Large language models (LLMs) are increasingly embedded in identity and access management (IAM) tools that support workflows such as account recovery, access request triage, provisioning, policy interpretation, and privileged access handling. In these settings, security risk is often dominated not by the model in isolation but by workflow exposure: who can trigger the system, what identity data and systems it can access, what actions it can execute, and which governance safeguards constrain behavior. We present a workflow-centric risk assessment method for LLM-enabled identity tools that uses the OWASP Top 10 for LLM Applications as a threat taxonomy and NIST Cybersecurity Framework (CSF) 2.0 as a governance outcomes layer. We instantiate OWASP categories as a compact library of 20 IAM-relevant, workflow-anchored threat scenarios and assign inherent risk scores per scenario. For each scenario, we map relevant CSF 2.0 Categories/Subcategories and score outcome coverage across tool/architecture archetypes. Residual risk is estimated by scaling inherent risk by uncovered outcome coverage, yielding an auditable signal to prioritize risk treatment and determine when workflows require mandatory human escalation versus safe automation. We additionally report backend sensitivity results under a fixed scenario suite and scoring rubric to quantify variance across LLM backends.
Sanaa S. Mironov, Shahmir Rizvi, B. Shariati· 2026 IEEE European Symposium...· 0 citations
A compact and configurable event-driven autoencoder that efficiently compresses neuromorphic data while preserving essential spatiotemporal structure for downstream inference and demonstrates the potential of compact event-driven models to advance environmentally conscious, low-power AI systems for high-speed perception in autonomous, mobile, and embedded computing environments.
Riadul Islam, Joey Mulé, Dhandeep Challagundla et al.· 0 citations