Skip to content
HTHo Dinh Tri
Open to AI / Software Engineering roles· Remote-friendly · internships welcome
Local time (UTC+7, Ho Chi Minh City)

Hi, I'm TriAI Systems & Cloud Security Engineer

I build generative AI systems and secure cloud infrastructure — from multilingual medical conversation summarization (Qwen3-4B LoRA) to LLM agents that find and patch Infrastructure-as-Code vulnerabilities.

View My Work Preview CV
54.59
Validation chrF++
99.5%
Constraint score
91.8%
IaC detection precision
17
Languages summarized
Ho Dinh Tri
Qwen3-4BLoRALangChainTransformerschrF++FastAPIDockerTerraformTree-sitterGitHub ActionsPostgreSQLpgvectorAzureCheckovtfsecXGBoostCaddyStreamlitQwen3-4BLoRALangChainTransformerschrF++FastAPIDockerTerraformTree-sitterGitHub ActionsPostgreSQLpgvectorAzureCheckovtfsecXGBoostCaddyStreamlit
Scroll to explore
About

Applied AI, built to a security standard

Information Technology student at VNUHCM University of Science, working at the intersection of AI Agent & LLM systems and security engineering. My work spans multilingual document summarization pipelines across 17 languages, static-analysis tooling powered by fine-tuned code LLMs, and scalable cloud backends with automated CI/CD.

Most of my work starts with the same question: what breaks if this model, policy or pipeline is wrong? The answer shapes the architecture — leak-free evaluation splits, AST-grounded context for LLM findings, ABAC at the database layer, and multi-layer validation gates that elevate response constraint scores to 99.5%.

Reliability by design

Multi-layer constraint gates and access control treated as build requirements, not afterthoughts.

Cloud native

Containerised services and CI/CD pipelines that deploy with zero downtime.

Systems thinking

AST parsing, policy analysis and network fundamentals behind every AI feature.

Measured impact

Latency, precision and false-positive rates tracked before and after every change.

Toolkit

Skills & technologies

The stack I reach for when a system has to be accurate, fast and safe at the same time.

AI Agent & Generative LLMs

Fine-tuning, agent orchestration and evaluating models that ship to production.

  • Qwen3-4B
  • LoRA / PEFT
  • LangChain
  • RAG Pipelines
  • Hugging Face Transformers
  • mT5
  • chrF++ (XAI)
  • scikit-learn
  • XGBoost

Security & Program Analysis

Policy-as-code, AST static analysis and data-protection engineering.

  • Static Analysis (AST)
  • Checkov
  • tfsec
  • Policy-as-Code
  • IAM / VPC Review
  • OWASP & CWE
  • ABAC / RLS
  • SARIF & CycloneDX

Cloud, DevOps & CI/CD

Reproducible builds and zero-downtime delivery pipelines.

  • Docker (Compose)
  • GitHub Actions
  • Azure
  • Terraform
  • Tree-sitter
  • Supabase
  • Caddy
  • Linux & Networking

Backend & Data Systems

APIs, vector search and the distributed interfaces that glue services together.

  • Python
  • FastAPI
  • pgvector (HNSW)
  • PostgreSQL
  • RESTful APIs
  • Streamlit
  • TypeScript
  • Next.js
Selected Work

Systems I've built and researched

Four engineering tracks across multilingual medical LLM summarization, AI-assisted infrastructure security, agentic cloud backends and applied machine learning. Explore interactive walkthroughs and architectural dataflows below.

AI / GenerativeOngoingJuly 2026 – Present

Multilingual Medical Conversation Summarization (Meddies)

Research Contributor · Research Lab

End-to-end intelligent clinical dialogue summarization pipeline across 17 languages using fine-tuned Qwen3-4B LoRA and mT5.

54.59
validation chrF++
99.5%
constraint score (was 85.9%)
17
languages supported
5-layer
evaluation framework

Pre-computed sample outputs from the project · no model runs in your browser

Multilingual Medical Dialogue Summarization (Meddies)

Fine-tuned Qwen3-4B LoRA & 5-Layer Constraint Verification Gate

17 Languages 99.5% ConstraintScore
Dialogue:
Model:
Tái Khám Tăng Huyết Áp & Rối Loạn Lipid MáuModel: Qwen3-4B LoRA (Fine-tuned)
Subjective (Chief Complaint & History)

Tái khám tăng huyết áp định kỳ, phù mắt cá chân hai bên, hồi hộp thoáng qua.

Objective (Vitals & Lab Data)

Huyết áp đo tại khám: 145/90 mmHg; Xét nghiệm lipid máu: LDL-C 3.6 mmol/L.

Assessment (Clinical Impression)

Tăng huyết áp nguyên phát chưa kiểm soát tối ưu; Rối loạn lipid máu; Tác dụng phụ phù ngoại vi nghi ngờ do Amlodipine.

Plan (Dosage Prescriptions & Follow-up)
  • •Giảm Amlodipine từ 5mg xuống 2.5mg uống mỗi sáng.
  • •Bổ sung Telmisartan 40mg uống 1 lần/ngày vào buổi sáng.
  • •Khởi trị rối loạn lipid với Atorvastatin 20mg uống buổi tối.
  • •Duy trì chế độ ăn giảm muối (<5g/ngày), theo dõi huyết áp tại nhà.
  • •Hẹn tái khám sau 4 tuần để đánh giá lại đáp ứng lâm sàng.
VALIDATION METRIC54.59 chrF++
CONSTRAINT SCORE99.5% (+13.6pp)
LANGUAGES17 Supported
GENERATIVE MODELQwen3-4B LoRA
PythonPyTorchHugging Face TransformersQwen3-4BLoRAmT5LangChainchrF++Docker
AI / SecurityOngoingFeb 2026 – Present

AI-Powered IaC Security & Remediation Agent

Research Contributor · Research Lab

Automated vulnerability detection and remediation for Infrastructure as Code, combining AST parsing with fine-tuned code LLMs.

91.8%
detection precision
−28%
false positives
95%
patch schema pass rate
1,500+
Terraform files analysed
Pythontree-sitter-hclPyTorchLoRACheckovtfsecGitHub ActionsDockerTerraform
Cloud / BackendJul 2026 – Aug 2026

SmartATS — Intelligent Agentic Recruitment Platform

Backend & CI/CD Platform Engineer · Product Team

Autonomous agentic recruitment system across 10 domain modules, automating enterprise resume ingestion, multi-modal signal extraction and candidate scoring.

10 modules
agentic domains
768-d HNSW
pgvector hybrid search
ABAC
access control model
Azure
LLM telemetry layer
PythonLangChainFastAPIpgvectorSentence TransformersAzureSupabaseDockerGitHub Actions
Machine LearningFeb 2026 – Apr 2026

Automobile Insurance Fraud Detection System

ML Engineer · Independent Project

End-to-end tabular ML pipeline with 145 engineered features, SMOTE re-sampling, and XGBoost classifier deployed with Streamlit and Caddy.

+46.6pp
fraud recall improvement
0.840
ROC-AUC
0.63
F1-score
145
engineered features
Pythonscikit-learnXGBoostSMOTEStreamlitDocker ComposeCaddy
Research Notes

Technical insights from the work

Short case studies on the engineering decisions behind the numbers — what worked, why, and what the metrics do and don't prove.

Case study 3 min · Sep 2026

From 85.9% to 99.5% ConstraintScore: why fine-tuning wasn't enough

LoRA fine-tuning Qwen3-4B made multilingual medical summaries fluent (54.59 chrF++). It took a separate validation gate with bounded retries to make them reliably correct.

85.9% → 99.5%
ConstraintScore
54.59
validation chrF++
17
languages
Read the note
Case study 2 min · Sep 2026

Grounding a code LLM in the AST to cut Terraform false positives

Rule-based scanners judge a resource in isolation. Parsing 1,500+ Terraform files with tree-sitter and feeding the model each resource's real connections cut false positives by 28% versus Checkov and tfsec.

91.8%
detection precision
−28%
false positives vs Checkov/tfsec
95%
patch schema pass rate
Read the note
Builds

Projects & side work

Filter by area or search by stack. Open a card to read its README inline.

6 projects

Meddies — Multilingual Medical Summarization

Clinical dialogue summarization across 17 languages with fine-tuned Qwen3-4B LoRA and mT5. 54.59 validation chrF++, a 5-layer evaluation framework, and a validation gate with bounded retries that lifted ConstraintScore from 85.9% to 99.5%.

LLMQwen3-4BLoRAMultilingualEvaluation

IaC Security & Remediation Agent

Terraform security scanner that grounds a fine-tuned code LLM in tree-sitter AST context. 91.8% detection precision, 28% fewer false positives than Checkov and tfsec, with auto-generated patches in CI.

AI SecurityTerraformTree-sitterCode LLMGitHub Actions

SmartATS — Agentic Recruitment Platform

Autonomous recruitment system across 10 domain modules. Hybrid retrieval on 768-d multilingual embeddings with HNSW in pgvector, LangChain tool-calling for candidate evaluation, and Azure telemetry for token, latency and cost tracking with ABAC masking.

LangChainFastAPIpgvectorAzureABAC
Insurance-Fraud-Detection-AI

Insurance-Fraud-Detection-AI

End-to-end tabular ML pipeline with 145 engineered features. Leakage-safe SMOTE + XGBoost lifted fraud recall by 46.6pp (18.4% → 65.0%) at 0.840 ROC-AUC, served through a Streamlit threshold UI behind Caddy.

Machine LearningXGBoostSMOTEStreamlit
EcomoveX

EcomoveX

EcomoveX is a full-stack platform that supports eco-friendly navigation, sustainable travel habits, and environmental awareness. It helps users explore greener routes, complete sustainability missions, earn rewards, and view detailed place information powered by multiple integrated APIs.

Web App
MystW

MystW

MysteriousWorld (MystW) is a simple role-playing game (RPG) developed in C++ using Object-Oriented Programming (OOP) principles. The game utilizes the SFML library to handle graphics, audio, and in-game interactions.

Game3D Pixel
Credentials

Licenses & certifications

Certified in Cybersecurity (CC)

ISC2

In progress · 2026

Gemini Certified Student

Google

Learning Journey

Education & certification track

University of Science, VNU-HCMSep 2024 – Jun 2028 (expected)

B.S. in Information Technology · GPA 3.82 / 4.0

Specialization in Computer Networks & Telecommunications with a focus on Information Security. Academic Merit Scholarship, Jan 2025 and Jan 2026.

  • Coursework: Machine Learning, Operating Systems, Database Systems, Computer Networks, Cryptography
  • Research contributor on multilingual medical LLM summarization and IaC security tooling
Self-study trackIn progress

Certified in Cybersecurity (ISC2 CC)

Entry-level security certification covering the five ISC2 CC domains.

  • Security principles, access control and risk management
  • Network security, incident response and business continuity
Contact

Let's build something secure

Open to internships, research collaborations and conversations about applied AI or infrastructure security.

LocationHo Chi Minh City, Vietnam