EDBT 2026 Demo / reviewers in the wild / expert
Cong Hiep Pham 0001
dblp:172/6749 · also Hiep Cong Pham 0001
· DBLP profile ↗
6ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0002-6423-1188ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Relationships between cultural orientations, phishing victimization, and phishing recognition: A cross-cultural experimentabstractBackground : Humans remain a critical vulnerability in the cybersecurity chain. While research has explored various behavioral factors influencing phishing susceptibility, the role of national culture and individual cultural orientations remains under-researched, representing a significant gap in the literature. Aims : This study investigates the impact of individual cultural orientations on phishing victimization, while taking into account other relevant factors, such as self-control, risk-taking, technical training, email management practices, demographics (age and gender), and country-level economic and ICT development. Methods : Data were collected via an online survey of university students (N = 2,143) across 12 countries in Asia, Africa, North America, and Europe. Outcomes measures included phishing victimization, phishing recognition, and legitimate email recognition; the last two measures were assessed via scenarios. Data were analyzed using Signal Detection Theory and mixed modelling. Results : Phishing victimization was significantly associated with low self-control, high risk-taking, high exposure, and poorer recognition of legitimate emails. Conversely, cultural orientations, religiosity, and country of origin had minimal effects. While phishing recognition was unrelated to victimization, the ability to recognize legitimate emails reduced victimization risk. For culturally diverse organizations, these findings suggest that cultural factors may be less critical to phishing victimization than has been previously assumed. Training users and improved self-control techniques may help protect against phishing victimization. Marianne Junger, Pawel Olber, Rafal Plocki, J. W. (Hans) Luyten, Luka Koning, Caitlyn N. Muniz, Jan-Willem Bullee, Victoria Wang, Reinhardt A. Botha, C. Jordan Howell, Verena Distler, Xiaowei Chen 0013, Cong Hiep Pham 0001, Mohammed Aljohani, Newman U. Richards, Fabian Muhly, Abhishta, Steven Furnell |
Comput. Secur. | 13 |
| 2025 | Workplace security and privacy implications in the GenAI age: A surveyabstractGenerative Artificial Intelligence (GenAI) is transforming the workplace, but its adoption introduces significant risks to data security and privacy. Recent incidents underscore the urgency of addressing these issues. This comprehensive survey investigates the implications of GenAI integration in workplaces, focusing on its impact on organizational operations and security. We analyze vulnerabilities within GenAI systems, threats they face, and repercussions of AI-driven workplace monitoring. By examining diverse attack vectors like model attacks and automated cyberattacks, we expose their potential to undermine data integrity and privacy. Unlike previous works, this survey specifically focuses on the security and privacy implications of GenAI within workplace settings, addressing issues like employee monitoring, deepfakes , and regulatory compliance. We delve into emerging threats during model training and usage phases, proposing countermeasures such as differential privacy for training data and robust authentication for access control. Additionally, we provide a comprehensive analysis of evolving regulatory frameworks governing AI tools globally. Based on our comprehensive analysis, we propose targeted recommendations for future research and policy-making to promote responsible and secure adoption of GenAI in the workplace, such as incentivizing the development of explainable AI (XAI) and establishing clear guidelines for ethical data usage. This survey equips stakeholders with a comprehensive understanding of GenAI’s complex workplace landscape, empowering them to harness its benefits responsibly while mitigating risks. Abebe Abeshu Diro, Shahriar Kaisar, Akanksha Saini, Samar Fatima, Cong Hiep Pham 0001, Fikadu Erba |
J. Inf. Secur. Appl. | 5 |
| 2024 | Leveraging zero knowledge proofs for blockchain-based identity sharing: A survey of advancements, challenges and opportunitiesabstractIdentity sharing systems, regardless of their architectural models, share common vulnerabilities. These systems compel users to divulge personal information and furnish proof of identity for accessing services, leaving them susceptible to data breaches that can culminate in identity theft and jeopardize online data security. While blockchain technology offers a potential remedy, delivering enhanced security, immutability, and traceability, it simultaneously raises pertinent concerns surrounding privacy and transparency. The integration of zero-knowledge proof (ZKP) technology has emerged as a promising solution, particularly in enhancing privacy within the transparent blockchain ecosystem. Our paper conducts an exhaustive survey of the existing literature, with a particular focus on the assimilation of ZKP technology into blockchain for the secure sharing of user identities. We undertake a critical evaluation of the advancements achieved in this domain, pinpoint the formidable challenges that must be confronted, and uncover nascent opportunities for further exploration. Our contribution transcends the realms of mere summarization and analysis; we go a step further by offering recommendations drawn from real-world case studies and delineating future research directions. Abebe Abeshu Diro, Lu Zhou 0003, Akanksha Saini, Shahriar Kaisar, Cong Hiep Pham 0001 |
J. Inf. Secur. Appl. | 5 |
| 2020 | Enhancing cyber security behavior: an internal social marketing approachabstractPurpose Understanding the behavioral change process of system users to adopt safe security practices is important to the success of an organization’s cybersecurity program. This study aims to explore how the 7Ps (product, price, promotion, place, physical evidence, process and people) marketing mix, as part of an internal social marketing approach, can be used to gain an understanding of employees’ interactions within an organization’s cybersecurity environment. This understanding could inform the design of servicescapes and behavioral infrastructure to promote and maintain cybersecurity compliance. Design/methodology/approach This study adopted an inductive qualitative approach using in-depth interviews with employees in several Vietnamese organizations. Discussions were centered on employee experiences and their perceptions of cybersecurity initiatives, as well as the impact of initiatives on compliance behavior. Responses were then categorized under the 7Ps marketing mix framework. Findings The study shows that assessing a cybersecurity program using the 7P mix enables the systematic capture of users’ security compliance and acceptance of IT systems. Additionally, understanding the interactions between system elements permits the design of behavioral infrastructure to enhance security efforts. Results also show that user engagement is essential in developing secure systems. User engagement requires developing shared objectives, localized communications, co-designing of efficient processes and understanding the “pain points” of security compliance. The knowledge developed from this research provides a framework for those managing cybersecurity systems and enables the design human-centered systems conducive to compliance. Originality/value The study is one of the first to use a cross-disciplinary social marketing approach to examine how employees experience and comply with security initiatives. Previous studies have mostly focused on determinants of compliance behavior without providing a clear platform for management action. Internal social marketing using 7Ps provides a simple but innovative approach to reexamine existing compliance approaches. Findings from the study could leverage proven successful marketing techniques to promote security compliance. Cong Hiep Pham 0001, Linda Brennan, Lukas Parker, Nhat Tram Phan-Le, Irfan Ulhaq, Mathews Z. Nkhoma, Minh Nhat Nguyen |
Inf. Comput. Secur. | 1 |
| 2019 | Information security burnout: Identification of sources and mitigating factors from security demands and resources
Cong Hiep Pham 0001, Linda Brennan, Steven Furnell |
J. Inf. Secur. Appl. | 1 |
| 2016 | Stress-based security compliance model - an exploratory studyabstractPurpose This paper aims to extend current information security compliance research by adapting “work-stress model” of the extended Job Demands-Resources model to explore how security compliance demands, organization and personal resources influence end-user security compliance. The paper proposes that security compliance burnout and security engagement as the mediating factors between security compliance demands, organizational and personal resources and individual security compliance. Design/methodology/approach The authors used a multi-case in-depth interview method to explore the relevance and significance of security demands, organizational resources and personal resources on security compliance at work. Seventeen participants in three organizations including a bank, a university and an oil distribution company in Vietnam were interviewed during a four-month period. Findings The study identified three security demands, three security resources and two aspects of personal resources that influence security compliance. The study demonstrates that the security environment factors such as security demands and resources affected compliance burden and security engagement. Personal resources could play an integral role in moderating the impact of security environment on security compliance. Research limitations/implications The findings presented are not generalizable to the wider population of end-users in Vietnam due to the small sample size used in the interviews. Further quantitative studies need to measure the extent of each predictor on security compliance. Originality/value The originality of the research stems from proposing not only stress-based but also motivating factors from the security environment on security compliance. By using qualitative approach, the study provides more insight to understand the impact of the security environments on security compliance. Cong Hiep Pham 0001, Jamal El-Den, Joan Richardson |
Inf. Comput. Secur. | 1 |