VLDB 2026 Research / reviewers in the wild / expert
Phu Hong Nguyen
dblp:129/9792
· DBLP profile ↗
23ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0003-1773-8581ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 5 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unsupervised Learning and Process Analysis for Sensor Data Validation in the IIoTabstractIntegrating Artificial Intelligence (AI) with the Industrial Internet of Things (IIoT) has transformed industrial processes, enhancing productivity, quality control, and operational efficiency. However, ensuring the precision and reliability of sensor-generated data remains a critical challenge due to the evolving nature of industrial processes and the limitations of conventional validation methods. Traditional rule-based and supervised learning approaches struggle to adapt to process shifts, drifts, and novel anomalies, making sensor data validation an ongoing issue. This article introduces UDAVA (Unsupervised Learning Approach using Process Mining for Sensor Data Validation in IIoT), a novel AI-driven pipeline designed to automate the identification of reference patterns in sensor data and validate subsequent production cycles by recognizing deviations from expected behaviors. UDAVA employs a multi-stage process that includes preprocessing sensor data, clustering recurring patterns, and assessing deviations. It supports semi-supervised learning by integrating manual labels where available, improving interpretability and accuracy. One of UDAVA’s key strengths lies in its ability to extract features from sensor data rather than relying on raw time series similarity, making it robust against noise and diverse process variations. Additionally, UDAVA integrates process mining techniques—process discovery and conformance checking—to enhance its ability to detect even subtle anomalies and deviations in industrial workflows. We conduct a comprehensive evaluation of UDAVA using three industrial datasets, demonstrating its effectiveness in identifying high-level process behaviors, detecting process shifts and drifts, and ensuring data validation across multiple production cycles. The results highlight UDAVA ’s adaptability across different industrial processes, making it a valuable tool for optimizing operations and ensuring sensor data reliability in IIoT environments. Erik Johannes Husom, Arda Goknil, Felix Mannhardt, Simeon Tverdal, Sagar Sen, Phu Hong Nguyen |
ACM Trans. Internet Techn. | 6 |
| 2025 | Combining Insights from Multiple Tools to Manage Technical Debt in Industrial C# ProjectsabstractTechnical Debt (TD) is a critical challenge in software development, leading to increased maintenance costs and reduced software quality over time. While considerable research has focused on identifying and managing TD in Java projects, studies on. NET (C#) projects remain limited. Additionally, existing approaches often rely on a single tool for TD detection, overlooking the benefits of combining multiple tools. In this paper, we analyze the effectiveness of Arcan, CodeScene, Designite, and DV8 on four industrial C#. NET 8 software products to address these research gaps. To validate and enrich our findings, we conducted online seminars and interviews with developers, architects, and managers involved in these projects, gathering practitioner insights on TD relevance and tool effectiveness. By leveraging complementary tools and practitioner feedback, we uncover different types of TD, including code-level, design, architectural, and knowledge debt. Our findings highlight each tool's strengths and limitations and demonstrate how integrating their outputs with expert input provides a more comprehensive and actionable TD assessment. Based on these insights, we propose a conceptual model for prioritizing and managing TD, offering guidance for practitioners. Simeon Tverdal, Phu Hong Nguyen, Arda Goknil, Antonio Martini 0001, Merve Astekin, Mili Orucevic, Maren Maritsdatter Kruke, Håvard Stranden |
ICSME | 2 |
| 2025 | Detecting Technical Debt in Source Code Changes Using Large Language Models
Merve Astekin, Arda Goknil, Sagar Sen, Simeon Tverdal, Phu Hong Nguyen |
PROFES | 5 |
| 2025 | Advanced Context-Sensitive Access Management for Edge-Driven IoT Data Sharing as a ServiceabstractThe Internet of Things (IoT) is becoming increasingly ubiquitous, acting as an important source of real-time data for various applications. By allowing data exchange between various parties along the IoT devices-Edge-Cloud computing continuum, the larger societal benefits of the IoT can be achieved. Assuring security and fostering confidence for IoT data sharing, however, is one of the biggest obstacles. Sharing real-time data originating from connected devices is crucial to real-world intelligent IoT applications, i.e., based on artificial intelligence/machine learning. Such IoT data sharing involves multiple parties for different purposes and is usually based on data contracts that might depend on the dynamic change of IoT data variety and velocity. We aim to support multiple parties (aka tenants) with dynamic contracts based on the data value for their specific contextual purposes. This work addresses these challenges by introducing a novel dynamic context-based policy enforcement framework to support IoT data sharing (on-Edge) based on dynamic contracts. Our enforcement framework allows IoT Data Hub owners to define extensible rules and metrics to govern the tenants accessing the shared data on the Edge based on policies defined with static and dynamic contexts. We have created an edge-centered architecture that enables multi-tenant use cases with tenant-specific application deployment and IoT-context-based data sharing on edge servers. Our proof-of-concept prototype for sharing sensitive data such as surveillance camera videos has illustrated our proposed framework. The experimental results demonstrated that our framework could soundly and timely enforce context-based policies at runtime with moderate overhead. Moreover, the context and policy changes are correctly reflected in the system in nearly real-time. We have addressed the need to enable multi-parties IoT (data) resources to be shared based on contracts, especially with dynamic IoT contexts, for tenant applications on the edge to allow their closer access to data. Phu Hong Nguyen, Huu-Ha Nguyen, Phu H. Phung, Hong Linh Truong 0001, Thomas Cheung |
ACM Trans. Internet Techn. | 1 |
| 2024 | Security Orchestration with Explainability for Digital Twins-Based Smart SystemsabstractThe Digital Twin (DT) paradigm has been largely adopted for many smart systems in various domains. Due to the heterogeneous and distributed nature of the physical twins, these systems increasingly incorporate disparate security tools, especially those based on service-based AI/ML capabilities. That presents numerous challenges in achieving a comprehensive understanding of security analytics and explainability in security operations carried out by ML-based security services, which require continuous monitoring and optimization to remain effective. This paper aims to support security service integration and automated analyses with enhanced explainability in DTs. We introduce a novel framework that unifies runtime contexts to facilitate security services unification and operation interpretation in security orchestration. We define a workflow and provide necessary services for generating security reports across physical and logical layers. Leveraging a centralized knowledge service, we let security analysts incorporate domain knowledge in automating incident reasoning and security enforcement at the logical layer. We demonstrate our explainability framework on a DT of an Industry 4.0 toy factory with two ML-based security services detecting network anomalies. Our experiments show a significant reduction in manual effort for orchestrating security incident analysis and mitigation. Minh-Tri Nguyen, An Ngoc Lam, Phu Hong Nguyen, Hong Linh Truong 0001 |
COMPSAC | 3 |
| 2023 | The DYNABIC approach to resilience of critical infrastructuresabstractWith increasing interdependencies and evolving threats, maintaining operational continuity in critical systems has become a significant challenge. This paper presents the DYNABIC (Dynamic business continuity of critical infrastructures on top of adaptive multi-level cybersecurity) approach as a comprehensive framework to enhance the resilience of critical infrastructures. The DYNABIC approach provides the resilience enhancement through dynamic adaptation, automated response, collaboration, risk assessment, and continuous improvement. By fostering a proactive and collaborative approach to resilience, the DYNABIC framework empowers critical infrastructure sectors to effectively mitigate disruptions and recover from incidents. The paper explores the key components and architecture of the DYNABIC approach and highlights its potential to strengthen the resilience of critical infrastructures using the concept of Digital Twins in the face of evolving threats and complex operating environments involving cascading effects. Erkuden Rios, Eider Iturbe, Angel Rego, Nicolas Ferry 0001, Jean-Yves Tigli, Stéphane Lavirotte, Gérald Rocher, Phu Hong Nguyen, Rustem Dautov, Wissam Mallouli, Ana R. Cavalli |
ARES | 8 |
| 2023 | Towards Smarter Security Orchestration and Automatic Response for CPS and IoTabstractCurrent security orchestration and response (SOAR) approaches have primarily focused on specific layers of systems, such as Intrusion Detection Systems, the network layer, or the application layer. We aim to find the gaps in the existing SOAR approaches for IoT/CPS-based systems, especially critical infrastructures, and propose some directions to fill in these gaps. This paper presents a literature survey and future research directions for advancing SOAR towards increased automation and more holistic operation, especially for the cyber-physical security of critical infrastructures. We have found 14 primary SOAR studies and discussed the gaps in general. There is a significant gap when it comes to a comprehensive and systematic approach to SOAR for multi-layered systems using IoT/CPS and considering the computing continuum perspective. To address the gap, we present our on-going work on a framework of multi-layer SOAR decision-making methods and orchestration tools that leverage Reinforcement Learning (RL)-based adaptation intelligence, virtual reality, avatar-human interaction and advanced Cyber Threat Intelligence (CTI) tools. Phu Hong Nguyen, Rustem Dautov, Angel Rego, Eider Iturbe, Erkuden Rios, Diego Sagasti, Gonzalo Nicolas, Valeria Valdés Ríos, Wissam Mallouli, Ana R. Cavalli, Nicolas Ferry 0001 |
CloudCom | 1 |
| 2023 | Migrating monoliths to cloud-native microservices for customizable SaaSabstractIt was common that software vendors sell licenses to their clients to use software products, such as Enterprise Resource Planning, which are deployed as a monolithic entity on clients’ premises. Moreover, many clients, especially big organizations, often require software products to be customized for their specific needs before deployment on premises. However, as software vendors are migrating their monolithic software products to Cloud-native Software-as-a-Service (SaaS), they face two big challenges that this paper aims at addressing: (1) How to migrate their exclusive monoliths to multi-tenant Cloud-native SaaS; and (2) How to enable tenant-specific customizations for multi-tenant Cloud-native SaaS. This paper suggests an approach for migrating monoliths to microservice-based Cloud-native SaaS, providing customers with a flexible customization opportunity, while taking advantage of the economies of scale that the Cloud and multi-tenancy provide. We develop two proofs-of-concept to demonstrate our approach on migrating a reference application of Microsoft called SportStore to a customizable SaaS as well as customizing another Microsoft’s microservices reference application called eShopOnContainers. We have shown not only the migration to microservices but also how to introduce the necessary infrastructure to support the new services and enable tenant-specific customization. Our customization-driven migration approach can guide a monolith to become SaaS having (synchronous and asynchronous) customization power for multi-tenant SaaS. Furthermore, our event-based customization approach can reduce the number of API calls to the main product while enabling different tenant-specific customization services for real-world scenarios. Espen Tønnessen Nordli, Sindre Grønstøl Haugeland, Phu Hong Nguyen, Franck Chauvel |
Inf. Softw. Technol. | 3 |
| 2022 | A decade of research on patterns and architectures for IoT securityabstractAbstract Security of the Internet of Things (IoT)-based Smart Systems involving sensors, actuators and distributed control loop is of paramount importance but very difficult to address. Security patterns consist of domain-independent time-proven security knowledge and expertise. How are they useful for developing secure IoT-based smart systems? Are there architectures that support IoT security? We aim to systematically review the research work published on patterns and architectures for IoT security (and privacy). Then, we want to provide an analysis on that research landscape to answer our research questions. We follow the well-known guidelines for conducting systematic literature reviews. From thousands of candidate papers initially found in our search process, we have systematically distinguished and analyzed thirty-six (36) papers that have been peer-reviewed and published around patterns and architectures for IoT security and privacy in the last decade (January 2010–December 2020). Our analysis shows that there is a rise in the number of publications tending to patterns and architectures for IoT security in the last three years. We have not seen any approach of applying systematically architectures and patterns together that can address security (and privacy) concerns not only at the architectural level, but also at the network or IoT devices level. We also explored how the research contributions in the primary studies handle the different issues from the OWASP Internet of Things (IoT) top ten vulnerabilities list. Finally, we discuss the current gaps in this research area and how to fill in the gaps for promoting the utilization of patterns for IoT security and privacy by design. Tanusan Rajmohan, Phu Hong Nguyen, Nicolas Ferry 0001 |
Cybersecur. | 2 |
| 2021 | A Systematic Mapping Study on Approaches for Al-Supported Security Risk AssessmentabstractEffective assessment of cyber risks in the increasingly dynamic threat landscape must be supported by artificial intelligence techniques due to their ability to dynamically scale and adapt. This article provides the state of the art of AI-supported security risk assessment approaches in terms of a systematic mapping study. The overall goal is to obtain an overview of security risk assessment approaches that use AI techniques to identify, estimate, and/or evaluate cyber risks. We carried out the systematic mapping study following standard processes and identified in total 33 relevant primary studies that we included in our mapping study. The results of our study show that on average, the number of papers about AI-supported security risk assessment has been increasing since 2010 with the growth rate of 133% between 2010 and 2020. The risk assessment approaches reported have mainly been used to assess cyber risks related to intrusion detection, malware detection, and industrial systems. The approaches focus mostly on identifying and/or estimating security risks, and primarily make use of Bayesian networks and neural networks as supporting AI methods/techniques. Gencer Erdogan, Enrique Garcia-Ceja, Åsmund Hugo, Phu Hong Nguyen, Sagar Sen |
COMPSAC | 4 |
| 2021 | Migrating Monoliths to Microservices-based Customizable Multi-tenant Cloud-native AppsabstractIt was common that software vendors sell licenses to their clients to use software products, such as Enterprise Resource Planning, which are deployed as a monolithic entity on clients’ premises. Moreover, many clients, especially big organizations, often require software products to be customized for their specific needs before deployment on premises. While software vendors are trying to migrate their monolithic software products to Cloud-native Software-as-a-Service (SaaS), they face two big challenges that this paper aims at addressing: 1) How to migrate their exclusive monoliths to multi-tenant Cloud-native SaaS; and 2) How to enable tenant-specific customization for multi-tenant Cloud-native SaaS. This paper suggests an approach for migrating monoliths to microservice-based Cloud-native SaaS, providing customers with a flexible customization opportunity, while taking advantage of the economies of scale that the Cloud and multi-tenancy provide. Our approach shows not only the migration to microservices but also how to introduce the necessary infrastructure to support the new services and enable tenant-specific customization. We illustrate the application of our approach on migrating a reference application of Microsoft called SportStore. Sindre Grønstøl Haugeland, Phu Hong Nguyen, Franck Chauvel |
SEAA | 2 |
| 2020 | Event-Based Customization of Multi-tenant SaaS Using Microservices
Espen Tønnessen Nordli, Phu Hong Nguyen, Franck Chauvel |
COORDINATION | 2 |
| 2020 | Research Landscape of Patterns and Architectures for IoT Security: A Systematic ReviewabstractWe have entered a tremendous computerized rev-olution of the Internet of Things (IoT) era when everything is connected. The popularity of IoT systems makes security for the IoT of paramount importance. Security patterns consist of domain-independent time-proven security knowledge and expertise. Would they be applicable to develop secure IoT systems? We aim to draw a research landscape of patterns and architectures for IoT security by conducting a systematic literature review. From more than a thousand of candidate papers, we have systematically distinguished and analyzed twenty-two (22) papers that have been published around patterns and architectures for IoT security (and privacy). Our analysis shows a rise in the number of publications tending to security patterns and architectures in the last two years. Within this rise, we see that most patterns and architectures are applicable for all IoT systems, while some are limited within specific domains. However, there are gaps in this research area that can be filled in to promote the utilization of patterns for IoT security and privacy. Tanusan Rajmohan, Phu Hong Nguyen, Nicolas Ferry 0001 |
SEAA | 2 |
| 2020 | A Systematic Mapping of Patterns and Architectures for IoT Security
Tanusan Rajmohan, Phu Hong Nguyen, Nicolas Ferry 0001 |
IoTBDS | 2 |
| 2020 | Towards a Simulation Framework for Edge-to-Cloud Orchestration in C-ITSabstractCooperative Intelligent Transport Systems (C-ITS) are essential for smart cities. To realise the vision of C-ITS in the European Strategy to implement smart mobility towards Cooperative, Connected and Automated Mobility (CCAM), there must be advanced infrastructures for message exchange between connected and autonomous vehicles (CAVs), road-side units (RSUs), and transport management centres. One of the most challenges to build such infrastructures is to ensure the scalability to support for millions of vehicles on roads at the same time. In this short paper, we aim to discuss the challenge of ensuring the scalability of a C-ITS platform and describe our simulation framework to test its scalability. First, we give a high-level description of a C-ITS platform that is based on Edge-Cloud orchestration for message exchange between CAVs, RSUs, and transportation data centres. Then, we present our simulation framework that is based on Eclipse SUMO and Veins to test the scalability of the C-ITS platform. We have initially worked in two main tasks for the simulation framework: build simulation scenarios and integrate MQTT clients into the simulation tools to test our C-ITS platform. These are two fundamental steps towards a full simulation framework for our C-ITS platform. Phu Hong Nguyen, Åsmund Hugo, Karl Svantorp, Bjørn Magne Elnes |
MDM | 1 |
| 2019 | GeneSIS: Continuous Orchestration and Deployment of Smart IoT SystemsabstractMultiple tools have emerged to support the development as well as the continuous deployment of cloud-based software systems. However, currently, there is a lack of proper tool support for the continuous orchestration and deployment of software systems spanning across the IoT, edge, and cloud space. In particular, there is a lack of languages and abstractions that can support the orchestration and deployment of software services across vastly heterogeneous IoT infrastructures. In this paper, we present a tool supported framework for the continuous orchestration and deployment of IoT systems, named GeneSIS. In particular, GeneSIS enables to cope with the heterogeneity at each of the IoT, edge, and cloud levels and allows to control the orchestration and continuous deployment of software systems that executes across IoT, edge, and cloud infrastructures. Nicolas Ferry 0001, Phu Hong Nguyen, Pierre-Emmanuel Novac, Stéphane Lavirotte, Jean-Yves Tigli, Arnor Solberg |
COMPSAC (1) | 2 |
| 2019 | Customizing Multi-Tenant SaaS by Microservices: A Reference ArchitectureabstractEnterprise applications are migrating to cloud as mutli-tenant SaaS. To empower businesses with highly customizable SaaS, software vendors need a novel approach for customizing SaaS in mutli-tenant context that still benefits from moving to cloud. In this initial industrial experience report, we present our design and experimental findings towards a novel and cloud-native architecture of customizing multi-tenant SaaS by microservices. The report clarifies the key concepts related to the problem of multi-tenant customization, nd describes a design with a reference architecture and high-level principles. An experimental use case to customize an open source web-based shopping application demonstrates that a microservice-based approach is feasible to meet the general customization requirements, and achieves a balance between isolation, assimilation and economy of scale. Phu Hong Nguyen, Franck Chauvel, Jens M. Glattetre, Thomas Schjerpen |
ICWS | 2 |
| 2019 | A Systematic Mapping Study of Deployment and Orchestration Approaches for IoTabstractInternational audience Phu Hong Nguyen, Nicolas Ferry 0001, Gencer Erdogan, Stéphane Lavirotte, Jean-Yves Tigli, Arnor Solberg |
IoTBDS | 1 |
| 2019 | Using microservices for non-intrusive customization of multi-tenant SaaSabstractEnterprise software vendors often need to support their customer companies to customize the enterprise software products deployed on-premises of customers. But when software vendors are migrating their products to cloud-based Software-as-a-Service (SaaS), deep customization that used to be done on-premises is not applicable to the cloud-based multi-tenant context in which all tenants share the same SaaS. Enabling tenant-specific customization in cloud-based multi-tenant SaaS requires a novel approach. This paper proposes a Microservices-based non-intrusive Customization framework for multi-tenant Cloud-based SaaS, called MiSC-Cloud. Non-intrusive deep customization means that the microservices for customization of each tenant are isolated from the main software product and other microservices for customization of other tenants. MiSC-Cloud makes deep customization possible via authorized API calls through API gateways to the APIs of the customization microservices and the APIs of the main software product. We have implemented a proof-of-concept of our approach to enable non-intrusive deep customization of an open-source cloud native reference application of Microsoft called eShopOnContainers. Based on this work, we provide some lessons learned and directions for future work. Phu Hong Nguyen, Franck Chauvel, Roy Müller, Seref Boyar, Erik Levin |
ESEC/SIGSOFT FSE | 1 |
| 2017 | Model-based security engineering for cyber-physical systems: A systematic mapping study
Phu Hong Nguyen, Shaukat Ali 0001, Tao Yue 0002 |
Inf. Softw. Technol. | 1 |
| 2015 | SoSPa: A system of Security design Patterns for systematically engineering secure systemsabstractModel-Driven Security (MDS) for secure systems development still has limitations to be more applicable in practice. A recent systematic review of MDS shows that current MDS approaches have not dealt with multiple security concerns systematically. Besides, catalogs of security patterns which can address multiple security concerns have not been applied efficiently. This paper presents an MDS approach based on a unified System of Security design Patterns (SoSPa). In SoSPa, security design patterns are collected, specified as reusable aspect models to form a coherent system of them that guides developers in systematically addressing multiple security concerns. SoSPa consists of not only interrelated security design patterns but also a refinement process towards their application. We applied SoSPa to design the security of crisis management systems. The result shows that multiple security concerns in the case study have been addressed by systematically integrating different security solutions. Phu Hong Nguyen, Koen Yskout, Thomas Heyman, Jacques Klein, Riccardo Scandariato, Yves Le Traon |
MoDELS | 1 |
| 2015 | An extensive systematic review on the Model-Driven Development of secure systems
Phu Hong Nguyen, Max E. Kramer, Jacques Klein, Yves Le Traon |
Inf. Softw. Technol. | 1 |
| 2013 | A Systematic Review of Model-Driven SecurityabstractTo face continuously growing security threats and requirements, sound methodologies for constructing secure systems are required. In this context, Model-Driven Security (MDS) has emerged since more than a decade ago as a specialized Model-Driven Engineering approach for supporting the development of secure systems. MDS aims at improving the productivity of the development process and quality of the resulting secure systems, with models as the main artifact. This paper presents how we systematically examined existing published work in MDS and its results. The systematic review process, which is based on a formally designed review protocol, allowed us to identify, classify, and evaluate different MDS approaches. To be more specific, from thousands of relevant papers found, a final set of the most relevant MDS publications has been identified, strictly selected, and reviewed. We present a taxonomy for MDS, which is used to synthesize data in order to classify and evaluate the selected MDS approaches. The results draw a wide picture of existing MDS research showing the current status of the key aspects in MDS as well as the identified most relevant MDS approaches. We discuss the main limitations of the existing MDS approaches and suggest some potential research directions based on these insights. Phu Hong Nguyen, Jacques Klein, Yves Le Traon, Max E. Kramer |
APSEC (1) | 1 |