Cao Thang Bui
Keynote Speaker
Dr. Cao Thang Bui is an Assistant Professor in the School of Computing and Design at California State University, Monterey Bay, where he specializes in cybersecurity, access control, computer networks, and software engineering. He earned his Ph.D., M.S., and B.S. in Computer Science from Stony Brook University, completing his doctoral dissertation on Mining Relationship-Based Access Control Policies under the guidance of Scott D. Stoller. Before joining CSUMB in 2023, Dr. Bui served as an Assistant Professor and Interim Program Director at West Virginia University Institute of Technology and later worked as a Postdoctoral Associate at Stony Brook University. His research focuses on access control, cybersecurity, artificial intelligence applications in security, and policy mining. He has authored numerous journal and conference publications in leading venues such as ACM Symposium on Access Control Models and Technologies, IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy, and Computers & Security. His work has earned recognition, including the Best Paper Award at DBSec 2016. Dr. Bui is also deeply committed to teaching, mentoring undergraduate researchers, and expanding opportunities in STEM education. He has led multiple funded projects, advised student organizations, and contributed to diversity and outreach initiatives aimed at promoting cybersecurity education among K-12 and undergraduate students.
AI for Access Control Policy Mining: Challenges and Opportunities Access control plays a central role in securing modern information systems, but designing effective policies remains a difficult and time-consuming task. Traditional policy mining approaches face challenges such as limited datasets, incomplete information, and the difficulty of balancing accuracy with interpretability. These obstacles make it difficult to develop policies that are both precise and understandable, particularly in large or dynamic systems. Recent advances in AI provide new opportunities to address these challenges. AI methods can assist in discovering patterns in permissions, generating candidate policies, and refining rules to achieve greater accuracy and clarity. Moreover, AI can help automate parts of the policy mining workflow, reducing manual effort and enabling researchers and practitioners to handle more complex systems. At the same time, introducing AI into this process brings new challenges: ensuring correctness, avoiding overfitting to noisy data, and maintaining transparency and trustworthiness in AI-assisted policy generation. This talk will explore the promise and pitfalls of applying AI to the policy mining problem. We will discuss how AI techniques can support the discovery of high-level access control rules, highlight the risks of relying on opaque models in security-critical contexts, and outline future directions for integrating AI into access control research and practice.