Cybersecurity student at FPT University · GenAI and agentic AI security
I study how LLM applications and autonomous agents fail under attack, and how to measure those failures rigorously. My current work covers security testing of RAG pipelines, the reliability of LLM-based penetration-testing agents, and AI-assisted database security assessment.
- LLM application security: direct and indirect prompt injection, RAG poisoning, system-prompt leakage, data exfiltration, excessive agency
- Agentic AI security: tool-using and multi-agent systems, trust boundaries, guardrail evaluation
- Autonomous pentesting agents: reliability and evaluation of LLM-based security agents
- Reproducible security evaluation: controlled labs, synthetic data, ablation studies, honest limitations
GenAI Security Lab Pro · Python, Streamlit
A controlled, reproducible lab that measures attack success rate, false-positive rate and latency overhead across four GenAI/RAG security configurations, from an unprotected baseline to layered Secure-SDLC controls. 198 prompts × 4 configurations, six attack categories including Vietnamese social-engineering prompts, synthetic data only.
NouriMe · TypeScript, Expo / React Native, Express · Team lead
A nutrition decision-support app for Vietnamese meals. Deterministic decision engine, just-in-time consent before any remote AI call, fail-closed safety policy and minimized data sent to the model. Advanced to Round 2 of AISC 2026.
- An AI assistant that generates database security testing reports with OWASP-aligned remediation for MySQL and SQL Server
- Research on evaluating LLM-based autonomous penetration-testing agents
All security testing I do runs only in authorized, isolated environments: CTFs, intentionally vulnerable systems, containers and researcher-controlled infrastructure.
