Ziyi Guo(Roland Guo) [Gallery] Northwestern University, Evanston, IL, USA. |
[2024.08] Our Team 42-b3yond-6ug won DARPA's AIxCC SemiFinal at DEFCON 32, awarded $2 million. [link]
[2024.07] Awarded Student Grant from USENIX Security'24
[2024.06] Page Spray is accepted by USENIX Security 2024. [link]
[2024.02] Our Team 42-b3yond-6ug won $1 million from DARPA's Artificial Intelligence Cyber Challenge(AIxCC), top 7 in the world. I learn a lot from Professors and Mates! [link]
I'm a 2nd year Ph.D. Student at Northwestern University, Computer Science. I work with Prof.Yan Chen, Prof.Xinyu Xing.
Before joining in Northwestern CS, I had a great research experience with Prof.Qi Li at TsingHua University.
I'm broadly interested in those realworld security problems, hidden in various software and systems.
I'm also a CTFer, focus on Vulnerability Exploitation (Especially Linux Kernel) & Reverse Engineering.
Northwestern University
CS PhD student, 2023 ~ Present.
Sichuan University
Bachelor in Cybersecurity, 2019 ~ 2023
Guiding Large Language Models Repair Realworld Bugs. [Link]
Under Review
Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation. [Link]
Ziyi Guo, Dang K Le, Zhenpeng Lin, Kyle Zeng, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé, Xinyu Xing
USENIX Security 2024
CAMP: Compiler and Allocator-based Heap Memory Protection. [Link]
Zhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni, Peter Dinda, Xinyu Xing
USENIX Security 2024
Cross Container Attacks: The Bewildered eBPF on Clouds. [Link]
Yi He* and Roland Guo*, Yunlong Xing, Xijia Che, Kun Sun, Zhuotao Liu, Ke Xu, Qi Li
USENIX Security 2023
* indicates co-first author
Our Attack has been acknowledged and included into eBPF Security Threat Model by Linux Foundation.
World Finalist, DARPA AI Cyber Challenge(AIxCC)
- Winner of Semi-Final.
- Core member of Northwestern 42-b3yond-6ug.
- DARPA News: "DARPA AI Cyber Challenge Proves Promise of AI-Driven Cybersecurity"
World Finalist, DEFCON 30 CTF in 2022.
- Team r3kapig
World Finalist, DEFCON 29 CTF in 2021.
- Team r3kapig
1st Prize, WMCTF 2020.
- Team 0x401
UNIQLO Scholarship Awardee in 2021.
Tencent Security Xuanwu Lab
Security Researcher. Linux Kernel Vulnerability Exploitation & Container Attacks.
Tsinghua University, Network and Information Security Lab
Research Intern, with Prof. Qi Li
Artifact Evaluation Program Committee(AEC): USENIX Security 2024, ISSTA 2024, USENIX Security 2025
External Reviewer: IEEE S&P 2024, IEEE S&P 2025
Safeguarding Critical Software Infrastructure through Novel AI Systems
News reports cover 42-b3yond-6ug: UWaterloo , DARPA , InfoSecurity Magazine , MeriTalk , Cyberscoop , Dark Reading , ExecutiveGov , The Readable , Science of Security , The Register
I wrote some tech blogs for people who want to learn vulnerability exploitation in Kanxue
I discovered and reported many realworld vulnerabilities, such as:
CVE-2024-25431
CVE-2024-27527
CVE-2024-27528
CVE-2024-27529
CVE-2024-27530
CVE-2024-27532