@adamshostack@infosec.exchange
2026-09-24 21:50 UTC
A question I hear all the time is “do we need a diagram if we’re asking an LLM to threat model for us?” The obvious answer is “no.” The LLM will “threat model” (whatever that means) without a diagram, or create one if its token stream stumbles on the idea it needs one. A better question is “how do we get the LLM to do a good job threat modeling?” The answer depends on how you engage with its output. Is a diagram a useful checkpoint? Does it help keep the LLM on task? Does it help the humans review the plan or output? (I know, those things aren’t as fashionable as turning dollars into tokens and burning them.)
(6/9)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-24 21:50
LLMs can drive down the costs of diagramming or modeling. Above, I wrote about the work to build models, and that really is changing. The change is unevenly distributed, and its impact is hard to see right now, but overarchingly, I think we’re going to move from diagrams to models as the cost of those models drops, enabling deeper, model-centered system analysis. But we won’t stop there. There’s already work in model-driven system construction, and it’s not limited to security. It offers a route to generally better code, because it offers us ways to specify and build systems with a larger number of more predictable properties. (7/9)