the processor circuitry 302), based on the candidate image and / or textual data, a threat data indicative of one or more threats associated with the candidate software architecture.

[0078] The electronic device 300 is configured to determine (e.g. via the processor circuitry 302), based on the threat data, one or more recommendations, wherein the one or more recommendations are indicative of respective mitigation techniques for corresponding one or more threats.

[0079] The electronic device 300 is configured to provide (e.g. via the interface 303 (e.g. a display device) and / or the processor circuitry 302), to a user, the one or more recommendations.

[0080] The processor circuitry 302 is optionally configured to perform any of the operations disclosed in Fig. 3A-3B (such as any one or more of: S102, S104, S106, S108, S108A, S108B, S108B-1, S108B-1A, S108C, S108C-1, S108C-2, S108D, S110. S112, S114, S114A, S116, S116A, S118, S118A, and S120). The operations of the electronic device 300 may be embodied in the form of executable logic routines (e.g., lines of code, software programs, etc.) that are stored on a non-transitory computer readable medium (e.g., the memory circuitry 301) and are executed by the processor circuitry 302).

[0081] Furthermore, the operations of the electronic device 300 may be considered a method that the electronic device 300 is configured to carry out. Also, while the described functions and operations may be implemented in software, such functionality may as well be carried out via dedicated hardware or firmware, or some combination of hardware, firmware and / or software.

[0082] The memory circuitry 301 may be one or more of a buffer, a flash memory, a hard drive, a removable media, a volatile memory, a non-volatile memory, a random access memory (RAM), or other suitable device. In a typical arrangement, the memory circuitry 301 may include a non-volatile memory for long term data storage and a volatile memory that functions as system memory for the processor circuitry 302. The memory circuitry 301 may exchange data with the processor circuitry 302 over a data bus. Control lines and an address bus between the memory circuitry 301 and the processor circuitry 302 also may

[0083] P24-052PCT1 be present (not shown in Fig. 4). The memory circuitry 301 is considered a non-transitory computer readable medium.

[0084] The memory circuitry 301 may be configured to store threat scenarios in a part of the memory.

[0085] Fig. 5 is an illustration of an exemplary user interface for receiving user input, according to this disclosure. Fig. 5 shows an example user interface 70 of example user input regarding a software deployment scenario, such as a set of user interface objects depicts a set of user inputs including a set of user selections from dropdown menus, according to the disclosure.

[0086] Embodiments of methods and products (such as an electronic device) according to the disclosure are set out in the following items:

[0087] Item 1. A method, performed by an electronic device, the method comprising: obtaining (S102) image data and / or textual data associated with a scenario for software deployment; generating (S106) input data by analysing, using a Large Language Model, LLM, the image data and / or textual data; determining (S112) candidate image and / or textual data by querying, based on the input data, a Retrieval Augmented Generation, RAG, model, wherein the RAG model is configured to store and retrieve, based on the querying, the candidate image and / or textual data for a candidate software architecture; generating (S114), based on the candidate image and / or textual data, a threat data indicative of one or more threats associated with the candidate software architecture; determining (S116), based on the threat data, one or more recommendations, wherein the one or more recommendations are indicative of respective mitigation techniques for corresponding one or more threats; and providing (S118), to a user, the one or more recommendations.

[0088] Item 2. The method according to item 1 , wherein the image data and / or the textual data is indicative of a software architecture to be analysed.

[0089] P24-052PCT1 Item 3. The method according to any of the previous items, wherein generating, based on the candidate image and / or textual data, the threat data comprises querying (S114A) the RAG model using the input data.

[0090] Item 4. The method according to any of the previous items, wherein determining, based on the threat data, the one or more recommendations comprises querying (S116A) the RAG model using the threat data.

[0091] Item 5. The method according to any of the previous items, wherein the method comprises selecting (S104) an LLM according to one or more intended capabilities.

[0092] Item 6. The method according to any of the previous items, wherein the method comprises generating (S108) the RAG model.

[0093] Item 7. The method according to item 6, wherein generating the RAG model comprises: obtaining (S108A) a first set of training data, wherein the training data comprises training image data and / or training textual data; processing (S108B) the training data to detect a set of threats and / or a set of mitigation techniques; and storing / indexing (S108C) the processed training data.

[0094] Item 8. The method according to item 7, wherein the first set of training data comprises historical training data indicative of one or more of: historical threat scenarios associated with historical scenarios for software deployments, historical mitigations, and / or historical scenarios represented in one or more historical architectures.

[0095] Item 9. The method according to any of items 7-8, wherein processing the training data comprises pre-processing (S108B-1) the training data.

[0096] Item 10. The method according to item 9, wherein pre-processing the training data comprises applying (S108B-1A)one or more of: a noise reduction

[0097] P24-052PCT1 technique, a chunking technique, a vectorization technique, and a word embedding technique.

[0098] Item 11. The method according to any of items 6-10, wherein generating the RAG model comprises adapting (S108D) the RAG model using one or more few-shot learning techniques.

[0099] Item 12. The method according to item 11 , wherein adapting the RAG model comprises: obtaining (S108D-1) a second set of training data, wherein the second set of training data is smaller than the first set; and updating (S108D-2), based on the second set of training data, the threat model and / or the RAG model.

[0100] Item 13. The method according to any of the previous items, the method comprising fine-tuning (S110) the RAG model for a cyber-security context.

[0101] Item 14. The method according to any of the previous items, the method comprising testing (S120) one or more performance parameters of the RAG model based on a testing set of image and / or textual data, wherein the testing set is indicative of a variety of types of images and texts.

[0102] Item 15. The method according to item 14, wherein the one or more performance parameters comprise one or more of: a visual accuracy parameter, a visual fidelity parameter, a fairness parameter, a correctness parameter, a context accuracy parameters, a hallucination grade parameter, a faithfulness parameter, and a context recall parameter.

[0103] Item 16. The method according to any of the previous items, wherein providing, to a user, the one or more recommendations comprises displaying (S118A) one or more user interface objects, wherein each of the one or more user interface

[0104] P24-052PCT1 objects are respectively representative of the one or more threats, the one or more recommendations, and the candidate software architecture.

[0105] Item 17. An electronic device comprising memory circuitry, processor circuitry, and an interface, wherein the electronic device is configured to perform any of the methods according to any of items 1-16.

[0106] Item 18. A computer readable storage medium storing one or more programs, the one or more programs comprising instructions, which when executed by an electronic device cause the electronic device to perform any of the methods of items 1-16.

[0107] The use of the terms “first”, “second”, “third” and “fourth”, “primary”, “secondary”, “tertiary” etc. does not imply any particular order, but are included to identify individual elements. Moreover, the use of the terms “first”, “second”, “third” and “fourth”, “primary”, “secondary”, “tertiary” etc. does not denote any order or importance, but rather the terms “first”, “second”, “third” and “fourth”, “primary”, “secondary”, “tertiary” etc. are used to distinguish one element from another. Note that the words “first”, “second”, “third” and “fourth”, “primary”, “secondary”, “tertiary” etc. are used here and elsewhere for labelling purposes only and are not intended to denote any specific spatial or temporal ordering. Furthermore, the labelling of a first element does not imply the presence of a second element and vice versa.

[0108] It may be appreciated that the Figures comprise some circuitries or operations which are illustrated with a solid line and some circuitries or operations which are illustrated with a dashed line. The circuitries or operations which are comprised in a solid line are circuitries or operations which are comprised in the broadest example embodiment. The circuitries or operations which are comprised in a dashed line are example embodiments which may be comprised in, or a part of, or are further circuitries or operations which may be taken in addition to the circuitries or operations of the solid line example embodiments. It should be appreciated that these operations need not be performed in order presented.

[0109] P24-052PCT1 Furthermore, it should be appreciated that not all of the operations need to be performed.

[0110] The exemplary operations may be performed in any order and in any combination.

[0111] It is to be noted that the word "comprising" does not necessarily exclude the presence of other elements or steps than those listed.

[0112] It is to be noted that the words "a" or "an" preceding an element do not exclude the presence of a plurality of such elements.

[0113] It is to be noted that the term "indicative of" may be seen as “associated with”, “related to”, “descriptive of’, “characterizing”, and / or “defining”. The terms “indicative of”, “associated with”, “related to”, “descriptive of’, “characterizing”, and “defining” can be used interchangeably. The term “indicative of” can be seen as indicating a relation. For example, weight data indicative of weight may comprise one or more weight parameters.

[0114] It is to be noted that the word "based on" may be seen as “as a function of’ and / or “derived from”. The terms “based on” and “as a function of” can be used interchangeably. For example, a parameter determined “based on” a data set can be seen as a parameter determined “as a function of’ the data set. In other words, the parameter may be an output of one or more functions with the data set as an input.

[0115] A function may be characterizing a relation between an input and an output, such as mathematical relation, a database relation, a hardware relation, logical relation, and / or other suitable relations.

[0116] It should further be noted that any reference signs do not limit the scope of the claims, that the exemplary embodiments may be implemented at least in part by means of both hardware and software, and that several "means", "units" or "devices" may be represented by the same item of hardware.

[0117] The various exemplary methods, devices, nodes, and systems described herein are described in the general context of method steps or processes, which may be implemented in one aspect by a computer program product, embodied in a computer- readable medium, including computer-executable instructions, such as program code, executed by computers in networked environments. A computer-readable medium may include removable and non-removable storage devices including, but not limited to, Read Only Memory (ROM), Random Access Memory (RAM), compact discs (CDs), digital

[0118] P24-052PCT1 versatile discs (DVD), etc. Generally, program circuitries may include routines, programs, objects, components, data structures, etc. that perform specified tasks or implement specific abstract data types. Computer-executable instructions, associated data structures, and program circuitries represent examples of program code for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represents examples of corresponding acts for implementing the functions described in such steps or processes.

[0119] Although features have been shown and described, it will be understood that they are not intended to limit the claimed disclosure, and it will be made obvious to those skilled in the art that various changes and modifications may be made without departing from the scope of the claimed disclosure. The specification and drawings are, accordingly, to be regarded in an illustrative rather than restrictive sense. The claimed disclosure is intended to cover all alternatives, modifications, and equivalents.

[0120] P24-052PCT1

Claims

CLAIMS1. A method, performed by an electronic device, the method comprising: obtaining (S102) image data and / or textual data associated with a scenario for software deployment; generating (S106) input data by analysing, using a Large Language Model, LLM, the image data and / or textual data; determining (S112) candidate image and / or textual data by querying, based on the input data, a Retrieval Augmented Generation, RAG, model, wherein the RAG model is configured to store and retrieve, based on the querying, the candidate image data and / or candidate textual data for a candidate software architecture; generating (S114), based on the candidate image and / or textual data, a threat data indicative of one or more threats associated with the candidate software architecture; determining (S116), based on the threat data, one or more recommendations, wherein the one or more recommendations are indicative of respective mitigation techniques for corresponding one or more threats; and providing (S118), to a user, the one or more recommendations.

2. The method according to claim 1, wherein the image data and / or the textual data is indicative of a software architecture to be analysed.

3. The method according to any of the previous claims, wherein generating, based on the candidate image and / or textual data, the threat data comprises querying (S114A) the RAG model using the input data.

4. The method according to any of the previous claims, wherein determining, based on the threat data, the one or more recommendations comprises querying (S116A) the RAG model using the threat data.

5. The method according to any of the previous claims, wherein the method comprises selecting (S104) an LLM according to one or more intended capabilities.

6. The method according to any of the previous claims, wherein the method comprises generating (S108) the RAG model.P24-052PCT17. The method according to claim 6, wherein generating the RAG model comprises: obtaining (S108A) a first set of training data, wherein the training data comprises training image data and / or training textual data; processing (S108B) the training data to detect a set of threats and / or a set of mitigation techniques; and storing / indexing (S108C) the processed training data.

8. The method according to claim 7, wherein the first set of training data comprises historical training data indicative of one or more of: historical threat scenarios associated with historical scenarios for software deployments, historical mitigations, and / or historical scenarios represented in one or more historical architectures.

9. The method according to any of claims 7-8, wherein processing the training data comprises pre-processing (S108B-1) the training data.

10. The method according to claim 9, wherein pre-processing the training data comprises applying (S108B-1A)one or more of: a noise reduction technique, a chunking technique, a vectorization technique, and a word embedding technique.

11. The method according to any of claims 6-10, wherein generating (S108) the RAG model comprises adapting (S108D) the RAG model using one or more few-shot learning techniques.

12. The method according to claim 11, wherein adapting (S108D) the RAG model comprises: obtaining (S108D-1) a second set of training data, wherein the second set of training data is smaller than the first set; and updating (S108D-2), based on the second set of training data, the threat model and / or the RAG model.

13. The method according to any of the previous claims, the method comprising fine-tuning (S110) the RAG model for a cyber-security context.P24-052PCT114. The method according to any of the previous claims, the method comprising testing (S120) one or more performance parameters of the RAG model based on a testing set of image and / or textual data, wherein the testing set is indicative of a variety of types of images and texts.

15. The method according to claim 14, wherein the one or more performance parameters comprise one or more of: a visual accuracy parameter, a visual fidelity parameter, a fairness parameter, a correctness parameter, a context accuracy parameters, a hallucination grade parameter, a faithfulness parameter, and a context recall parameter.

16. The method according to any of the previous claims, wherein providing, to a user, the one or more recommendations comprises displaying (S118A) one or more user interface objects, wherein each of the one or more user interface objects are respectively representative of the one or more threats, the one or more recommendations, and the candidate software architecture.

17. An electronic device comprising memory circuitry, processor circuitry, and an interface, wherein the electronic device is configured to perform any of the methods according to any of claims 1-16.

18. A computer readable storage medium storing one or more programs, the one or more programs comprising instructions, which when executed by an electronic device cause the electronic device to perform any of the methods of claims 1-16.P24-052PCT1