LLM-Enabled IAM Risk Mapping

May 27, 2026·
Sanaa Mironov
Sanaa Mironov
· 1 min read
projects

This research project examines how LLM-enabled identity and access management tools introduce new risk patterns across common IAM workflows.

The project uses the OWASP Top 10 for LLM Applications and NIST Cybersecurity Framework 2.0 as organizing lenses for analyzing use cases such as account recovery, MFA reset, access request triage, provisioning, deprovisioning, policy Q&A, and privileged-access handling.

The repository includes manuscript materials, experiment artifacts, local-model testing notes, and reproducibility instructions.

Key themes:

  • Workflow-centered AI risk assessment
  • Mapping LLM threat taxonomies to governance frameworks
  • Local model testing with open-weight LLMs
  • Reproducibility materials for research review

Next site pass: add the final abstract, paper status, and selected figures.

Sanaa Mironov
Authors
Assistant Teaching Professor of Computer Science
I make operating systems and AI make sense. I teach systems at UMBC, explain OS concepts on YouTube, and study how to make AI and software systems secure and trustworthy.