Skip to content

Author

Van-Hau Pham

We have 4 of 67 papers

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Conference Aug 2026

PRECISE: Precision-Driven Discovery of Token-centric MEV

Token-centric maximal extractable value (tMEV) arises when token supply-control behavior interacts with exchanges whose pricing ignores particular balance updates. Existing analyses face state explosion, missing deep inter-transaction paths or producing false positives. PRECISE combines token-level static filtering, fork-based dynamic fuzzing, and state-difference verification. Inter-procedural system dependence graphs (SDGs) identify candidate paths from source or bytecode; utility-guided fuzzing validates them on a pinned Anvil mainnet fork against authorization-, event-, and profitability-aware Type-1/Type-2 predicates. This division limits dynamic search to supply-sensitive control flow while retaining execution-grounded validation. Profitability follows a constant-product automated market maker (AMM) slippage model. PRECISE scans 22,279 token contracts and 7,030 pools; on the 499-contract standard scored set it reaches 72.45% precision, 84.58% recall, and 78.04% F1 against Nyx, FORAY, DeFiTainter, and SmartCAT. Recall rises to 91.2% on a 150-contract Complex-Tokens stress set. The artifact pins replay contexts and reproduces the scan for an estimated compute cost of $25.84 at the reported instance-hour rate.

Dinh-Khang Nguyen, Huynh-Nhu Nguyen Thi, Bich-Nhu Hong et al. · 0 citations
Conference Aug 2026

Explainable Malware Detection from Noisy API Sequences with RAG-Based MITRE ATT&CK Mapping

As sophisticated evasion techniques like polymorphism and staged execution increasingly neutralize conventional signature-based defenses, dynamic API sequence analysis has emerged as an effective approach for malware detection. However, extracting actionable intelligence from noisy execution logs while maintaining model interpretability remains a challenge. To address this, we propose a multi-layered framework that connects raw behavioral signals with standardized threat intelligence. The architecture utilizes a Log2 noise filtering mechanism to distill execution traces into API segments, which are then mapped into semantic representation spaces using CodeBERT. By leveraging HDBSCAN for density-based clustering alongside PrefixSpan, the system extracts sequential patterns representing core malicious activities. For classification, a soft-voting Ensemble model (Random Forest and XGBoost) is employed, achieving an accuracy of 99.40%, with feature-level interpretability provided by SHAP values. Furthermore, we integrate a Retrieval-Augmented Generation (RAG)-based LLM agent to interpret technical signals and assist in mapping behaviors to the MITRE ATT&CK framework. Experimental results on Windows malware datasets demonstrate that the proposed framework can effectively identify obfuscated threats and automatically generate structured digital forensics reports to support Incident Response and DFIR workflows.

Dat Quoc Phan, Tien Duc Anh Hao, Nghi Hoang Khoa et al. · 0 citations
Conference Jul 2026

Active Digital Twin Verification for Robust Federated Learning in IoT Intrusion Detection

Federated Learning has become a practical approach for training intrusion detection models across distributed Internet of Things devices, but it remains exposed to poisoning attacks, non-IID data heterogeneity, and free-rider exploitation. This paper presents DT-Guard, a defense framework that leverages a server-side Digital Twin as a controlled testing environment for actively verifying client model behavior. Each submitted update is deployed in the Digital Twin and evaluated on synthetic challenge data through a four-layer pipeline that examines detection capability, backdoor resistance, parameter deviation, and cross-round stability. A complementary aggregation scheme called DT-Driven Performance Weighting compares client predictions against the current global model, exposing free-riders whose outputs are nearly indistinguishable from the global baseline. We validate DT-Guard on CIC-IoT-2023 under five poisoning strategies. DT-Guard generally outperforms nine existing defenses in accuracy, false positive rate, and contribution fairness.

H. Pham, Duy The Phan, Van-Hau Pham · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.