MASTRIA: Automated Threat Modeling and Risk Analysis for LLM Multi-Agent Systems
Abstract
Assessing the security of LLM-driven multi-agent systems (MASs) is challenging because execution paths, task-delegation relationships, and attack surfaces can evolve dynamically through model reasoning and inter-agent interactions, limiting the effectiveness of conventional threat-modeling approaches. Existing threat modeling frameworks for agentic systems address some of these challenges but still rely on manually authored architecture descriptions, diagrams, or contextual inputs, making their effectiveness sensitive to the completeness and accuracy of the provided system representation. To address this gap, we present MASTRIA, a three-phase automated threat modeling and analysis approach for MASs. Given the source code and an inventory of protected assets, MASTRIA first constructs a system model by identifying entry and exit points, generating an enriched data-flow diagram of agents, tools, data stores, and inter-agent communication, and deriving trust boundaries and segmentation. Next, it applies three complementary threat-identification modules: a deterministic rule-based OWASP Agentic Security Initiative (ASI) module, an agentic OWASP ASI module, and an agentic MAS taxonomy module. The identified threats are linked to relevant assets, attack paths, and adversarial techniques, then semantically de-duplicated and validated using both deterministic rules and LLM-based modules. Finally, MASTRIA assigns likelihood- and impact-based risk scores and generates mitigation recommendations. The effectiveness of MASTRIA was evaluated on six open-source multi-agent applications, recovering human-identified threats with 97.5% recall and 94.8% precision. The consistency of the results across repeated runs further demonstrates the feasibility of reproducible, implementation-grounded threat modeling for MASs.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.