EDBT 2026 Demo / reviewers in the wild / expert
Nhung H. Nguyen
dblp:374/5456
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-8607-2299ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An integrated cyber offence-defence framework for unmanned ground vehiclesabstractUnmanned ground vehicles (UGVs), including autonomous vehicles (AVs), are increasingly deployed across civilian, industrial, and defence environments. Their growing complexity across sensors, controllers, communication modules, and critical functional software also increases their exposure to cyber threats. Although current research on UGV cybersecurity provides valuable insights, it remains fragmented and often focuses on isolated attacks or individual defences without offering a consolidated security perspective. Existing resources, such as MITRE ATT&CK, AUTO-ISAC’s Automotive Threat Matrix, and NIST 800-160, provide useful guidance; however, they are designed for other domains and do not fully capture the operational characteristics and requirements of UGVs. This paper addresses this gap by developing a unified offensive and defensive framework specifically for UGVs. It organises existing literature into UGV-specific tactics, techniques, and asset dependencies, and pairs them with a UGV-focused mitigation database mapped to relevant security controls. Unlike prior efforts, this work integrates these components into a single coherent model, forming the first consolidated cyber offence–defence matrix tailored to UGV operations. To demonstrate the applicability of the framework, we analyse the 2014 Jeep Cherokee remote compromise and map its attack chain into the UGV threat structure. We also evaluate how mitigation strategies align with attack techniques by implementing three representative defences using the CARLASec simulation platform. Finally, we identify remaining gaps in current defences and point to areas requiring further development to improve UGV resilience. Nhung H. Nguyen, Hyunjae Kang 0001, Tina Moghaddam, Myung Kil Ahn, Dong Seong Kim 0001 |
Comput. Secur. | 1 |
| 2025 | Model-based structural and behavioral cybersecurity risk assessment in system designsabstractCybersecurity risk assessment has become a critical task in systems development and the operation of complex networked systems. However, current state-of-the-art approaches for detecting vulnerabilities, such as automated security testing or penetration testing, often result in late detection. Thus, there is a growing need for security by design, which involves conducting security-related analyses as early as possible in the system development life cycle. This paper proposes an integrated approach that combines static and dynamic hierarchical model-based security risk assessment. The approach enables early identification of security risks during system design, utilizing various models based on the Unified Modeling Language (UML), with lightweight extensions using profiles and stereotypes to capture security attributes like vulnerabilities and asset values. These security attributes are then used to compute relevant properties, including threat space, possible attack paths, and selected network-based security metrics. To facilitate dynamic security analysis, the UML model is subsequently translated into a deterministic and stochastic Petri net (DSPN). This translation allows for the dynamic analysis and simulation of the system’s state and behavior during an attack, capturing temporal aspects and probabilistic transitions. By representing system components and their interactions as modular Petri nets, the DSPN framework facilitates comprehensive simulation and analysis of possible attack scenarios. This also allows us to estimate time-based security metrics such as the duration required for an attacker to compromise system components. Consequently, this combined approach effectively addresses both static security analysis and dynamic state behavior, providing an integrated understanding of the system’s resilience against cyber threats. A real-world industrial case study illustrates the effectiveness of this approach. The underlying data originates from security assessments performed by Keen Security Labs, which were independently verified by BMW (Cai et al., 2019). Specifically, we present an infotainment system network model as implemented in multiple car models along with corresponding attack and defense models. We then demonstrate how the approach assesses the cybersecurity risk of such in-vehicle networks. Tino Jungebloud, Nhung H. Nguyen, Dong Seong Kim 0001, Armin Zimmermann |
Comput. Secur. | 2 |
| 2025 | Graphical security modelling for Autonomous Vehicles: A novel approach to threat analysis and defence evaluationabstractAutonomous Vehicles (AVs) integrate numerous control units , network components, and protocols to operate effectively and interact with their surroundings, such as pedestrians and other vehicles. While these technologies enhance vehicle capabilities and enrich the driving experience, they also introduce new attack surfaces, making AVs vulnerable to cyber-attacks. Such cyber-attacks can lead to severe consequences, including traffic disruption and even threats to human life. Security modelling is crucial to safeguarding AVs as it enables the simulation and analysis of an AV’s security before any potential attacks. However, the existing research on AV security modelling methods for analysing security risks and evaluating the effectiveness of security measures remains limited. In this work, we introduce a novel graphical security model and metrics to assess the security of AV systems. The proposed model utilizes initial network information to build attack graphs and attack trees at different layers of network depth. From this, various metrics are automatically calculated to analyse the security and safety of the AV network. The proposed model is designed to identify potential attack paths, analyse security and safety with precise metrics, and evaluate various defence strategies. We demonstrate the effectiveness of our framework by applying it to two AV networks and distinct AV attack scenarios, showcasing its capability to enhance the security of AVs. Nhung H. Nguyen, Mengmeng Ge 0001, Jin-Hee Cho, Terrence J. Moore, Seunghyun Yoon 0001, Hyuk Lim, Frederica Free-Nelson, Guangdong Bai, Dong Seong Kim 0001 |
Comput. Secur. | 1 |
| 2023 | Hierarchical Model-Based Cybersecurity Risk Assessment During System Design
Tino Jungebloud, Nhung H. Nguyen, Dong Seong Kim 0001, Armin Zimmermann |
SEC | 2 |