Probabilistic security mapping of large language model integrations via stochastic Petri Nets

bracu.degree.levelPostgraduate
bracu.type.groupStudent Works
datacite.rightsOpen Access
dc.contributor.advisorFerdous, Md Sadek
dc.contributor.advisorSadeque, Farig Yousuf
dc.contributor.authorMohammad, Zaber
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-05-03T05:37:30Z
dc.date.available2026-05-03T05:37:30Z
dc.date.copyright2026
dc.date.issued2026
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 76-82).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Master of Science in Computer Science and Engineering, 2026.en_US
dc.description.abstractLarge Language Models (LLMs) are becoming increasingly popular for use in modern software systems. However, with increasing popularity, newly introduced security risks have emerged while integrating LLMs in a software system. These security gaps do not align with the traditional cybersecurity framework. To address it, this study specifically focuses on modeling three distinct related threats: prompt injection, context extraction, and Denial of Service (DoS) by resource exhaustion. First, the research maps these three LLM security aspects with the traditional CIA triad (Confidentiality, Integrity, Availability) and maps the system assets with corresponding justifications to show exactly what component of a system is at risk during these specific attacks. After that, the research investigates three distinct and independent threat models across the LLM architecture. First, Prompt Injection is analyzed at the input processing layer to mathematically evaluate Defensive Depth theory. Second, Data Exfiltration is evaluated during output scanning to formalize the Temporal Defense theory. Finally, a Denial of Service (DoS) attack is modeled to validate the Saturation theory. To transition from theoretical risk to measurable impact, an independent threat model is developed using Petri Net diagram to simulate these distinct stages of the LLM pipeline. Mathematical analysis is then conducted using a Continuous-Time Markov Chain (CTMC) and finite queuing theories. Specifically for the DoS evaluation, the adversarial arrival rate (λ) and system processing bottleneck (ρ) are modeled to measure the queue wait times and resource depletion. Across all three threat vectors, Monte Carlo validation is used to ensure the theoretical mathematical calculations match the simulated reality. The result provides a formalized mathematical baseline for each independent vulnerability. The findings demonstrate the exact architectural trade-offs to implement input-layer defensive depth, the temporal cost for output sanitization, and the critical threshold where system queues saturate and drop legitimate requests during a DoS attack. These insights help developer to design more resilient, optimized, and mathematically verifiable security architecture for deployed LLM applications.en_US
dc.description.degreeMaster of Science in Computer Science and Engineering
dc.description.statementofresponsibilityZaber Mohammad
dc.format.extent82 pages
dc.identifier.otherID 1000054897
dc.identifier.urihttp://hdl.handle.net/10361/28146
dc.language.isoenen_US
dc.publisherBRAC Universityen_US
dc.rightsBRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission.
dc.subjectLarge Language Modelsen_US
dc.subjectPrompt injectionen_US
dc.subjectSystem securityen_US
dc.subjectThreat simulationen_US
dc.subject.lcshNatural language generation (Computer science).
dc.subject.lcshComputer security--Simulation methods.
dc.subject.lcshData protection.
dc.subject.lcshComputer networks--Security measures.
dc.titleProbabilistic security mapping of large language model integrations via stochastic Petri Netsen_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
1000054897_CSE.pdf
Size:
824.25 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: