Hieu Dinh Vo

dblp:17/1569 · DBLP profile ↗
← Back
23ranked-venue papers
2as first author
21since 2021 · last 2026
0000-0002-9407-1971ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 19 · 2 first-author · 17 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Safety-critical scenario generation for automated testing of autonomous driving systems
Trung-Hieu Nguyen, Truong-Giang Vuong, Hong-Nam Duong, Hieu Dinh Vo, Toshiaki Aoki, Thu-Trang Nguyen
Autom. Softw. Eng.5
2026 A program-centered approach to solving AI tasks with ready-to-use models
Tung-Thuy Pham, Minh-Quan Duong, Duy-Quan Luong, Trung-Hieu Nguyen, Thu-Trang Nguyen, Hieu Dinh Vo
Future Gener. Comput. Syst.7
2026 Model-agnostic quality assessment for LLM-generated code via dynamic internal representation selection
Thanh Trong Vu, Tuan-Dung Bui, Thu-Trang Nguyen, Hieu Dinh Vo
J. Syst. Softw.5
2026 Structured exploration and exploitation of label functions for automated data annotation
Phong Lam, Ha-Linh Nguyen, Thu-Trang Nguyen, Hieu Dinh Vo
Knowl. Based Syst.5
2025 Leveraging local and global relationships for corrupted label detection
Phong Lam, Ha-Linh Nguyen, Xuan-Truc Dao Dang, Van-Son Tran, Minh-Duc Le, Thu-Trang Nguyen, Hieu Dinh Vo
Future Gener. Comput. Syst.8
2025 Layered microservices architecture: A multitree-based domain-driven approach
Duc Minh Le, Duc-Hanh Dang, Hieu Dinh Vo
Inf. Softw. Technol.3
2025 An empirical study on capability of Large Language Models in understanding code semantics
Thu-Trang Nguyen, Thanh Trong Vu, Hieu Dinh Vo
Inf. Softw. Technol.3
2025 Automated description generation for software patches
Thanh Trong Vu, Tuan-Dung Bui, Thanh-Dat Do, Thu-Trang Nguyen, Hieu Dinh Vo
Inf. Softw. Technol.5
2025 Correctness assessment of code generated by Large Language Models using internal representations
Tuan-Dung Bui, Thanh Trong Vu, Thu-Trang Nguyen, Hieu Dinh Vo
J. Syst. Softw.5
2025 Automated program repair for variability bugs in software product line systems
Thu-Trang Nguyen, Xiao-Yi Zhang 0005, Paolo Arcaini, Fuyuki Ishikawa, Hieu Dinh Vo
J. Syst. Softw.5
2024 Context-Encoded Code Change Representation for Automated Commit Message Generation
abstract
Changes in source code are an inevitable part of software development. They are the results of indispensable activities such as fixing bugs or improving functionality. Descriptions for code changes (commit messages) help people better understand the changes. However, due to the lack of motivation and time pressure, writing high-quality commit messages remains reluctantly considered. Several methods have been proposed with the aim of automated commit message generation. However, the existing methods are still limited because they only utilize either the changed codes or the changed codes combined with their surrounding statements. This paper proposes a method to represent code changes by combining the changed codes and the unchanged codes which have program dependence on the changed codes. Specifically, we first create program dependence graphs (PDGs) of source code before and after the change. After that, slices related to the changed code from these PDGs are extracted. These slices are then merged to represent the change. This method overcomes the limitations of current representations while improving the performance of 5/6 of state-of-the-art commit message generation methods by up to 15% in METEOR, 14% in ROUGE-L, and 10% in BLEU-4.
Thanh Trong Vu, Thanh-Dat Do, Hieu Dinh Vo
Int. J. Softw. Eng. Knowl. Eng.3
2024 Context-based statement-level vulnerability localization
Thu-Trang Nguyen, Hieu Dinh Vo
Inf. Softw. Technol.2
2024 Code-centric learning-based just-in-time vulnerability detection
Thu-Trang Nguyen, Thanh Trong Vu, Thanh-Dat Do, Kien-Tuan Ngo, Hieu Dinh Vo
J. Syst. Softw.6
2023 Detecting false-passing products and mitigating their impact on variability fault localization in software product lines
Thu-Trang Nguyen, Kien-Tuan Ngo, Hieu Dinh Vo
Inf. Softw. Technol.4
2023 Can an old fashioned feature extraction and a light-weight model improve vulnerability type identification performance?
Hieu Dinh Vo
Inf. Softw. Technol.1
2023 ARist: An effective API argument recommendation approach
Cuong Tran Manh, Trung Kien Tran, Tan M. Nguyen, Thu-Trang Nguyen, Kien-Tuan Ngo, Hieu Dinh Vo
J. Syst. Softw.7
2022 SCAR: Smart Contract Alarm Ranking
abstract
In 2016, the famous attack on the smart contract named The DAO led to a financial loss of 60 million dollars. Since then, attacks on smart contracts have increased. Thus, the security issue of smart contracts has attracted more and more attention from the community, putting pressure on developers to discover security issues in smart contracts before deploying them. To address this problem, many researchers have developed smart contract analyzers to early detect potential vulnerabilities. However, a common problem with these tools is a large number of alarms with a high false positive rate. Consequently, developers need to spend much time and effort investigating the alarms which are falsely detected as vulnerable. In this paper, we propose SCAR, a novel approach to prioritize the alarms of static analysis tools. Based on the intuition that alarms with similar contexts tend to have the same labels (true positive or false positive), SCAR is built with two deep learning models to capture the patterns associated with the contexts of the labeled alarms. After that, for new alarms, SCAR calculates their likelihood to be true positives and ranks them according to the predicted scores. SCAR is evaluated on a large data set of 14,184 alarms from 47,518 realworld smart contracts. The results show that the programmers can productively find up to two-thirds of the actual vulnerabilities by investigating only 20% of the ranked alarms.
Trung Kien Tran, Hieu Dinh Vo
APSEC2
2022 A Variability Fault Localization Approach for Software Product Lines
abstract
Software fault localization is one of the most expensive, tedious, and time-consuming activities in program debugging. This activity becomes even much more challenging in Software Product Line (SPL) systems due to variability of failures. These unexpected behaviors are induced by variability faults which can only be exposed under some combinations of system features. The interaction among these features causes the failures of the system. Although localizing bugs in single-system engineering has been studied in-depth, variability fault localization in SPL systems still remains mostly unexplored. In this article, we presentVarCop, a novel and effective variability fault localization approach. For an SPL system failed by variability bugs,VarCopisolates suspicious code statements by analyzing the overall test results of the sampled products and their source code. The isolated suspicious statements are the statements related to the interaction among the features which are necessary for the visibility of the bugs in the system. InVarCop, the suspiciousness of each isolated statement is assessed based on both the overall test results of the products containing the statement as well as the detailed results of the test cases executed by the statement in these products. On a large public dataset of buggy SPL systems, our empirical evaluation shows thatVarCopsignificantly improves two state-of-the-art techniques by 33% and 50% in ranking the incorrect statements in the systems containing a single bug each. In about two-thirds of the cases,VarCopcorrectly ranks the buggy statements at the top-3 positions in the ranked lists. For the cases containing multiple bugs,VarCopoutperforms the state-of-the-art approaches 2 times and 10 times in the proportion of bugs localized at the top-1 positions. Especially, in 22% and 65% of the buggy versions,VarCopcorrectly ranks at least one bug in a system at the top-1 and top-5 positions.
Thu-Trang Nguyen, Kien-Tuan Ngo, Hieu Dinh Vo
IEEE Trans. Software Eng.4
2021 API parameter recommendation based on language model and program analysis
abstract
APIs are extensively and frequently used in source code to leverage existing libraries and improve programming productivity. However, correctly and effectively using APIs, especially from unfamiliar libraries, is a non-trivial task. Although various approaches have been proposed for recommending API method calls in code completion, suggesting actual parameters for such APIs still needs further investigating. In this paper, we introduce FLUTE, an efficient and novel approach combining program analysis and language models for recommending API parameters. With FLUTE, the source code of programs is first analyzed to generate syntactically legal and type-valid candidates. Then, these candidates are ranked using language models. Our empirical results on two large real-world projects Netbeans and Eclipse indicate that FLUTE achieves 80% and +90% in Top-1 and Top-5 Precision, which means the tool outperforms the state-of-the-art approach.
Tran Manh Cuong, Trung Kien Tran, Tan M. Nguyen, Thu-Trang Nguyen, Hieu Dinh Vo
APSEC6
2021 Ranking Warnings of Static Analysis Tools Using Representation Learning
abstract
Static analysis tools are frequently used to detect potential vulnerabilities in software systems. However, an inevitable problem of these tools is their large number of warnings with a high false positive rate, which consumes time and effort for investigating. In this paper, we present DEFP, a novel method for ranking static analysis warnings. Based on the intuition that warnings which have similar contexts tend to have similar labels (true positive or false positive), DEFP is built with two BiLSTM models to capture the patterns associated with the contexts of labeled warnings. After that, for a set of new warnings, DEFP can calculate and rank them according to their likelihoods to be true positives (i.e., actual vulnerabilities). Our experimental results on a dataset of 10 real-world projects show that using DEFP, by investigating only 60% of the warnings, developers can find +90% of actual vulnerabilities. Moreover, DEFP improves the state-of-the-art approach 30% in both Precision and Recall.
Kien-Tuan Ngo, Dinh-Truong Do, Thu-Trang Nguyen, Hieu Dinh Vo
APSEC4
2021 VSEC: Transformer-Based Model for Vietnamese Spelling Correction
Dinh-Truong Do, Ha-Thanh Nguyen, Thang Ngoc Bui, Hieu Dinh Vo
PRICAI (2)4
2019 Improvements of Directed Automated Random Testing in Test Data Generation for C++ Projects
abstract
This paper improves the breadth-first search strategy in directed automated random testing (DART) to generate a fewer number of test data while gaining higher branch coverage, namely Static DART or SDART for short. In addition, the paper extends the test data compilation mechanism in DART, which currently only supports the projects written in C, to generate test data for C++ projects. The main idea of SDART is when it is less likely to increase code coverage with the current path selection strategies, the static test data generation will be applied with the expectation that more branches are covered earlier. Furthermore, in order to extend the test data compilation of DART for C++ context, the paper suggests a general test driver technique for C++ which supports various types of parameters including basic types, arrays, pointers, and derived types. Currently, an experimental tool has been implemented based on the proposal in order to demonstrate its efficacy in practice. The results have shown that SDART achieves higher branch coverage with a fewer number of test data in comparison with that of DART in practice.
Tran Nguyen Huong, Hieu Dinh Vo, Pham Ngoc Hung
Int. J. Softw. Eng. Knowl. Eng.3
2007 An Approach for Specifying Access Control Policy in J2EE Applications
abstract
Most applications based on J2EE platform use rolebased access control as an efficient mechanism to achieve security. The current approach for specifying access rule is based on methods of Enterprise JavaBeans (EJBs). In large-scale systems, where a large number of EJBs are used and the interactions between EJBs are complex, direct use of this methodbased approach is error-prone and difficult to maintain. We propose an alternative approach for specifying access control policy based on the concept of business function.
Hieu Dinh Vo, Masato Suzuki
APSEC1