Institution profile

ST Engineering Aerospace Ltd.

Industry researchasia · sg
Official website
Research library12linked papers
Opportunities0open roles
Selected work

Representative Papers

Explaining Intrusion Alert Decisions of Deep Learning-based Network Intrusion Detection Systems for Security Analysts

Jul 13, 2026

This work addresses the limited interpretability of alerts generated by existing deep learning–based network intrusion detection systems (NIDS), which hinders effective analyst-driven triage in practice. To bridge this gap, the authors propose EXP-SEC, a novel framework that incorporates a forensic module to pinpoint suspicious traffic and introduces a fine-grained explanation mechanism capable of handling feature overlap and group-wise dependencies. By leveraging a multi-stage mapping strategy, EXP-SEC translates model predictions into semantically meaningful alerts aligned with the domain knowledge of security operations centers. This framework is the first to deliver domain-aligned explanations tailored for security analysts, significantly outperforming xNIDS in group-level and overlap-aware explanatory utility while maintaining comparable performance in accuracy, sparsity, and stability. The resulting explanations are more intuitive and actionable for human analysts.

0 citationsRead paper

HilEnT: Hilbert, Entropy Transformed Image Based Malware Detection

Jul 06, 2026

This study addresses the growing threat of malware by proposing HilEnT, a novel binary-to-image conversion method that maps malware binaries into three-channel color images through Hilbert curve mapping integrated with local entropy features. By combining deep learning with few-shot learning strategies, the approach significantly enhances malware detection and classification performance across four public datasets. Experimental results demonstrate that HilEnT achieves high accuracy and robustness in both binary and multi-class classification tasks, particularly excelling in low-data regimes. The method effectively supports few-shot malware recognition, offering a promising solution for identifying malicious software under data-scarce conditions.

0 citationsRead paper

TIER: Trajectory-Invariant Explanation Regularization for Membership Privacy

Jul 02, 2026

This work addresses the privacy risks posed by explanation interfaces, which can leak membership information and are inadequately mitigated by existing defenses against membership inference attacks based on confidence descent trajectories. To counter such explanation-driven attacks, the authors propose a trajectory-invariance regularization mechanism that, during training, leverages model gradients to generate perturbations mimicking confidence descent trajectories. The method enforces explanation consistency via KL divergence constraints and aligns the explanatory behaviors of members and non-members through a variance penalty. This approach significantly enhances robustness against trajectory-based membership inference attacks while preserving both model utility and explanation fidelity, thereby strengthening privacy guarantees.

0 citationsRead paper

Impact of Task Phrasing on Presumptions in Large Language Models

May 01, 2026

Large language models (LLMs) are susceptible to task phrasing in real-world applications, often adopting irrational prior assumptions that compromise their reliability and safety. This study addresses this issue by systematically investigating, for the first time, how variations in task wording influence LLMs’ decision-making priors, using the iterated prisoner’s dilemma as a case study. Through a controlled experimental design combined with behavioral analysis and logical reasoning evaluation, the research demonstrates that neutral phrasing significantly reduces models’ reliance on prior assumptions, thereby encouraging more logically consistent reasoning. These findings underscore the critical role of deliberate task wording in enhancing the controllability and safety of LLM behavior.

0 citationsRead paper

The Effects of Visual Priming on Cooperative Behavior in Vision-Language Models

Apr 30, 2026

This study investigates how visual inputs influence the behavior of vision-language models (VLMs) in cooperative decision-making, with a particular focus on the risk of uncontrolled actions in safety-critical scenarios. Using an iterated prisoner’s dilemma framework, the authors systematically evaluate the impact of semantic images and color-coded reward matrices on VLMs’ propensity to cooperate, while also assessing mitigation strategies such as prompt engineering, chain-of-thought reasoning, and visual token reduction. The work reveals for the first time that visual priming significantly alters VLM cooperation behavior and demonstrates substantial differences in susceptibility across model architectures. These findings underscore the necessity of architecture-specific robustness evaluations prior to real-world deployment.

0 citationsRead paper
Recent publications

Latest Papers

Explaining Intrusion Alert Decisions of Deep Learning-based Network Intrusion Detection Systems for Security Analysts

Jul 13, 2026

This work addresses the limited interpretability of alerts generated by existing deep learning–based network intrusion detection systems (NIDS), which hinders effective analyst-driven triage in practice. To bridge this gap, the authors propose EXP-SEC, a novel framework that incorporates a forensic module to pinpoint suspicious traffic and introduces a fine-grained explanation mechanism capable of handling feature overlap and group-wise dependencies. By leveraging a multi-stage mapping strategy, EXP-SEC translates model predictions into semantically meaningful alerts aligned with the domain knowledge of security operations centers. This framework is the first to deliver domain-aligned explanations tailored for security analysts, significantly outperforming xNIDS in group-level and overlap-aware explanatory utility while maintaining comparable performance in accuracy, sparsity, and stability. The resulting explanations are more intuitive and actionable for human analysts.

0 citationsRead paper

HilEnT: Hilbert, Entropy Transformed Image Based Malware Detection

Jul 06, 2026

This study addresses the growing threat of malware by proposing HilEnT, a novel binary-to-image conversion method that maps malware binaries into three-channel color images through Hilbert curve mapping integrated with local entropy features. By combining deep learning with few-shot learning strategies, the approach significantly enhances malware detection and classification performance across four public datasets. Experimental results demonstrate that HilEnT achieves high accuracy and robustness in both binary and multi-class classification tasks, particularly excelling in low-data regimes. The method effectively supports few-shot malware recognition, offering a promising solution for identifying malicious software under data-scarce conditions.

0 citationsRead paper

TIER: Trajectory-Invariant Explanation Regularization for Membership Privacy

Jul 02, 2026

This work addresses the privacy risks posed by explanation interfaces, which can leak membership information and are inadequately mitigated by existing defenses against membership inference attacks based on confidence descent trajectories. To counter such explanation-driven attacks, the authors propose a trajectory-invariance regularization mechanism that, during training, leverages model gradients to generate perturbations mimicking confidence descent trajectories. The method enforces explanation consistency via KL divergence constraints and aligns the explanatory behaviors of members and non-members through a variance penalty. This approach significantly enhances robustness against trajectory-based membership inference attacks while preserving both model utility and explanation fidelity, thereby strengthening privacy guarantees.

0 citationsRead paper

Impact of Task Phrasing on Presumptions in Large Language Models

May 01, 2026

Large language models (LLMs) are susceptible to task phrasing in real-world applications, often adopting irrational prior assumptions that compromise their reliability and safety. This study addresses this issue by systematically investigating, for the first time, how variations in task wording influence LLMs’ decision-making priors, using the iterated prisoner’s dilemma as a case study. Through a controlled experimental design combined with behavioral analysis and logical reasoning evaluation, the research demonstrates that neutral phrasing significantly reduces models’ reliance on prior assumptions, thereby encouraging more logically consistent reasoning. These findings underscore the critical role of deliberate task wording in enhancing the controllability and safety of LLM behavior.

0 citationsRead paper

The Effects of Visual Priming on Cooperative Behavior in Vision-Language Models

Apr 30, 2026

This study investigates how visual inputs influence the behavior of vision-language models (VLMs) in cooperative decision-making, with a particular focus on the risk of uncontrolled actions in safety-critical scenarios. Using an iterated prisoner’s dilemma framework, the authors systematically evaluate the impact of semantic images and color-coded reward matrices on VLMs’ propensity to cooperate, while also assessing mitigation strategies such as prompt engineering, chain-of-thought reasoning, and visual token reduction. The work reveals for the first time that visual priming significantly alters VLM cooperation behavior and demonstrates substantial differences in susceptibility across model architectures. These findings underscore the necessity of architecture-specific robustness evaluations prior to real-world deployment.

0 citationsRead paper