VLDB 2026 Research / reviewers in the wild / expert
Lam Nguyen Tung
dblp:316/1426
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | UntrustVul: Automated Untrustworthy Alert Identification in Vulnerability Detection ModelsabstractMachine learning (ML) has shown promising results in detecting software vulnerabilities. However, ML detectors are not guaranteed to make predictions based on the right indicators. Studies have revealed that they can rely onirrelevantcode features, such as identifiers or function signatures, particularly those that commonly appear in vulnerable code, yet are not related to the actual vulnerabilities. As a result, the lines of code that the detectors depend on and flag as suspicious are not always genuinely vulnerable. Consequently, developers must manually review these suspicious lines, which is time-consuming and error-prone. If the suspicious lines are wrong, developers may be misled, spend unnecessary effort, or even reach incorrect patching strategies. This highlights the need for automated approaches to identify untrustworthy vulnerability predictions.In this paper, we introduce UNTRUSTVUL, a new approach for identifying untrustworthy vulnerability predictions. Specifically, we focus on cases where a model highlights suspicious lines that would not appear in reliable predictions, i.e., lines that are inherently non-vulnerable and unrelated to any vulnerabilities. To achieve this, we leverage patterns of vulnerable lines observed in historical data. UNTRUSTVUL automatically rules out as untrustworthy any predictions that highlight suspicious lines neither observed in history nor influential to those that have been observed. We refer to such lines as vulnerability-irrelevant. A line is deemed vulnerability-irrelevant if ① it does not match any known patterns of historical vulnerabilities, and ② all its successors in the data and control dependency graph are also vulnerability-irrelevant. Intuitively, a vulnerability-irrelevant line shows low similarity to known vulnerabilities and has no dependency paths to any lines outside the vulnerability-irrelevant category. Notably, these rules are designed to be conservative, as mislabeling a trustworthy prediction as untrustworthy is also undesired. We evaluate UNTRUSTVULon 115K vulnerability predictions made by four models across BigVul, MegaVul, SARD, and PrimeVul datasets, with ground-truth trustworthiness labeled based on the overlap between actual denoised vulnerable lines and model-annotated suspicious lines. UNTRUSTVULeffectively detects untrustworthy predictions with AUC of 70%–88% and F1–score of 82%–94%, outperforming existing approaches by 6%–59% in AUC and 13%–92% in F1–score. Lam Nguyen Tung, Xiaoning Du 0001, Neelofar, Aldeida Aleti |
IEEE Trans. Software Eng. | 1 |
| 2024 | Automated test data generation and stubbing method for C/C++ embedded projects
Lam Nguyen Tung, Nguyen Vu Binh Duong, Khoi Nguyen Le, Pham Ngoc Hung |
Autom. Softw. Eng. | 1 |
| 2022 | An automated test data generation method for void pointers and function pointers in C/C++ libraries and embedded projects
Lam Nguyen Tung, Hoang-Viet Tran, Khoi Nguyen Le, Pham Ngoc Hung |
Inf. Softw. Technol. | 1 |