UIT INFORMATION SECURITY LABORATORY

Công bố khoa học

Tra cứu các công bố khoa học theo năm, loại công trình, tác giả và từ khóa.

Phạm vi thống kê: Năm 2026
46 công bố được hiển thị

Nhấp vào tiêu đề để xem nội dung chi tiết hoặc sử dụng DOI/PDF khi dữ liệu được cung cấp.

2026
Tạp chí Quốc tế SCIE Q1

Interpretable Detection and Threat Characterization of Malicious PowerShell Scripts via Multi-Level Representation Fusion and LLM Reasoning

Nghi Hoang Khoa, Bao Pham-Thai, Van-Hau Pham

Journal of Information Security and Applications Elsevier Ngày xuất bản: -
Ngày được chấp nhận: -

Malicious PowerShell scripts remain a practical challenge for enterprise security because attackers can combine obfuscation, fileless execution, and legitimate administrative utilities to evade detectors that rely on a single code representation. Existing approaches often model lexical, structural, or semantic information separately, which…

2026
Tạp chí Quốc tế SCIE Q1

ContractShield: Bridging Semantic-Structural Gaps via Hierarchical Cross-Modal Fusion for Multi-Label Vulnerability Detection in Obfuscated Smart Contracts

Minh-Dai Tran-Duong, Nguyen Hai Phong, Nguyen Chi Thanh, Doan Minh Trung, Tram Truong-Huu, Van-Hau Pham, Phan The Duy

Engineering Applications of Artificial Intelligence Elsevier Ngày xuất bản: -
Ngày được chấp nhận:

Smart contracts are increasingly targeted by adversaries employing obfuscation techniques such as bogus code injection and control-flow manipulation to evade vulnerability detection. Existing multimodal methods often process semantic, temporal, and structural features in isolation and fuse them using simple strategies such as…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

FedAug-CTI: A Federated Framework with LM-Based Cyber Threat Intelligence Generation for Hierarchical Tactic-Technique Mapping

Tran Duc Luong, Tran Vy Khang, Van-Hau Pham, Phan The Duy

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận:

Mapping unstructured Cyber Threat Intelligence (CTI) reports to MITRE ATT\&CK Tactics and Techniques is essential for threat understanding but remains largely manual due to severe class imbalance in technique labels and the inability of Security Operations Centers (SOCs) to share raw CTI…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

SSCFuzz: Combining LLM-Generated Transaction Sequences with Undirected Exploration for Smart Contract Fuzzing

Huynh Thai Thi, Phan The Duy

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận:

Smart contracts manage substantial financial value yet resist testing: valid inputs follow an application binary interface (ABI), exploitable bugs need multi-step stateful sequences, and each Ethereum Virtual Machine (EVM) execution is costly, so executions bind. We present SSCFuzz, which separates \emph{what to…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

VulnPrism: Explainable Multi-Agent Vulnerability Detection via Multi-View Security Analysis

Phan Thai Hung, Luu Hong Phuc, Nghi Hoang Khoa, Phan The Duy

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) - Ngày hội nghị:
Ngày được chấp nhận:

Large language models show promise for source-code vulnerability detection, but a reliable verdict also depends on data dependencies, execution paths, and protective conditions that may be reconstructed inconsistently from source text. We propose VulnPrism, an explainable multi-agent framework for function-level detection. A…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

Adversarial Robustness of Quantum Learning-based Intrusion Detection Systems in IoT Networks

Quach Tuan Kiet, Le Sy Liem, Le Tran Gia Bao, Nghi Hoang Khoa, Dang Van Huynh, Van-Hau Pham, Phan The Duy

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận:

Quantum machine learning (QML) has emerged as a promising paradigm for intrusion detection systems (IDS) in resource-constrained and highly dynamic IoT networks due to its superior data efficiency and ability to capture complex non-linear attack patterns. However, the adversarial robustness of QML-based…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

Understanding Large Language Model Performance in Vulnerability Detection: A Systematic Analysis

Trong-Nghia To, Mai Ngoc Phuong Trinh, Pham Do Thanh, Thieu Minh Vien, Van-Hau Pham, Phan The Duy

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận:

Large Language Models (LLMs) have emerged as powerful tools for software vulnerability detection, yet their decision-making processes remain opaque and highly sensitive to prompt design. This paper presents a systematic study on how different forms of auxiliary information - metadata-derived program semantics,…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

Evidence-Grounded Multi-Agent Coordination for Automated Digital Forensics: Hierarchical versus Peer-to-Peer Architectures

Khuong Ngoc Toan, Phan Quang Vu, Doan Minh Trung, Phan The Duy

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) - Ngày hội nghị:
Ngày được chấp nhận:

Digital forensic investigation requires the correlation of large volumes of heterogeneous host and network telemetry while preserving evidentiary consistency. Large Language Model (LLM) agents can assist this process, but their reliability is limited by context-window constraints, unsupported technical claims, and the lack…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

Small Language Models for Smart Contract Vulnerability Detection: A Fine-Grained Analysis on Capabilities, Localization, and Failure Modes

Doan Minh Trung, Hoang Cao Phong, Luc Vinh Kiet, Ho Minh Tri, Nguyen Nhat Dong, Phan The Duy, Tu-Anh Nguyen-Hoang, Van-Hau Pham

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận:

Smart contracts secure high-value blockchain applications, yet vulnerabilities continue to cause severe financial losses, making automated detection critical. While large language models (LLMs) show strong potential for code and security analysis, their cost, deployment constraints, and reliance on proprietary services limit practical…

2026
Hội nghị Quốc tế Scopus Indexed Rank B

From Prediction to Understanding: A Robustness and Explainability Study of LLM-Based Vulnerability Detection

Trong-Nghia To, Dinh Huu Nhien, Le Quoc Ngo, Hien Do Hoang, Van-Hau Pham

The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận:

Large Language Models (LLMs) for code are increasingly used for software vulnerability detection, yet security review requires more than a correct Vulnerable or Safe label. Analysts also need to know whether a decision remains reliable when code is rewritten and whether the…

2026
Hội nghị Quốc tế Scopus Indexed

OpenSetDGA: A Benchmark for Open-Set Domain Generation Algorithm Detection

Truong Nguyen Hoang Quan, Nguyen Ngoc Thanh, Phan The Duy

Future Data and Security Engineering (FDSE 2026) Springer Ngày hội nghị:
Ngày được chấp nhận:

Although Domain Generation Algorithm (DGA) detectors often achieve strong performance under closed-set evaluation, deployed systems must also handle previously unseen DGA families and heterogeneous domains that differ substantially from the training distribution. Existing evaluations, however, rarely study these two forms of novelty…

2026
Tạp chí Quốc tế SCIE Q1

DMLDroid: Deep Multimodal Fusion Framework for Android Malware Detection with Resilience to Code Obfuscation and Adversarial Perturbations

Doan Minh Trung, Tien Duc Anh Hao, Luong Hoang Minh, Nghi Hoang Khoa, Nguyen Tan Cam, Van-Hau Pham, Phan The Duy

Journal of Network and Computer Applications Elsevier Ngày xuất bản: -
Ngày được chấp nhận:

In recent years, Android malware detection has advanced rapidly with the adoption of learning-based techniques, which typically analyze app code as text, images, or graphs. Despite strong performance, these methods often struggle in real-world settings, especially when malware uses code obfuscation to…

2026
Tạp chí Quốc tế SCIE Q2

Evaluating the robustness and transferable adversarial example resistance of multimodal learning-based intrusion detection systems against evasion attacks

Phan The Duy, Cao The Thuan, Doan Ngoc Nhu Quynh, Truong Thi Hoang Hao, Doan Minh Trung, Nghi Hoang Khoa, Van-Hau Pham

Mobile Networks and Applications Springer Ngày xuất bản: -
Ngày được chấp nhận:

Intrusion Detection Systems (IDS) play a crucial role in safeguarding computer networks against malicious activities. However, current IDS models based on machine learning (ML) and deep learning (DL) encounter challenges in accurately classifying malicious network traffic, especially when confronted with adversarial perturbations…

2026
Tạp chí Quốc tế SCIE Q1

Navigating and orchestrating Web 3.0 innovation challenges: A theory of cross-chain ecosystem strategy

Tuan-Dung Tran, Phuong-Dai Bui, Van-Hau Pham

Journal of Engineering and Technology Management - Ngày xuất bản:
Ngày được chấp nhận: -

Web 3.0 technologies present fundamental challenges to established theories of platform strategy and organizational design, yet the organizational forms enabling decentralized innovation remain theoretically underexamined. This paper reconceptualizes cross-chain bridges, which enable value and message transfer across independent blockchain networks, not as…

2026
Hội nghị Quốc tế Scopus Indexed

PRECISE: Precision-Driven Discovery of Token-centric MEV

Dinh Khang Nguyen, Huynh Nhu Nguyen Thi, Bich Nhu Hong, Quang Trung Do, Tuan-Dung Tran, Van-Hau Pham

The 9th International Conference on Multimedia Analysis and Pattern Recognition (MAPR2026) - Ngày hội nghị:
Ngày được chấp nhận: -

-

2026
Hội nghị Quốc tế Scopus Indexed

An Empirical Study on the Transferability of Transformer-Based Models for Software Vulnerability Detection

Huu Nhien Dinh, Chau The Vi, Thai Hung Van, Trong-Nghia To, Phan The Duy

The 9th International Conference on Multimedia Analysis and Pattern Recognition (MAPR 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận: -

Despite the dominance of Transformer-based models in software vulnerability detection, the extent to which their learned security logic generalizes across different programming languages remains a critical open question. To address this, we propose a comprehensive evaluation framework organized into three phases spanning…

2026
Hội nghị Quốc tế Scopus Indexed

Graph-Driven LLM-Augmented Stateful API Fuzzing for OWASP API Top 10

Khanh-Khoa Ngo, Trieu Huynh Pham Long, Truong Nguyen Van, Thai Hung Van, Phan The Duy

The 9th International Conference on Multimedia Analysis and Pattern Recognition (MAPR 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận: -

Security testing of REST APIs remains difficult because real-world OpenAPI specifications are often incomplete, many security flaws are inherently stateful, and prevailing stateful fuzzers still optimize primarily for structural exploration rather than OWASP-aligned risk categories. Based on this gap, this paper presents…

2026
Hội nghị Quốc tế Scopus Indexed

A Class-incremental and Few-shot learning model for Intrusion detection under Concept drift

Cao Phan Xuan Qui, Le Quoc Ngo, Phan The Duy, Van-Hau Pham

The 9th International Conference on Multimedia Analysis and Pattern Recognition (MAPR 2026) IEEE Ngày hội nghị:
Ngày được chấp nhận: -

Network Intrusion Detection Systems (NIDS) based on machine learning must evolve after deployment to detect emerging threats very soon with a few labeled samples, while without catastrophic forgetting or degrading due to concept drift. Existing methods address these issues in isolation, lacking…

2026
Tạp chí Quốc tế SCIE Q1

MORPH-IDS: A Context-Driven Multi-Agent Reinforcement Learning Framework for Drift-Aware Moving Target Defense in Adversarial-Robust Intrusion Detection

Truong Duc Hao, Hong Huy Hoang, Le Hong Hien, Dang Van Huynh, Quan Le-Trung, Van-Hau Pham, Phan The Duy

Computer Networks Elsevier Ngày xuất bản: -
Ngày được chấp nhận: -

In the rapidly evolving cybersecurity landscape, Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) have become essential for detecting sophisticated threats, yet they are increasingly vulnerable to adversarial evasion attacks and concept drift caused by adaptive attackers. Existing ensemble-based defenses optimize for…

2026
Tạp chí Quốc tế SCIE Q1

XDFC-IDS: An Explainable Decentralized Federated Class-Incremental Fusion Framework for Intrusion Detection

Nguyen Huu Quyen, Van-Hau Pham, Phan The Duy

Expert Systems with Applications Elsevier Ngày xuất bản: -
Ngày được chấp nhận: -

With the widespread adoption of IoT and edge computing, federated learning (FL)-based intrusion detection systems (IDSs), which enable privacy-preserving, cost-effective training by fusing knowledge extracted from collaborators without centralizing the sensitive data, have become essential. Specifically, decentralized FL (DFL)-based IDSs are increasingly…

2026
Tạp chí Quốc tế SCIE Q1

Poisoning the Swarm: Evaluating Data-Level Vulnerabilities in Decentralized Internet of Medical Things-enabled Healthcare Networks

Ngo Duc Hoang Son, Vuong Dinh Thanh Ngan, Le Minh Nha, Tran Duc Luong, Van-Hau Pham, Phan The Duy

Computers and Electrical Engineering Elsevier Ngày xuất bản: -
Ngày được chấp nhận: -

Swarm Learning (SL) integrates federated learning and blockchain to support decentralized privacy-preserving learning for smart healthcare. However, the resilience of its learning and aggregation process against malicious data injection remains underexplored. This study presents a vulnerability analysis of SL against data-level poisoning,…

2026
Tạp chí Quốc tế Q1

Enhanced android malware classification using multi machine learning models and generative adversarial network

Nguyen Tan Cam, Nguyen Cong Danh, Nghi Hoang Khoa

Neural Computing and Applications Springer Ngày xuất bản:
Ngày được chấp nhận: -

Android malware is increasingly becoming a serious security threat to users as the popularity of mobile phones continues to rise. The application of machine learning models for classifying Android malware has been widely used in related studies. However, machine learning models can…

2026
Hội nghị Quốc tế Scopus Indexed

MAF-LLM: A Multi-Agent Framework Based on Large Language Models for Automated Ransomware Memory Forensics

Tran Anh Khoi, Nguyen Phan Huu Khanh, Huu-Han Nguyen, Doan Minh Trung and Phan The Duy

The 15th Conference on Information Technology and Its Applications (CITA 2026) Springer Ngày hội nghị:
Ngày được chấp nhận: -

MAF-LLM: A Multi-Agent Framework Based on Large Language Models for Automated Ransomware Memory Forensics

2026
Tạp chí Quốc tế SCIE Q1

P4P: A Probe-Guided Anti-Poisoning Defense for Federated Learning-based Intrusion Detection in IoT Networks under Non-IID Data

Thai Tuan Khang, Tran Huu Duc, Dang Van Huynh, Van-Hau Pham, Phan The Duy

Journal of Network and Computer Applications - Ngày xuất bản: -
Ngày được chấp nhận: -

Federated learning (FL) enables collaborative Intrusion Detection Systems (IDS) across distributed Internet of Things (IoT) networks without sharing raw data. However, its openness exposes it to model poisoning and backdoor attacks, where malicious clients manipulate updates to corrupt the global model. Detecting…

2026
Tạp chí Quốc tế SCIE Q1

AutoWAFuzzer: An Adaptive Framework for Web Application Firewall Penetration Testing with Multi-agent System and RAG-enabled Reinforcement Learning

Phan The Duy, Nguyen Ngoc Thanh, Pham Cong Lap, Van-Giau Ung, Khanh-Khoa Ngo, Tram Truong-Huu, Van-Hau Pham

Expert Systems with Applications Elsevier Ngày xuất bản: -
Ngày được chấp nhận: -

Web Application Firewalls (WAFs) are crucial in mitigating web-based threats such as SQLi and XSS, yet the evolving complexity of WAF detection mechanisms poses significant challenges for penetration testing (pentest) tools. Existing ML- and RL-based fuzzers often suffer from three main limitations:…

2026
Hội nghị Quốc tế Scopus Indexed

Checklist-Guided Reinforcement Learning for Adaptive SQL Injection Detection with Dynamic WAF Evasion

Khanh-Khoa Ngo, Kieu Phuong Dinh Bach, Uyen Do Thi Phuong, Hien Do Hoang, and Phan The Duy

The 2026 11th International Conference on Intelligent Information Technology (ICIIT 2026) ACM Ngày hội nghị:
Ngày được chấp nhận:

SQL Injection (SQLi) remains a critical threat to web applications despite defensive mechanisms like WAF. Traditional tools rely on fixed payloads, limiting adaptability against obfuscated attacks. This paper proposes a checklist-integrated reinforcement learning framework that dynamically optimizes sqlmap configuration based on real-time…

2026
Tạp chí Quốc tế SCIE Q1

A Multimodal Approach for Windows Malware Detection using Comprehensive Analysis on Called APIs

Do Thi Thu Hien, Bao Pham-Thai, Nguyen Tan Cam, Van-Hau Pham

Journal of Information Security and Applications Elsevier Ngày xuất bản:
Ngày được chấp nhận: -

With the continuous evolution of the Windows operating system, malware-especially those based on Portable Executable (PE) files-has become increasingly sophisticated. Recent studies have widely adopted artificial intelligence (AI), particularly deep learning (DL) models, for malware detection. Among these, approaches focusing on API…

2026
Tạp chí Quốc tế SCIE Q1

A study on functionality validation for windows malware mutating using reinforcement learning

Do Thi Thu Hien, Le Viet Tai Man, Le Trong Nhan, Phan Ngoc Yen Nhi, Hoang Thanh Lam, Nguyen Tan Cam, Van-Hau Pham

Information and Software Technology Elsevier Ngày xuất bản:
Ngày được chấp nhận: -

To keep pace with the rapid advancements in both the quality and complexity of malware, recent research has extensively employed machine learning (ML) and deep learning (DL) models to detect malicious software, particularly in the widely used Windows system. Despite demonstrating promising…

2026
Tạp chí Quốc tế SCIE Q1

xPriMES: Explainable Reinforcement Learning-guided Mutation Strategy with Dual-Environment Interaction for Evading Black-box Malware Detectors

Phan The Duy, Nguyen Manh Cuong, Ha Trieu Yen Vy, Le Tuan Luong, Nguyen Tran Duc Anh, Nghi Hoang Khoa, Van-Hau Pham

Information and Software Technology Elsevier Ngày xuất bản:
Ngày được chấp nhận: -

Malware continues to evolve, exposing weaknesses in conventional detectors and motivating realistic adversarial evaluations. Prior RL-based evasion methods often rely on partial model access or feature-level perturbations, limiting realism under strict black-box constraints. We propose xPriMES, a dual-environment reinforcement learning framework that…

2026
Tạp chí Quốc tế SCIE Q1

Android malware detection by using graph optimization of static features based on pre-trained language models

Nghi Hoang Khoa, Doan Minh Trung, Duong The Dat, Phan The Duy, Van-Hau Pham, Nguyen Tan Cam

Information and Software Technology Elsevier Ngày xuất bản:
Ngày được chấp nhận: -

The Android platform is the dominant mobile operating system, making it a prime target for malware attacks. The increasing complexity of Android malware necessitates advanced detection methods that integrate modern machine learning techniques with security analysis. This study aims to enhance Android…

2026
Tạp chí Quốc tế SCIE Q1

Hawkeyes: An Intelligent Honeypot Allocation Strategy for Cyber Deception using Reinforcement Learning

Hien Do Hoang, Trong-Nghia To, Ngo Duc Hoang Son, Khoa Ngo-Khanh, Nguyen Tan Cam, Van-Hau Pham

Computer Networks Elsevier Ngày xuất bản:
Ngày được chấp nhận: -

Honeypot allocation has emerged as a pivotal strategy in cyber deception. However, existing approaches often face scalability issues, limited coordination, and inadequate consideration of intrusion stages, which constrain their effectiveness in complex attack environments. To address these challenges, this study introduces Hawkeyes,…