Noise vs. Signal: The Central Paradox of LLMs in Threat Modeling track 2 @OWASPGLOBAL
Noise vs. Signal: The Central Paradox of LLMs in Threat Modeling track 2  @OWASPGLOBAL
Uploaded April 2026 | Updated September 2026, 2 weeks ago
Large Language Models promise faster, automated threat modeling. But in practice, they introduce a fundamental and intractable failure mode, which we call “The Central Paradox”. When asked to generate all possible threats, LLMs produce excessive noise that overwhelms developers and AppSec teams. Yet, when asked to identify only the “important” threats, the same models demonstrate properties that are non-deterministic, opaque, and untrustworthy. You cannot rely on their selections with 100% confidence, and you cannot reproduce their choices. Used indiscriminately in threat modeling, LLMs generate more work, reduce reliability, undermine credibility with stakeholders, and create an absence of regulatory readiness.

This talk dissects the Central Paradox and explains why threat modeling, unlike content generation, requires determinism, reproducibility, and auditability. We outline the seven failure modes common to LLM-only approaches: hallucinations, explainability theater, validation gaps, automation bias, token inefficiency, data sovereignty concerns, and non-reproducible outputs.

We then present an alternative: more deterministic AI architectures that use expert systems, embedding-based retrieval, and graph analysis to produce consistent, explainable threat models. Finally, we show where LLMs do belong: in building context, summarization, rule suggestion, verification of control implementations, and human-facing interfaces assisting in security decisions.

Attendees will leave with a clear framework for building hybrid systems that eliminate noise, preserve signal, and restore trust in AI-assisted threat modeling.

Vikramaditya Narayan
Creator of The Precogly Open Source Threat Modeling Platform

Vikramaditya Narayan is the creator of Precogly, an open-source, enterprise-grade threat modeling platform built for compliance-aware security teams. Previously, he designed the prototype for a YC-funded AI governance platform. Vikramaditya leads the Bangalore chapter of Threat Modeling Connect and has spoken at ThreatModCon DC on emergent risks in multi-agentic systems. He holds an MS from Carnegie Mellon and is a Certified Threat Modeling Professional.
-


Managed by the OWASP® Foundation
owasp.org
Noise vs. Signal: The Central Paradox of LLMs in Threat Modeling track 2BREAKStriding Your Way to LINDDUN: Threat Modeling for Privacy - Shanni Prutchi, Chris BushOWASP DefectDojo - Matt TesauroOWASP DefectDojoOWASP Global Board of Directors Meeting - May 2025Developer-Centric Threat Modeling: Embedding Security in Agile WorkflowsEscaping Vulnerability Hell: Bridging the Gap Between Developers and Security Teams - Ahmad SadeddinRethinking how we evaluate security agents for real-world use - Track 1Securing Access: Leveraging IGA, JIT & Policy Controls to Tackle OWASP ThreatsMaturing Your Application Security Program with ASVS-Driven Development - Aram HovsepyanEvolving Your Security Champions Program: Introducing the OWASP Security Champions Maturity Model
OWASP Foundation |

Noise vs. Signal: The Central Paradox of LLMs in Threat Modeling track 2

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER