OverSync: Covert and Side-Channel Attacks on Linux Synchronization System
Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes Operators
Andong Chen, Ziyi Guo#, Zhaoxuan Jin, Zhenyuan Li, Yan Chen
2026 Network and Distributed System Security (NDSS) Symposium, to appear
PatchAgent: A Practical Program Repair Agent Mimicking Human Expertise
Zheng Yu, Ziyi Guo, Yuhang Wu, Jiahao Yu, Meng Xu, Dongliang Mu, Yan Chen, Xinyu Xing
2025 USENIX Security Symposium
DARPA AI Cyber Challenge (AIxCC), Finalist, with $2 million award. [news] [our team - 42-b3yond-6ug]
CSAW Applied Research Competition, Winner in Technical Impact (2 out of 189) [news]
PatchAgent generated fixes have been merged into multiple real-world projects. [example]
Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
Ziyi Guo, Dang K Le, Zhenpeng Lin, Kyle Zeng, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé, Xinyu Xing
2024 USENIX Security Symposium
Page Spray Technique has been applied in real-world 0-Day exploitation scenarios, including Google kCTF, mobile devices (Google Pixel, and Samsung Galaxy), won the novel exploitation award. [disclosure]
CAMP: Compiler and Allocator-based Heap Memory Protection
Zhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni, Peter Dinda, Xinyu Xing
2024 USENIX Security Symposium
Cross Container Attacks: The Bewildered eBPF on Clouds
Roland Guo* and Yi He*, Yunlong Xing, Xijia Che, Kun Sun, Zhuotao Liu, Ke Xu, Qi Li
2023 USENIX Security Symposium
Cross Container Attack has been integrated into eBPF Security Threat Model by Linux Foundation. [PDF]