Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

The Right Tool for the Job: On the Selection of Mitigations for GenAI Privacy Threats

A position paper bridging the gap between GenAI privacy threats and mitigation techniques
Jonah Bellemans; Qianying Liao; Laurens Sion; Lieven Desmet; Wouter Joosenยท 2026ยท DOI 10.48550/arXiv.2609.20884

The core problem

Generative Artificial Intelligence (GenAI) has rapidly evolved from an experimental technology into a foundational component of modern software systems. However, as its adoption grows, protecting sensitive personal data becomes increasingly challenging. Specifically, GenAI systems not only amplify traditional privacy threats but also introduce new inference-based risks, such as constructing detailed user profiles from seemingly harmless inputs. In response, privacy threat modeling frameworks are beginning to capture GenAI-specific privacy threats with finer granularity. At the same time, a growing number of mitigation techniques have been proposed to address these threats. However, although knowledge of both threats and mitigations continues to mature, the problem- and solution-space have developed largely independently. This position paper argues that the primary challenge in GenAI privacy engineering is not the lack of knowledge about privacy threats or mitigation techniques, but the missing bridge between them. We decompose this gap into three sub-problems: (i) lack of fine-grained threat-to-mitigation mapping for GenAI systems, (ii) inapplicable solution-space assumptions in th

Innovation

The paper identifies three sub-problems that constitute the gap between GenAI privacy threats and mitigations:

1. **Lack of fine-grained threat-to-mitigation mapping for GenAI systems**: Existing mapping methods are not granular enough to capture the specific characteristics of GenAI threats, leading to mismatches between threats and mitigations.

2. **Inapplicable solution-space assumptions in the GenAI context**: Many mitigation techniques assume a traditional software architecture, which does not hold for GenAI systems, making them ineffective or impractical.

3. **Prioritization difficulty under GenAI constraints**: GenAI systems operate under unique constraints (e.g., resource limitations, latency requirements, and model opacity), making it hard to prioritize mitigations effectively.

Based on these sub-problems, the authors derive four recommendations for future mitigation-selection approaches:

- **Recommendation 1**: Develop fine-grained threat-to-mitigation mappings tailored to GenAI-specific threats.
- **Recommendation 2**: Re-evaluate solution-space assumptions to ensure mitigations are applicable in GenAI contexts.
- **Recommendation 3**: Incorporate GenAI constraints

Generative Artificial Intelligence (GenAI) has rapidly evolved from an experimental technology into a foundational component of modern software systems. However, as its adoption grows, protecting sensitive personal data becomes increasingly challenging. Specifically, GenAI systems not only amplify traditional privacy threats but also introduce new inference-based risks, such as constructing detailed user profiles from seemingly harmless inputs. In response, privacy threat modeling frameworks are beginning to capture GenAI-specific privacy threats with finer granularity. At the same time, a growing number of mitigation techniques have been proposed to address these threats. However, although knowledge of both threats and mitigations continues to mature, the problem- and solution-space have developed largely independently. This position paper argues that the primary challenge in GenAI privacy engineering is not the lack of knowledge about privacy threats or mitigation techniques, but the missing bridge between them. We decompose this gap into three sub-problems: (i) lack of fine-grained threat-to-mitigation mapping for GenAI systems, (ii) inapplicable solution-space assumptions in the GenAI context, and (iii) prioritization difficulty under GenAI constraints. We derive four recommendations for future mitigation-selection approaches, and outline a suggested approach that extends established threat-to-mitigation mapping methods to GenAI-specific threat characteristics. We propose a research agenda toward more systematic privacy mitigation selection for GenAI-based systems.
As a position paper, this work does not follow a traditional empirical methodology. Instead, it synthesizes existing knowledge from privacy threat modeling and mitigation research to identify and articulate a critical gap. The authors conduct a conceptual analysis of the current state of GenAI privacy engineering, drawing on established frameworks and techniques. They decompose the identified gap into three sub-problems and derive four recommendations for future mitigation-selection approaches. The paper outlines a suggested approach that extends established threat-to-mitigation mapping methods to GenAI-specific threat characteristics, proposing a research agenda toward more systematic privacy mitigation selection for GenAI-based systems. The methodology is thus argumentative and agenda-setting, aiming to stimulate further research rather than present new experimental results.

Why it matters

The authors argue that the disconnect between threat modeling and mitigation selection is the primary obstacle to effective GenAI privacy engineering. They emphasize that while both areas have matured independently, their integration is crucial for practical deployment. The three sub-problems highlight the need for a paradigm shift: from generic mitigation catalogs to context-aware, GenAI-specific selection frameworks. The four recommendations provide concrete directions for researchers and practitioners. For instance, fine-grained mapping requires a taxonomy of GenAI threats that captures inference-based risks and their propagation through the system. Re-evaluating solution-space assumptions calls for a critical assessment of techniques like differential privacy, federated learning, and secure multi-party computation in the context of large language models and generative models. Prioritization must account for trade-offs between privacy, utility, and performance, which are exacerbated by the scale and complexity of GenAI systems. The suggested approach extends established methods, such as LINDDUN, to GenAI by incorporating threat characteristics like model inversion, membership inference, and prompt leakage. The paper concludes with a research agenda that includes developing a comprehensive threat-to-mitigation mapping, creating evaluation benchmarks for GenAI privacy mitigations, and establishing guidelines for selecting mitigations based on system constraints. This agenda aims to bridge the gap and enable more systematic privacy engineering for GenAI-based systems.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ