Skip to content

Author

Tran Duc Le

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Jul 2026

TRACE: Feature-Space Feasible Action Contracts for Explainable Intrusion Triage

Explainable intrusion detection systems often provide feature attributions without indicating whether a security action should be released, downgraded, or deferred. This paper investigates whether action-governed explanations can provide bounded triage evidence under traffic feature feasibility constraints. We present TRACE, a framework that maps calibrated detector outputs to a finite action ladder, constructs conformal action sets, selects actions via a utility-minimax rule, and releases high-severity actions only when compact support contracts remain stable under feasible perturbations, where feasibility is a property of the processed benchmark features and not of packet-level realizability. Ablations isolate the conformal set and release gate as the primary drivers of system behavior. Across 11 gated dataset–model pairs, TRACE produces non-degenerate action sets with zero full-set collapse and defer/block rates from 0.603 to 1.000. Under held-out sample split tuning, it achieves higher average proxy utility than unconditional release and release rate-matched random release on all 11 pairs. Against the strongest simple selective gate, however, it matches on 6 of 11 pairs and trails on the remaining 5. Robustness sweeps confirm positive all-row utility on all pairs, though pass-only utility becomes fragile in ultra-low-release regimes. Unlike display-only attribution summaries, the TRACE contract records the plausible action set, feasibility checks, stability summaries, and an explicit release rationale. The results support TRACE as a bounded evidentiary framework for action-governed XAI in IDS, rather than claiming superiority over all IDS/XAI methods or general deployment readiness.

Tran Duc Le, Mohammad Arifuzzaman, Yida Bao · 0 citations
Review Aug 2026

Research Methodologies for Cybersecurity in Enterprise Environments: A Narrative Review, Synthesis and Executable Guide

Enterprise cybersecurity research draws on a wider range of methods than any single community routinely teaches. Researchers face a selection problem before they face a technical one: a study may simultaneously need a systematic review, a design-science artifact, a controlled detection experiment, an interview study, or an attack-graph model. This paper addresses that problem in two ways. First, it provides a narrative review and synthesis of methodological practices across a verified corpus of 151 works. We organise these practices into eleven methodology families, detailing for each what questions it answers, the strength of its supporting evidence, and its common failure modes. Second, we convert each family into an executable protocol comprising ordered steps, required instruments, evaluation criteria, common validity threats, and a reporting checklist. Every protocol is also visually mapped to make the sequence, decisions, and threats legible at a glance. We also treat contradictions in the literature as evidence. For example, reported rankings of intrusion-detection algorithms are wildly inconsistent across individually careful studies. We argue this pattern is most parsimoniously explained by variations in evaluation design rather than the algorithms themselves, as these studies differ in design dimensions known to shift results by more than the margins separating the algorithms. Ultimately, the evidence supports methodological pluralism disciplined by explicit validity reasoning. We conclude that researchers must match their evaluation design to the decision under study, triangulate technical against organisational evidence, explicitly state the population a result generalises to, and report the conditions under which the result would not hold.

Tran Duc Le · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.