The issue is solved but not perfect.
The client update virus pattern because the SEPM push the update virus pattern whenever the SEPM had completed the virus update.
Then, the client receive the virus pattern and do the action scan.
Nothing we can do in setting as it is designed behaviour.
We changed the SEPM to update once daily rather than every 4 hours to minimize the impact.
Thanks for your help!
Best Regards,
Ivan