PEPR 26 - Scaling Privacy Threat Modeling: From Architects to Developers @UsenixOrg
PEPR 26 - Scaling Privacy Threat Modeling: From Architects to Developers  @UsenixOrg
Uploaded June 2026 | Updated September 2026, 3 weeks ago
Scaling Privacy Threat Modeling: From Architects to Developers

Nitish Uplavikar, Comcast Cable

Privacy threat modeling is essential for assessing an application's privacy posture at an architecture level. Yet automated tooling that allows thus analysis to scale remains limited compared to security threat modeling. We present an open-source contribution of twelve privacy threat modeling rules implemented in Threagile, a machine assisted threat modeling toolkit. These rules analyze system architecture, data flows, and technical assets to automatically identify privacy violations including data minimization failures, unauthorized disclosure, insecure storage, and re-identification risks.
Our rules align with the LINDDUN privacy threat modeling framework, covering threat categories such as Linking, Identifying, Data Disclosure, Unawareness, and Non-compliance, while also addressing some OWASP-based Privacy Risks. Each rule provides high fidelity detection logic with actionable mitigations, enabling privacy-by-design practices early in development.
It can be used by privacy architects for assessments as well as designers and developers as a self-service tool. Our contribution bridges the gap between privacy threat modeling theory and practical implementation, offering a systematic privacy risk assessment.

View the full PEPR '26 program at usenix.org/conference/pepr26/program
PEPR 26 - Scaling Privacy Threat Modeling: From Architects to DevelopersNSDI 26 - FAST: An Efficient Scheduler for All-to-All GPU CommunicationNSDI 26 - Express Lane to Efficiency and Reliability: Multi-Dimensional Control in Meta’s Express..NSDI 26 - CascadeNet: Generating Network Traffic with High-Fidelity Temporal PatternsPEPR 26 - Privacy Review for Non-ManiacsSREcon24 Europe/Middle East/Africa - I Can OIDC You Clearly Now: How We Made Static Credentials a...NSDI 26 - Come Hell or Still Water: Alleviating Tail Latency in Cloud Block StoreVehicleSec 25 - You Can Drive But You Cannot Hide: Detection of Hidden Cellular GPS Vehicle...USENIX Security 25 - GPUHammer: Rowhammer Attacks on GPU Memories are PracticalSREcon25 Europe/Middle East/Africa - The Chicken or the Egg: Creating a Stable Preprod...NSDI 26 - Bifrost: Alibabas Next-Generation VPC Network with High-Performance Multipath...NSDI 26 - In Link We Trust: BFT at the Speed of CFT using Switches
USENIX |

PEPR '26 - Scaling Privacy Threat Modeling: From Architects to Developers

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER