
Mới
Học tập - Nghiên cứuSinh viên UIT nghiên cứu cải thiện mô phỏng hành vi mã độc bằng mô hình LLM và cơ chế xác minh kỹ thuật tấn công
Chúc mừng Nguyễn Ngọc Sáng và Nguyễn Minh Quân – sinh viên ngành An toàn thông tin – đã có bài báo khoa học được chấp nhận đăng tại Hội nghị Quốc tế IEEE lần thứ 32 về Hệ thống Song song và Phân tán – The 32nd IEEE International Conference on Parallel and Distributed Systems (ICPADS 2026), tổ chức tại Tokyo, Nhật Bản.Bài báo: “Improving TTP Alignment in LLM-Based Malware Artifact Generation via Hybrid Verification”Sinh viên thực hiện:- Nguyễn Ngọc Sáng - Lớp ATTT2023.2- Nguyễn Minh Quân - Lớp ATTT2023.2Giảng viên hướng dẫn: TS. Phan Thế DuyLời cảm ơn của nhóm sinh viên:"Chúng em xin gửi lời cảm ơn chân thành đến TS. Phan Thế Duy và cùng với các thầy cô của Phòng thí nghiệm An toàn thông tin (InSecLab) thuộc Khoa Mạng máy tính và Truyền thông đã tận tình hướng dẫn, góp ý và đồng hành cùng chúng em trong suốt quá trình thực hiện nghiên cứu. Những định hướng chuyên môn, các ý kiến phản biện và sự hỗ trợ của các thầy và các cô đã giúp chúng em hoàn thiện đề tài cũng như bài báo tốt hơn. Đây là một trải nghiệm rất quý báu và là động lực để chúng em tiếp tục phát triển trên con đường nghiên cứu khoa học."Tóm tắt bài báo:The rapid development of Large Language Models (LLMs) has opened up new possibilities for automating cybersecurity tasks, including threat analysis, code generation, and adversarial behavior simulation. However, in systems that use LLMs to generate artifacts for malware research, a key challenge is ensuring that the techniques selected during the planning stage are truly aligned with the cybersecurity behaviors intended to be simulated. This paper extends the MalGEN architecture, a multi-agent framework for modeling and generating malware artifacts in controlled research environments, by introducing a new component called the TTP-conditioned Hybrid Verifier. Positioned between the Planner and Developer stages, this component validates and refines the MITRE ATT&CK techniques selected by the Planner before the system proceeds to code generation. The complete framework consists of five components: Planner → Hybrid Verifier → Developer → Integrator → Builder.The verification mechanism combines Planner confidence, attack-stage compatibility, semantic similarity using SciBERT, dataset-supported evidence, and rule-based adjustments. The system is evaluated on 15 cybersecurity behavior scenarios using four configurations based on GPT-4o and DeepSeek-V4-Pro, with and without the Hybrid Verifier. A total of 60 outputs are used to assess the impact of verification on TTP selection prior to code generation. Experimental results show that the Hybrid Verifier improves the alignment between selected TTPs and the expected behaviors. Macro-F1 increases from 51.92% to 57.53% for GPT-4o and from 56.92% to 63.00% for DeepSeek-V4-Pro, mainly due to improved recall. In addition, the number of cases in which the selected TTPs match MITRE ATT&CK signals reported by VirusTotal also increases for both models. These findings indicate that Hybrid Verification improves the accuracy of TTP selection before code generation, providing stronger support for research on adversarial behavior simulation and defensive system evaluation.Thông tin về hội nghị:IEEE ICPADS 2026 – The 32nd IEEE International Conference on Parallel and Distributed Systems là kỳ thứ 32 của hội nghị quốc tế IEEE về các hệ thống song song và phân tán. Hội nghị năm 2026 sẽ diễn ra từ 22–26/11/2026 tại Tokyo, Nhật Bản, tại International Conference Center, Waseda University. Với chủ đề “Ubiquitous Computing for Global Communities”, ICPADS 2026 được giới thiệu là một flagship conference của IEEE Computer Society, tập trung vào các hướng nghiên cứu như AI Infrastructure and Systems, Edge Intelligence, AIoT, Web3 Security and Privacy, Agentic Systems and Networks và Intelligent Computing.Đặc biệt, ICPADS được xếp hạng B theo hệ thống xếp hạng hội nghị quốc tế ICORE/CORE 2026, thuộc lĩnh vực Distributed Computing and Systems Software. Các bài báo nghiên cứu tại ICPADS 2026 được phản biện theo hình thức single-blind peer review và sử dụng định dạng IEEE Computer Society Proceedings. Theo thông tin chính thức của hội nghị, các bài được chấp nhận sẽ được submitted to IEEE Xplore và EI, đồng thời các công trình chất lượng cao có cơ hội được đề cử vào các số đặc biệt của các tạp chí liên kết. Hội nghị được hỗ trợ bởi IEEE, IEEE Computer Society, IEEE Computer Society Technical Committee on Parallel Processing (TCPP) và Technical Community on Distributed Processing (TCDP).Thông tin chi tiết tại: https://www.facebook.com/share/p/19VRTZMm9e/ Đông Xanh - Cộng tác viên truyền thông Trường Đại học Công nghệ Thông tin
25/09/2026