{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T18:21:42Z","timestamp":1757614902951,"version":"3.44.0"},"reference-count":107,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T00:00:00Z","timestamp":1752710400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T00:00:00Z","timestamp":1752710400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2025,8]]},"DOI":"10.1007\/s10207-025-01094-0","type":"journal-article","created":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T19:29:16Z","timestamp":1752780556000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Comprehensive User Study on Medical Device Threat Modeling Methodologies and CyberLlama2 - MEDICALHARM Threat Modeling Assistant."],"prefix":"10.1007","volume":"24","author":[{"given":"Emmanuel","family":"Kwarteng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mumin","family":"Cebe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jamila","family":"Kwarteng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Naveen","family":"Bansal","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,17]]},"reference":[{"key":"1094_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.smhl.2022.100295","volume":"25","author":"E Kwarteng","year":"2022","unstructured":"Kwarteng, E., Cebe, M.: A survey on security issues in modern implantable devices: Solutions and future issues. Smart Health 25, 100295 (2022)","journal-title":"Smart Health"},{"key":"1094_CR2","unstructured":"Quaadgras, A.: Digital transformation in healthcare delivery systems: what have we learned?, March 2021. https:\/\/ilp.mit.edu\/attend\/digital-transformation Last Accessed October 5, 2023 (2023)"},{"key":"1094_CR3","doi-asserted-by":"publisher","first-page":"678","DOI":"10.1109\/ACCESS.2015.2437951","volume":"3","author":"SM Riazul Islam","year":"2015","unstructured":"Riazul Islam, S.M., Daehan Kwak, M.D., Kabir, H., Hossain, M., Kwak, K.-S.: The internet of things for health care: A comprehensive survey. IEEE Access 3, 678\u2013708 (2015)","journal-title":"IEEE Access"},{"issue":"6","key":"1094_CR4","doi-asserted-by":"publisher","first-page":"411","DOI":"10.32604\/csse.2020.35.411","volume":"35","author":"VS Naresh","year":"2020","unstructured":"Naresh, V.S., Pericherla, S.S., Murty, P.S.R., Sivaranjani, R.: Internet of things in healthcare: Architecture, applications, challenges, and solutions. Comput. Syst. Sci. Eng. 35(6), 411\u2013421 (2020)","journal-title":"Comput. Syst. Sci. Eng."},{"key":"1094_CR5","unstructured":"Deloitte. Global health care outlook. https:\/\/www2.deloitte.com\/content\/dam\/Deloitte\/global\/Documents\/Life-Sciences-Health-Care\/gx-health-care-outlook-Final.pdf last accessed August 16, 2022 (2022)"},{"key":"1094_CR6","unstructured":"Vakhter, V., Soysal, B., Schaumont, P., Guler, U.: Security for emerging miniaturized wireless biomedical devices: Threat modeling with application to case studies. (2021) arXiv preprint arXiv: 2105.05937"},{"key":"1094_CR7","doi-asserted-by":"crossref","unstructured":"Camara, C., Pens-Lopez, P., Tapiador, J.E.: Security and privacy issues in implantable medical devices: A comprehensive survey. Journal of Biomedical Informatics (2015)","DOI":"10.1016\/j.jbi.2015.04.007"},{"key":"1094_CR8","unstructured":"Forbes. How do we close the skills gap in the cybersecurity industry? https:\/\/www.forbes.com\/sites\/forbesbusinesscouncil\/2023\/02\/28\/how-do-we-close-the-skills-gap-in-the-cybersecurity-industry\/?sh=490e5438e178 Last accessed June 23, 2023"},{"key":"1094_CR9","doi-asserted-by":"crossref","unstructured":"et\u00a0al. Newaz, AKM\u00a0Iqtidar. A survey on security and privacy issues in modern healthcare systems: Attacks and defenses. ACM Transactions on Computing for Healthcare 1-44., (2021)","DOI":"10.1145\/3453176"},{"key":"1094_CR10","unstructured":"stride. The threats to our products. https:\/\/shostack.org\/files\/microsoft\/The-Threats-To-Our-Products.docx April 20, (2025)"},{"key":"1094_CR11","doi-asserted-by":"crossref","unstructured":"Siddiqi, M.A., Seepers, R.M., Hamad, M., Prevelakis, V., Strydis, C.: Attack-tree-based threat modeling of medical implants. In PROOFS, pages 32\u201349, (2018)","DOI":"10.29007\/8gxh"},{"key":"1094_CR12","volume-title":"Threat modeling: Designing for security","author":"A Shostack","year":"2014","unstructured":"Shostack, A.: Threat modeling: Designing for security. John Wiley & Sons, Hoboken, New Jersey (2014)"},{"key":"1094_CR13","unstructured":"LeBlanc, D., August, D.: 2007. https:\/\/learn.microsoft.com\/en-us\/archive\/blogs\/david_leblanc\/dreadful Last Accessed October 5, (2023)"},{"key":"1094_CR14","unstructured":"Peeters, J.: Agile security requirements engineering. In Symposium on Requirements Engineering for Information Security, volume\u00a012, (2005)"},{"issue":"12","key":"1094_CR15","first-page":"21","volume":"24","author":"B Schneier","year":"1999","unstructured":"Schneier, B.: Attack trees. Dr. Dobb\u2019s journal 24(12), 21\u201329 (1999)","journal-title":"Attack trees. Dr. Dobb\u2019s journal"},{"key":"1094_CR16","unstructured":"Mitre. Mitre att &ck\u00aeR matrix"},{"key":"1094_CR17","unstructured":"Van\u00a0Palm, G., Legay, A.: Threat modeling with attack-defense trees"},{"issue":"1","key":"1094_CR18","first-page":"53","volume":"4","author":"AS Sodiya","year":"2007","unstructured":"Sodiya, A.S., Onashoga, S.A., Oladunjoye, B.A.: Threat modeling using fuzzy logic paradigm. Informing Science: International Journal of an Emerging Transdiscipline 4(1), 53\u201361 (2007)","journal-title":"Informing Science: International Journal of an Emerging Transdiscipline"},{"key":"1094_CR19","doi-asserted-by":"crossref","unstructured":"den Braber, F.: Theo Dimitrakos, B.A Gran, Lund, M.S., Stolen, K.,Aagedal, J.O.: The coras methodology: model-based risk assessment using uml and up. In UML and the Unified Process, pages 332\u2013357. IGI Global, 2003","DOI":"10.4018\/978-1-93177-744-5.ch017"},{"key":"1094_CR20","unstructured":"Luo, Z., Xu, C., Zhao, P, Sun, Q, Geng, X., Hu, W., Tao, C., Ma, J., Lin, Q., Jiang, D.: Wizardcoder: Empowering code large language models with evol-instruct. arXiv preprint arXiv: 2306.08568 , (2023)"},{"key":"1094_CR21","unstructured":"Wu, S., Irsoy, O., Lu, S., Dabravolski, V., Dredze M., Sebastian Gehrmann, Prabhanjan Kambadur, David Rosenberg, and Gideon Mann. Bloomberggpt: A large language model for finance. arXiv preprint arXiv: 2303.17564 , (2023)"},{"key":"1094_CR22","unstructured":"Fraiwan, M., Khasawneh, N.: A review of chatgpt applications in education, marketing, software engineering, and healthcare: Benefits, drawbacks, and research directions. arXiv preprint arXiv: 2305.00237, (2023)"},{"issue":"3","key":"1094_CR23","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1177\/20965311231168423","volume":"6","author":"S Jiahong","year":"2023","unstructured":"Jiahong, S., Yang, W.: Unlocking the power of chatgpt: A framework for applying generative ai in education. ECNU Review of Education 6(3), 355\u2013366 (2023)","journal-title":"ECNU Review of Education"},{"issue":"1","key":"1094_CR24","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1186\/s41239-023-00392-8","volume":"20","author":"H Crompton","year":"2023","unstructured":"Crompton, H., Burke, D.: Artificial intelligence in higher education: the state of the field. Int. J. Educ. Technol. High. Educ. 20(1), 22 (2023)","journal-title":"Int. J. Educ. Technol. High. Educ."},{"key":"1094_CR25","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1016\/j.procir.2023.04.001","volume":"119","author":"X Wang","year":"2023","unstructured":"Wang, X., Anwer, N., Dai, Y., Liu, A.: Chatgpt for design, manufacturing, and education. Procedia CIRP 119, 7\u201314 (2023)","journal-title":"Procedia CIRP"},{"issue":"8","key":"1094_CR26","doi-asserted-by":"publisher","first-page":"1930","DOI":"10.1038\/s41591-023-02448-8","volume":"29","author":"AJ Thirunavukarasu","year":"2023","unstructured":"Thirunavukarasu, A.J., Ting, D.S.J., Elangovan, K., Gutierrez, L., Tan, T.F., Ting, D.S.W.: Large language models in medicine. Nat. Med. 29(8), 1930\u20131940 (2023)","journal-title":"Nat. Med."},{"key":"1094_CR27","first-page":"28541","volume":"36","author":"C Li","year":"2024","unstructured":"Li, C., Wong, C., Zhang, S., Usuyama, N., Liu, H., Yang, J., Naumann, T., Poon, H., Gao, J.: Llava-med: Training a large language-and-vision assistant for biomedicine in one day. Adv. Neural. Inf. Process. Syst. 36, 28541\u201328564 (2024)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"1094_CR28","unstructured":"chatGPT. Introducing chatgpt. https:\/\/openai.com\/index\/chatgpt\/ April 20, (2025)"},{"key":"1094_CR29","unstructured":"Radford, A., Karthik Narasimhan, Ilya Sutskever, et al.: Improving language understanding by generative pre-training, Tim Salimans (2018)"},{"issue":"70","key":"1094_CR30","first-page":"1","volume":"25","author":"HW Chung","year":"2024","unstructured":"Chung, H.W., Hou, L., Longpre, S., Zoph, B., Tay, Y., Fedus, W., Li, Y., Wang, X., Dehghani, M., Brahma, S., et al.: Scaling instruction-finetuned language models. J. Mach. Learn. Res. 25(70), 1\u201353 (2024)","journal-title":"J. Mach. Learn. Res."},{"issue":"140","key":"1094_CR31","first-page":"1","volume":"21","author":"C Raffel","year":"2020","unstructured":"Raffel, C., Shazeer, N., Roberts, A., Lee, K., Narang, S., Matena, M., Zhou, Y., Li, W., Liu, P.J.: Exploring the limits of transfer learning with a unified text-to-text transformer. J. Mach. Learn. Res. 21(140), 1\u201367 (2020)","journal-title":"J. Mach. Learn. Res."},{"key":"1094_CR32","unstructured":"falcon. Introducing the technology innovation institutes falcon 3. https:\/\/falconllm.tii.ae\/ April 20, (2025)"},{"key":"1094_CR33","unstructured":"Llama. Llama 2: open source, free for research and commercial use. https:\/\/www.llama.com\/llama2\/ April 20, (2025)"},{"key":"1094_CR34","unstructured":"Touvron, H., Lavril, T., Izacard, G., Martinet, X., Lachaux, M.-A., Lacroix, T., Rozi\u00e8re, B., Goyal, N., Hambro, E., Azhar, F., et al.: Llama: Open and efficient foundation language models. arXiv preprint arXiv: 2302.13971 , (2023)"},{"key":"1094_CR35","unstructured":"Minghao, W., Waheed, A., Zhang, C., Abdul-Mageed, M., Aji, A.F.: Lamini-lm A diverse herd of distilled models from large-scale instructions. arXiv preprint arXiv: 2304.14402, (2023)"},{"key":"1094_CR36","doi-asserted-by":"crossref","unstructured":"Kim, Y., Rush, A.M.: Sequence-level knowledge distillation. arXiv preprint arXiv: 1606.07947 (2016)","DOI":"10.18653\/v1\/D16-1139"},{"key":"1094_CR37","unstructured":"Gao, P., Han, J., Zhang, R., Lin, Z., Geng, S., Zhou, A., Zhang, W., Lu, P., He, C., Yue, X., et\u00a0al.: Llama-adapter v2: Parameter-efficient visual instruction model. arXiv preprint arXiv: 2304.15010, (2023)"},{"key":"1094_CR38","unstructured":"Chiang, W.-L., Li, Z., Lin, Z., Sheng, Y., Wu, Z., Zhang, H., Zheng, L., Zhuang, S., Zhuang, Y., Gonzalez, J.E., et\u00a0al.: Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality, march 2023. URL https:\/\/lmsys. org\/blog\/2023-03-30-vicuna, 3(5), (2023)"},{"key":"1094_CR39","unstructured":"FDA. Classification of products as drugs and devices and additional product classification issues, September (2017)"},{"key":"1094_CR40","unstructured":"FDA. How to determine if your product is a medical device, September (2022)"},{"key":"1094_CR41","doi-asserted-by":"crossref","unstructured":"Kwarteng, Cebe, M.: Medicalharm - a threat modeling designed for modern medical devices. 22nd IEEE International Conference on Trust, Security and Privacy in Computing and Communications, Exeter UK, 2023","DOI":"10.1109\/TrustCom60117.2023.00157"},{"key":"1094_CR42","doi-asserted-by":"crossref","unstructured":"Kwarteng, E., Cebe, M.: Medicalharm: A threat modeling designed for modern medical devices and a comprehensive study on effectiveness, user satisfaction, and security perspectives. International Journal of Information Security, pages 1\u201344, (2024)","DOI":"10.1007\/s10207-024-00826-y"},{"issue":"6","key":"1094_CR43","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1007\/s00604-022-05317-2","volume":"189","author":"SU Singh","year":"2022","unstructured":"Singh, S.U., Chatterjee, S., Lone, S.A., Ho, H.-H., Kaswan, K., Peringeth, K., Khan, A., Chiang, Y.-W., Lee, S., Lin, Z.-H.: Advanced wearable biosensors for the detection of body fluids and exhaled breath by graphene. Microchim. Acta 189(6), 236 (2022)","journal-title":"Microchim. Acta"},{"key":"1094_CR44","unstructured":"Medical\u00a0Life Sciences. Medical devices"},{"issue":"1","key":"1094_CR45","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng, M., Wuyts, K., Scandariato, R., Preneel, B., Joosen, W.: A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requirements Eng. 16(1), 3\u201332 (2011)","journal-title":"Requirements Eng."},{"key":"1094_CR46","unstructured":"Shevchenko, N., Chick, T.A., O\u2019Riordan, P., Scanlon, T.P., Woody, C.: Threat modeling: A summary of available methods. Technical report, Carnegie Mellon University Software Engineering Institute Pittsburgh United. (2018)"},{"key":"1094_CR47","unstructured":"Bochniewicz, E., Chase, M.P, Coley, S.M.C., Wallace, K., Weir, M., Zuk, M.: Playbook for threat modeling medical devices, MITRE and the Medical Device Innovation Consortium (MDIC) (2021)"},{"key":"1094_CR48","unstructured":"NIST. Sp 800-30 rev 1. guide for conducting risk assessments"},{"key":"1094_CR49","unstructured":"Conklin, L.: Threat modeling process"},{"key":"1094_CR50","doi-asserted-by":"crossref","unstructured":"Crotty, J., Daniel, E.: Cyber threat: Its origins and consequence and the use of qualitative and quantitative methods in cyber risk assessment. Applied Computing and Informatics, (ahead-of-print), (2022)","DOI":"10.1108\/ACI-07-2022-0178"},{"issue":"2","key":"1094_CR51","doi-asserted-by":"publisher","first-page":"615","DOI":"10.5114\/biolsport.2023.125623","volume":"40","author":"I Dergaa","year":"2023","unstructured":"Dergaa, I., Chamari, K., Zmijewski, P., Saad, H.B.: From human writing to artificial intelligence generated text: examining the prospects and potential threats of chatgpt in academic writing. Biol. Sport 40(2), 615\u2013622 (2023)","journal-title":"Biol. Sport"},{"key":"1094_CR52","unstructured":"Hoffmann, J., Borgeaud, S., Mensch, A., Buchatskaya, E., Cai, T., Rutherford, E., de\u00a0Las Casas, D., Hendricks, L.A., Welbl, J., Clark, A., et\u00a0al.: Training compute-optimal large language models. arXiv preprint arXiv: 2203.15556, (2022)"},{"key":"1094_CR53","unstructured":"Keskar, N.S., McCann, B., Varshney, L.R., Xiong, C., Socher, R.: Ctrl: A conditional transformer language model for controllable generation. arXiv preprint arXiv: 1909.05858, (2019)"},{"key":"1094_CR54","doi-asserted-by":"crossref","unstructured":"Williams, I., Yuan, X.: Evaluating the effectiveness of microsoft threat modeling tool. In Proceedings of the 2015 information security curriculum development conference, pages 1\u20136, (2015)","DOI":"10.1145\/2885990.2885999"},{"key":"1094_CR55","doi-asserted-by":"publisher","first-page":"24448","DOI":"10.1109\/ACCESS.2023.3255548","volume":"11","author":"A Rodrigues","year":"2023","unstructured":"Rodrigues, A., Villela, M.L.B., Feitosa, E.L.: Privacy threat modeling language. IEEE Access 11, 24448\u201324471 (2023)","journal-title":"IEEE Access"},{"key":"1094_CR56","unstructured":"Selin, J.: Evaluation of threat modeling methodologies. (2019)"},{"issue":"4","key":"1094_CR57","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1109\/MSEC.2021.3125229","volume":"20","author":"Z Shi","year":"2021","unstructured":"Shi, Z., Graffi, K., Starobinski, D., Matyunin, N.: Threat modeling tools: A taxonomy. IEEE Security & Privacy 20(4), 29\u201339 (2021)","journal-title":"IEEE Security & Privacy"},{"key":"1094_CR58","first-page":"35","volume":"2008","author":"A Shostack","year":"2008","unstructured":"Shostack, A.: Experiences threat modeling at microsoft. MODSEC@ MoDELS 2008, 35 (2008)","journal-title":"MODSEC@ MoDELS"},{"key":"1094_CR59","doi-asserted-by":"crossref","unstructured":"Ranade, P., Piplai, A., Joshi, A., Finin, T.: Cybert: Contextualized embeddings for the cybersecurity domain. In 2021 IEEE International Conference on Big Data (Big Data), pages 3334\u20133342. IEEE, (2021)","DOI":"10.1109\/BigData52589.2021.9671824"},{"issue":"4","key":"1094_CR60","doi-asserted-by":"publisher","first-page":"615","DOI":"10.3390\/jcp1040031","volume":"1","author":"K Ameri","year":"2021","unstructured":"Ameri, K., Hempel, M., Sharif, H., Lopez, J., Jr., Perumalla, K.: Cybert: Cybersecurity claim classification by fine-tuning the bert language model. Journal of Cybersecurity and Privacy 1(4), 615\u2013637 (2021)","journal-title":"Journal of Cybersecurity and Privacy"},{"key":"1094_CR61","doi-asserted-by":"crossref","unstructured":"Das, S.S., Serra, E., Halappanavar, M., Pothen, A., Al-Shaer, E.: V2w-bert: A framework for effective hierarchical multiclass classification of software vulnerabilities. In 2021 IEEE 8th International Conference on Data Science and Advanced Analytics (DSAA), pages 1\u201312. IEEE, (2021)","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"1094_CR62","doi-asserted-by":"crossref","unstructured":"Zhou, S., Liu, J., Zhong, X., Zhao, W.: Named entity recognition using bert with whole world masking in cybersecurity domain. In 2021 IEEE 6th International Conference on Big Data Analytics (ICBDA), pages 316\u2013320. IEEE, (2021)","DOI":"10.1109\/ICBDA51983.2021.9403180"},{"key":"1094_CR63","doi-asserted-by":"crossref","unstructured":"Chen, Y.X., Ding, J., Li, D., Chen, Z.: Joint bert model based cybersecurity named entity recognition. In Proceedings of the 2021 4th International Conference on Software Engineering and Information Management, pages 236\u2013242, (2021)","DOI":"10.1145\/3451471.3451508"},{"key":"1094_CR64","doi-asserted-by":"publisher","first-page":"23164","DOI":"10.1609\/aaai.v38i21.30362","volume":"38","author":"G Agrawal","year":"2024","unstructured":"Agrawal, G., Pal, K., Deng, Y., Liu, H., Chen, Y.-C.: Cyberq: Generating questions and answers for cybersecurity education using knowledge graph-augmented llms. In Proceedings of the AAAI Conference on Artificial Intelligence 38, 23164\u201323172 (2024)","journal-title":"In Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"1094_CR65","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.106529","volume":"210","author":"J Yin","year":"2020","unstructured":"Yin, J., Tang, M.J., Cao, J., Wang, H.: Apply transfer learning to cybersecurity: Predicting exploitability of vulnerabilities by description. Knowl.-Based Syst. 210, 106529 (2020)","journal-title":"Knowl.-Based Syst."},{"key":"1094_CR66","unstructured":"Sewak, M., Emani, V., Naresh, A.: Crush: Cybersecurity research using universal llms and semantic hypernetworks. (2023)"},{"key":"1094_CR67","unstructured":"Shao, M., Chen, B., Jancheska, S., Dolan-Gavitt, B., Garg, S., Karri, R., Shafique, M.: An empirical evaluation of llms for solving offensive security challenges. arXiv preprint arXiv: 2402.11814, (2024)"},{"key":"1094_CR68","doi-asserted-by":"crossref","unstructured":"Shafee, S., Bessani, A., Ferreira, P.M.: Evaluation of llm chatbots for osint-based cyberthreat awareness. arXiv preprint arXiv: 2401.15127, (2024)","DOI":"10.2139\/ssrn.4703135"},{"key":"1094_CR69","doi-asserted-by":"crossref","unstructured":"Yamin, M.M. Hashmi, E., Ullah, M., Katt, B.: Applications of llms for generating cyber security exercise scenarios. (2024)","DOI":"10.21203\/rs.3.rs-3970015\/v1"},{"key":"1094_CR70","doi-asserted-by":"crossref","unstructured":"Goto, T., Ono, K., Morita, A.: Evaluating the cybersecurity robustness of commercial llms against adversarial prompts: A promptbench analysis. Authorea Preprints, (2024)","DOI":"10.36227\/techrxiv.170975411.12532297\/v1"},{"key":"1094_CR71","unstructured":"Kuehn, P., Schmidt, M., Reuter, C.: Threatcrawl: A bert-based focused crawler for the cybersecurity domain. arXiv preprint arXiv: 2304.11960, (2023)"},{"key":"1094_CR72","unstructured":"Bayer, M., Kuehn, P., Shanehsaz, R., Reuter, C.: Cysecbert: A domain-adapted language model for the cybersecurity domain. arXiv preprint arXiv: 2212.02974, (2022)"},{"key":"1094_CR73","doi-asserted-by":"crossref","unstructured":"Aghaei, E., Niu, X., Shadid, W., Al-Shaer, E.: Securebert: A domain-specific language model for cybersecurity. In International Conference on Security and Privacy in Communication Systems, pages 39\u201356. Springer, (2022)","DOI":"10.1007\/978-3-031-25538-0_3"},{"issue":"3","key":"1094_CR74","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1136\/jme.2002.001594","volume":"30","author":"JP Bentley","year":"2004","unstructured":"Bentley, J.P., Thacker, P.G.: The influence of risk and monetary payment on the research participation decision making process. J. Med. Ethics 30(3), 293\u2013298 (2004)","journal-title":"J. Med. Ethics"},{"issue":"1","key":"1094_CR75","doi-asserted-by":"publisher","first-page":"70","DOI":"10.4103\/2229-3485.106394","volume":"4","author":"M Pandya","year":"2013","unstructured":"Pandya, M., Desai, C.: Compensation in clinical research: The debate continues. Perspect. Clin. Res. 4(1), 70\u201374 (2013)","journal-title":"Perspect. Clin. Res."},{"key":"1094_CR76","unstructured":"HISAC. About health information sharing and analysis center. https:\/\/h-isac.org\/about-h-isac\/ Last Accessed July 5, (2023)"},{"key":"1094_CR77","unstructured":"Linkedin. Welcome to your professional community. https:\/\/www.linkedin.com\/ Last Accessed July 5, 2023"},{"key":"1094_CR78","unstructured":"Qualtrics. Build technology that closes experience gaps. https:\/\/www.qualtrics.com\/about\/ Last Accessed July 5, 2023"},{"key":"1094_CR79","unstructured":"Bodeau, D.J., McCollum, C.D., Fox, D.B.: Cyber threat modeling: Survey, assessment, and representative framework. Mitre Corp, Mclean, (2018)"},{"key":"1094_CR80","unstructured":"Shevchenko, N., Frye, B.R., Woody, C.: Evaluation and recommendations. Carnegie Mellon Univ. Softw. Eng. Inst, Threat modeling (2018)"},{"key":"1094_CR81","unstructured":"Laurens Sion. Automated threat analysis for security and privacy. (2020)"},{"key":"1094_CR82","unstructured":"NIST\u00a0Special Pub. 800-30 rev 1: Guide for conducting risk assessments. US Dept. of Commerce, (2012)"},{"key":"1094_CR83","doi-asserted-by":"crossref","unstructured":"Bygd\u00e5s, E., Jaatun, L.A., Antonsen, S.B., Ringen, A., Eiring, E.: Evaluating threat modeling tools: Microsoft tmt versus owasp threat dragon. In 2021 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), pages 1\u20137. IEEE, (2021)","DOI":"10.1109\/CyberSA52016.2021.9478215"},{"key":"1094_CR84","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/s00766-013-0195-2","volume":"20","author":"R Scandariato","year":"2015","unstructured":"Scandariato, R., Wuyts, K., Joosen, W.: A descriptive study of microsoft\u2019s threat modeling technique. Requirements Eng. 20, 163\u2013180 (2015)","journal-title":"Requirements Eng."},{"key":"1094_CR85","unstructured":"HHS. Breach portal: Notice to the secretary of hhs breach of unsecured protected health information. https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf last Accessed April 15, (2024)"},{"issue":"1","key":"1094_CR86","doi-asserted-by":"publisher","first-page":"56","DOI":"10.5937\/telfor2001056H","volume":"12","author":"A Hajri\u0107","year":"2020","unstructured":"Hajri\u0107, A., Smaka, T., Barakovi\u0107, S., Barakovi\u0107, H.J.: Methods, methodologies, and tools for threat modeling with case study. Telfor Journal 12(1), 56\u201361 (2020)","journal-title":"Telfor Journal"},{"key":"1094_CR87","unstructured":"Mohanakrishnan, R.: What is threat modeling? definition, process, examples, and best practices. https:\/\/www.spiceworks.com\/it-security\/network-security\/articles\/what-is-threat-modeling-definition-process-examples-and-best-practices\/ Last Accessed July 27, (2023)"},{"key":"1094_CR88","unstructured":"Dettmers, T., Pagnoni, A., Holtzman, A., Zettlemoyer, L.: Qlora: Efficient finetuning of quantized llms. Advances in Neural Information Processing Systems, 36, (2024)"},{"key":"1094_CR89","unstructured":"CVE. Common vulnerability exposure. https:\/\/www.cve.org\/Downloads lastaccessed April 15, (2024)"},{"key":"1094_CR90","unstructured":"CWE. Common weakness enumeration. https:\/\/cwe.mitre.org\/data\/downloads.html lastaccessed April 15, (2024)"},{"key":"1094_CR91","unstructured":"CAPEC. Common attack pattern enumeration and classification. https:\/\/capec.mitre.org\/ lastaccessed April 15, (2024)"},{"key":"1094_CR92","unstructured":"Taori, R., Gulrajani, I., Zhang, T., Dubois, Y., Li, X., Guestrin, C., Liang, P., Hashimoto, T.B.: Stanford alpaca: an instruction-following llama model (2023). URL https:\/\/github. com\/tatsu-lab\/stanford_alpaca, (2023)"},{"key":"1094_CR93","unstructured":"Huggingface. Advanced autotrain"},{"key":"1094_CR94","unstructured":"Meta. Llama-2-7b-chat-hf. https:\/\/huggingface.co\/meta-llama\/Llama-2-7b-chat-hf April 19, (2024)"},{"key":"1094_CR95","unstructured":"Hu, E.J., Shen, Y., Wallis, P., Allen-Zhu, Z., Li, Y., Wang, S., Wang, L., Chen, W.: Lora: Low-rank adaptation of large language models. arXiv preprint arXiv: 2106.09685, (2021)"},{"key":"1094_CR96","doi-asserted-by":"crossref","unstructured":"Zhang, J., Wen, H., Deng, L., Xin, M., Ii, Z., Li, L., Zhu, H., Sun, L.: Hackmentor: Fine-tuning large language models for cybersecurity. In Proceedings of the 22nd Internaltional Conference on trust, Security and Privacy in Computing and Communications (TrustCom). IEEE Computer Society Conference Publishing Services, (2023)","DOI":"10.1109\/TrustCom60117.2023.00076"},{"key":"1094_CR97","unstructured":"Lin, C.-Y.: ROUGE: A package for automatic evaluation of summaries. In Text Summarization Branches Out, pages 74\u201381, Barcelona, Spain, July 2004. Association for Computational Linguistics"},{"key":"1094_CR98","unstructured":"Pillutla, K., Swayamdipta, S., Zellers, R., Thickstun, J., Welleck, S., Choi, Y., Harchaoui, Z.: Mauve: Measuring the gap between neural text and human text using divergence frontiers. In: NeurIPS (2021)"},{"key":"1094_CR99","doi-asserted-by":"crossref","unstructured":"Morris, A., Maier, V., Green, P.: From wer and ril to mer and wil: improved evaluation measures for connected speech recognition. 01, (2004)","DOI":"10.21437\/Interspeech.2004-668"},{"key":"1094_CR100","unstructured":"Banerjee, S., Lavie, A.: METEOR: An automatic metric for MT evaluation with improved correlation with human judgments. In Proceedings of the ACL Workshop on Intrinsic and Extrinsic Evaluation Measures for Machine Translation and\/or Summarization, pages 65\u201372, Ann Arbor, Michigan, June 2005. Association for Computational Linguistics"},{"key":"1094_CR101","doi-asserted-by":"crossref","unstructured":"Popovi\u0107, M.: chrF: character n-gram F-score for automatic MT evaluation. In Proceedings of the Tenth Workshop on Statistical Machine Translation, pages 392\u2013395, Lisbon, Portugal, September 2015. Association for Computational Linguistics","DOI":"10.18653\/v1\/W15-3049"},{"key":"1094_CR102","doi-asserted-by":"crossref","unstructured":"Burleson, W., Clark, S.S., Ransford, B., Fu, K.: Design challenges for secure implantable medical devices. In Proceedings of the 49th annual design automation conference, pages 12\u201317, (2012)","DOI":"10.1145\/2228360.2228364"},{"key":"1094_CR103","doi-asserted-by":"crossref","unstructured":"Daniel Halperin, Thomas\u00a0S Heydt-Benjamin, Benjamin Ransford, Shane\u00a0S Clark, Benessa Defend, Will Morgan, Kevin Fu, Tadayoshi Kohno, and William\u00a0H Maisel. Pacemakers and implantable cardiac defibrillators: Software radio attacks and zero-power defenses. In 2008 IEEE Symposium on Security and Privacy (sp 2008), pages 129\u2013142. IEEE, 2008","DOI":"10.1109\/SP.2008.31"},{"key":"1094_CR104","doi-asserted-by":"crossref","unstructured":"Chunxiao Li, Anand Raghunathan, and Niraj\u00a0K Jha. Hijacking an insulin pump: Security attacks and defenses for a diabetes therapy system. In e-Health Networking Applications and Services (Healthcom), pages 150\u2013156. IEEE, 2011","DOI":"10.1109\/HEALTH.2011.6026732"},{"key":"1094_CR105","doi-asserted-by":"crossref","unstructured":"Denis\u00a0Foo Kune, John Backes, Shane\u00a0S Clark, Daniel Kramer, Matthew Reynolds, Kevin Fu, Yongdae Kim, and Wenyuan Xu. Ghost talk: Mitigating emi signal injection attacks against analog sensors. In 2013 IEEE Symposium on Security and Privacy, pages 145\u2013159. IEEE, 2013","DOI":"10.1109\/SP.2013.20"},{"key":"1094_CR106","doi-asserted-by":"crossref","unstructured":"Meng Zhang, Anand Raghunathan, and Niraj\u00a0K Jha. Towards trustworthy medical devices and body area networks. In Proceedings of the 50th Annual Design Automation Conference, pages 1\u20136, 2013","DOI":"10.1145\/2463209.2488751"},{"key":"1094_CR107","doi-asserted-by":"crossref","unstructured":"AKM Newaz, Amit\u00a0Kumar Sikder, Mohammad\u00a0Ashiqur Rahman, and A\u00a0Selcuk Uluagac. A survey on security and privacy issues in modern healthcare systems: Attacks and defenses. arXiv preprint arXiv:2005.07359, 2020","DOI":"10.1145\/3453176"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-01094-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-025-01094-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-01094-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T11:33:06Z","timestamp":1757071986000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-025-01094-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,17]]},"references-count":107,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,8]]}},"alternative-id":["1094"],"URL":"https:\/\/doi.org\/10.1007\/s10207-025-01094-0","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"type":"print","value":"1615-5262"},{"type":"electronic","value":"1615-5270"}],"subject":[],"published":{"date-parts":[[2025,7,17]]},"assertion":[{"value":"17 July 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}],"article-number":"180"}}