Audio-Visual Multimodal LLM Threat Modeling for Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Threat modeling for complex application architectures is challenging and time-consuming, often leading to developer avoidance or incomplete implementation, which hinders secure application development.

Innovation Solution

A multimodal large language model (LLM)-based threat modeling system that uses audio and visual prompts to simplify the threat modeling process, incorporating interleaved language and visual modalities to automate the generation of threat models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual threat modeling is performed to ensure comprehensive security analysis, then security quality is improved, but time consumption and resource usage increase significantly

Engineering Contradiction:
Improvesecurity qualityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an AI-based threat modeling system as an intermediary between developers and security analysis. This automated system processes application architecture descriptions and generates comprehensive threat models, security requirements, and mitigation strategies without requiring developer time investment, thus maintaining high security quality while eliminating time consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The threat modeling system performs self-service by automatically analyzing application architectures and generating security documentation without human intervention. The system independently identifies threats, evaluates risks, and produces security requirements, freeing developers from manual security analysis tasks while ensuring comprehensive security coverage.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual threat modeling is performed to identify and document potential security threats, then security decision-making is improved, but developer productivity decreases

Engineering Contradiction:
Improvesecurity decision-makingVSAvoiddeveloper productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical manual process of threat modeling with an automated AI system. Instead of developers manually analyzing architectures and documenting threats, the system automatically processes architecture descriptions and generates comprehensive security analyses, maintaining high-quality security decision-making while completely eliminating the productivity loss associated with manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive threat modeling is performed to analyze complex application architectures, then security coverage is improved, but process complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex threat modeling process into distinct automated stages: architecture description input, automated threat identification, risk evaluation, and security requirement generation. Each stage is handled independently by the AI system, maintaining comprehensive security coverage while simplifying the overall process through systematic breakdown of complex analysis tasks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250298902A1Multimodal large language model (LLM)-based threat modeling
Publication Date: 2025.09.25 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US20250298902A1 patent drawing
  • US20250298902A1 patent drawing
  • US20250298902A1 patent drawing

AI summary

Disclosed are various approaches for multimodal large language model (LLM) based threat modeling. The multimodal LLM based threat modeling can include a system or method that can input, into a threat modeling multimodal LLM, prompting data that includes audio data, image data, and LLM instructions to generate application security data. The threat modeling multimodal LLM can generate and provide application security data that includes at least one of: threat data, weakness data, security control data, a security risk summarization, an application threat model, or any combination thereof.