Skip to content
View buiPhongGiang's full-sized avatar
  • FPT University
  • Ho Chi Minh City, Vietnam

Block or report buiPhongGiang

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
buiPhongGiang/README.md

Hi, I'm Bui Phong Giang

Cybersecurity student at FPT University · GenAI and agentic AI security

I study how LLM applications and autonomous agents fail under attack, and how to measure those failures rigorously. My current work covers security testing of RAG pipelines, the reliability of LLM-based penetration-testing agents, and AI-assisted database security assessment.

Research interests

  • LLM application security: direct and indirect prompt injection, RAG poisoning, system-prompt leakage, data exfiltration, excessive agency
  • Agentic AI security: tool-using and multi-agent systems, trust boundaries, guardrail evaluation
  • Autonomous pentesting agents: reliability and evaluation of LLM-based security agents
  • Reproducible security evaluation: controlled labs, synthetic data, ablation studies, honest limitations

Featured work

GenAI Security Lab Pro · Python, Streamlit
A controlled, reproducible lab that measures attack success rate, false-positive rate and latency overhead across four GenAI/RAG security configurations, from an unprotected baseline to layered Secure-SDLC controls. 198 prompts × 4 configurations, six attack categories including Vietnamese social-engineering prompts, synthetic data only.

NouriMe · TypeScript, Expo / React Native, Express · Team lead
A nutrition decision-support app for Vietnamese meals. Deterministic decision engine, just-in-time consent before any remote AI call, fail-closed safety policy and minimized data sent to the model. Advanced to Round 2 of AISC 2026.

Currently working on

  • An AI assistant that generates database security testing reports with OWASP-aligned remediation for MySQL and SQL Server
  • Research on evaluating LLM-based autonomous penetration-testing agents

Tech

Python TypeScript Kotlin React Native NestJS Next.js MySQL SQL Server Streamlit


All security testing I do runs only in authorized, isolated environments: CTFs, intentionally vulnerable systems, containers and researcher-controlled infrastructure.

Pinned Loading

  1. genai-security-lab-pro genai-security-lab-pro Public

    Reproducible lab for measuring prompt injection, RAG poisoning and data exfiltration risk across layered GenAI security controls

    Python