Ziyi Guo(Roland Guo) [Gallery] Department of Computer Science, Northwestern University, Evanston, IL, USA. |
[2024.08] Our Team 42-b3yond-6ug won DARPA's AIxCC SemiFinal at DEFCON 32, awarded $2 million. [link]
[2024.07] Awarded Student Grant from USENIX Security'24
[2024.06] Page Spray is accepted by USENIX Security 2024. [link]
I'm a 2nd year CS Ph.D. student at Northwestern University. I work with Prof.Yan Chen, Prof.Xinyu Xing. Before joining in Northwestern, I had a great research experience at NISL in Tsinghua University, advised by Prof.Qi Li.
I'm broadly interested in those realworld security problems, hidden in various software and systems. I'm also a CTFer @r3kapig, focus on vulnerability exploitation (Pwn).
I also design and develop AI / LLM agent to improve the security and reliability for real-world software and systems.
(USENIX Security '25) PatchAgent: A Practical Program Repair Agent Mimicking Human Expertise. [link]
Zheng Yu, Ziyi Guo, Yuhang Wu, Jiahao Yu, Meng Xu, Dongliang Mu, Yan Chen, Xinyu Xing
(USENIX Security '24) Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation. [link]
Ziyi Guo, Dang K Le, Zhenpeng Lin, Kyle Zeng, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé, Xinyu Xing
Page Spray has been applied in realworld 0-day exploitation: CLOCK_THREAD_CPUTIME_ID LPE
(USENIX Security '24) CAMP: Compiler and Allocator-based Heap Memory Protection. [link]
Zhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni, Peter Dinda, Xinyu Xing
(USENIX Security '23) Cross Container Attacks: The Bewildered eBPF on Clouds. [link]
Yi He* and Roland Guo*, Yunlong Xing, Xijia Che, Kun Sun, Zhuotao Liu, Ke Xu, Qi Li
* indicates co-first author
C.C.A has been acknowledged and included in eBPF Security Threat Model
Finalist (top 7 worldwide), DARPA AIxCC
- Finalist [Press]
Finalist, DEFCON 30 CTF in 2022.
- Team r3kapig
Finalist, DEFCON 29 CTF in 2021.
- Team r3kapig
1st Prize, WMCTF 2020.
- Team 0x401
UNIQLO Scholarship Awardee in 2021. (0.05% in Sichuan University)
Tsinghua University NISL, 2022.03 ~ 2023.05
Research Intern, advised by Prof. Qi Li
Tencent Xuanwu Lab, 2021.11 ~ 2022.03
Security Researcher (Intern). Linux Kernel Vulnerability Exploitation & Container Attacks. Leader: Huiming Liu
Northwestern University
Ph.D. student, 2023.09 ~ Present.
Sichuan University
Bachelor, 2019.09 ~ 2023.08
Artifact Evaluation Program Committee(AEC): USENIX Security 2024, ISSTA 2024, USENIX Security 2025
External Reviewer: IEEE S&P 2024, IEEE S&P 2025
Department Of The Navy: DARPA AI Cyber Challenge Proves Promise of AI-Driven Cybersecurity
Northwestern University News: Safeguarding Critical Software Infrastructure through Novel AI Systems
Northwestern University News: Advancing Compiler Technology
News reports cover 42-b3yond-6ug: UWaterloo , DARPA , InfoSecurity Magazine , MeriTalk , Cyberscoop , Dark Reading , ExecutiveGov , The Readable , Science of Security , The Register
I discovered and reported many realworld vulnerabilities, such as:
[WebAssembly] CVE-2024-25431: Understanding and Mitigating the Wasm-Micro-Runtime Vulnerability
[WebAssembly] CVE-2024-27527: GitHub Advisory
[WebAssembly] CVE-2024-27528: Snyk Security Report
[WebAssembly] CVE-2024-27529: Snyk Security Report
[WebAssembly] CVE-2024-27530: Synk Security Report
[WebAssembly] CVE-2024-27532: Addressing NULL Pointer Dereference Vulnerability in Wasm-Micro-Runtime
[CI/CD] GHSA-7q92-pph9-5686: GitHub Actions expression injection vulnerability