Uploaded April 2026 | Updated September 2026, 2 weeks ago
Large Language Models promise faster, automated threat modeling. But in practice, they introduce a fundamental and intractable failure mode, which we call “The Central Paradox”. When asked to generate all possible threats, LLMs produce excessive noise that overwhelms developers and AppSec teams. Yet, when asked to identify only the “important” threats, the same models demonstrate properties that are non-deterministic, opaque, and untrustworthy. You cannot rely on their selections with 100% confidence, and you cannot reproduce their choices. Used indiscriminately in threat modeling, LLMs generate more work, reduce reliability, undermine credibility with stakeholders, and create an absence of regulatory readiness.
This talk dissects the Central Paradox and explains why threat modeling, unlike content generation, requires determinism, reproducibility, and auditability. We outline the seven failure modes common to LLM-only approaches: hallucinations, explainability theater, validation gaps, automation bias, token inefficiency, data sovereignty concerns, and non-reproducible outputs.
We then present an alternative: more deterministic AI architectures that use expert systems, embedding-based retrieval, and graph analysis to produce consistent, explainable threat models. Finally, we show where LLMs do belong: in building context, summarization, rule suggestion, verification of control implementations, and human-facing interfaces assisting in security decisions.
Attendees will leave with a clear framework for building hybrid systems that eliminate noise, preserve signal, and restore trust in AI-assisted threat modeling.
Vikramaditya Narayan
Creator of The Precogly Open Source Threat Modeling Platform
Vikramaditya Narayan is the creator of Precogly, an open-source, enterprise-grade threat modeling platform built for compliance-aware security teams. Previously, he designed the prototype for a YC-funded AI governance platform. Vikramaditya leads the Bangalore chapter of Threat Modeling Connect and has spoken at ThreatModCon DC on emergent risks in multi-agentic systems. He holds an MS from Carnegie Mellon and is a Certified Threat Modeling Professional.
-
Managed by the OWASP® Foundation
owasp.org
Large Language Models promise faster, automated threat modeling. But in practice, they introduce a fundamental and intractable failure mode, which we call “The Central Paradox”. When asked to generate all possible threats, LLMs produce excessive noise that overwhelms developers and AppSec teams. Yet, when asked to identify only the “important” threats, the same models demonstrate properties that are non-deterministic, opaque, and untrustworthy. You cannot rely on their selections with 100% confidence, and you cannot reproduce their choices. Used indiscriminately in threat modeling, LLMs generate more work, reduce reliability, undermine credibility with stakeholders, and create an absence of regulatory readiness.
This talk dissects the Central Paradox and explains why threat modeling, unlike content generation, requires determinism, reproducibility, and auditability. We outline the seven failure modes common to LLM-only approaches: hallucinations, explainability theater, validation gaps, automation bias, token inefficiency, data sovereignty concerns, and non-reproducible outputs.
We then present an alternative: more deterministic AI architectures that use expert systems, embedding-based retrieval, and graph analysis to produce consistent, explainable threat models. Finally, we show where LLMs do belong: in building context, summarization, rule suggestion, verification of control implementations, and human-facing interfaces assisting in security decisions.
Attendees will leave with a clear framework for building hybrid systems that eliminate noise, preserve signal, and restore trust in AI-assisted threat modeling.
Vikramaditya Narayan
Creator of The Precogly Open Source Threat Modeling Platform
Vikramaditya Narayan is the creator of Precogly, an open-source, enterprise-grade threat modeling platform built for compliance-aware security teams. Previously, he designed the prototype for a YC-funded AI governance platform. Vikramaditya leads the Bangalore chapter of Threat Modeling Connect and has spoken at ThreatModCon DC on emergent risks in multi-agentic systems. He holds an MS from Carnegie Mellon and is a Certified Threat Modeling Professional.
-
Managed by the OWASP® Foundation
owasp.org










