VLDB 2026 Research / reviewers in the wild / expert
Jinmeng Zhou
dblp:179/8187
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PhantomMap: GPU-Assisted Kernel Exploitation
Jiayi Hu, Jinmeng Zhou, Wenbo Shen |
NDSS | 4 |
| 2026 | Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux SystemsabstractThe widespread deployment of control-flow integrity has shifted attackers' focus to non-control data attacks. In OS kernel exploits, attackers can gain root access or escalate privileges by corrupting critical non-control objects without hijacking the control flow. However, searching for exploitable non-control data in the OS kernel is challenging because of the data's semantic complexity and lack of universal patterns. This work represents the first study to semi-automatically discover and evaluate exploitable non-control data within the Linux kernel's file system, with minimal domain knowledge. Utilizing a custom analysis and testing framework, we identify promising candidate objects both statically and dynamically. We categorize these objects into types suitable for various exploit strategies, including a systematic strategy to overcome defenses that isolate many of these objects. These objects can be exploitable without requiring KASLR, thus making the exploits simpler and more reliable. We evaluate the exploitability of the file system objects using 18 real-world CVEs with various exploit strategies. We further develop 10 end-to-end exploits against the kernel with all state-of-the-art mitigations enabled. Jinmeng Zhou, Ziyue Pan, Jiayi Hu, Jiaxun Zhu, Wenbo Shen, Guoren Li, Zhiyun Qian |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Practical Protection Design of Forward-Edge Control-Flow Integrity for Linux KernelabstractThe operating system kernel is the security foundation for the entire system. Yet control flow hijacking is a prevalent attack method that continually threatens its security. Control-Flow Integrity (CFI) defends against these attacks by enforcing execution compliance with a pre-computed Control-Flow Graph (CFG). The kernel is very sensitive to performance overhead, challenging the CFI scheme design. The existing Clang-CFI is software-based, making it the general solution widely deployed as the de facto CFI. However, it is coarse-grained, and its CFI scheme design cannot be easily applied to fine-grained CFGs. To provide CFI for fine-grained CFG, we propose a flexible protection design, FLEX-CFI. This software-based approach enhances generality by eliminating hardware dependencies. Our CFI design is practical and applicable to various fine-grained CFGs with negligible overhead. We implemented a prototype of FLEX-CFI based on Clang/LLVM and evaluated it on the Android ARM64 Linux kernel using a real-world hardware device. The results show that FLEX-CFI effectively secures 92% of all indirect call-sites in the allyesconfig kernel configuration while reducing target functions by 93.5% and imposing close-tozero performance overhead. Jinmeng Zhou, Ziyue Pan, Xun Xie, Wenbo Shen |
ICC | 1 |
| 2024 | Interp-flow Hijacking: Launching Non-control Data Attack via Hijacking eBPF Interpretation Flow
Wenbo Shen, Jinmeng Zhou, Zhuoruo Zhang, Jiayi Hu, Shukai Ni, Kangjie Lu |
ESORICS (3) | 3 |
| 2024 | DMAAUTH: A Lightweight Pointer Integrity-based Secure Architecture to Defeat DMA Attacks
Wenbo Shen, Yujie Bu, Jinmeng Zhou, Yajin Zhou |
USENIX Security Symposium | 4 |
| 2023 | A Hybrid Alias Analysis and Its Application to Global Variable Protection in the Linux Kernel
Guoren Li, Hang Zhang 0012, Jinmeng Zhou, Wenbo Shen, Yulei Sui, Zhiyun Qian |
USENIX Security Symposium | 3 |
| 2023 | Automatic Permission Check Analysis for Linux KernelabstractPermission checks play an essential role in operating system security by providing access control to privileged functionalities. However, it is challenging for kernel developers to scalably verify the soundness of existing checks due to the large codebase and complexity of the kernel. In fact, Linux kernel contains millions of lines of code with hundreds of permission checks, and even worse its complexity is fast-growing. This paper presents PeX, a static permission check error detector for Linux, which takes as input a kernel source code and reports any missing, inconsistent, and redundant permission checks. PeX uses KIRIN (Kernel InteRface based Indirect call aNalysis), a novel, precise, and scalable indirect call analysis technique. Over the interprocedural control flow graph built by KIRIN, PeX automatically identifies permission checks and infers the mappings between permission checks and privileged functions. For each privileged function, PeX examines all possible paths to the function to check if necessary permission checks are correctly enforced. We evaluated PeX on the latest stable Linux kernel v4.18.5 for three types of permission checks: Discretionary Access Controls (DAC), Capabilities, and Linux Security Modules (LSM). PeX reported 45 new permission check errors, 17 of which have been confirmed by the kernel developers. Jinmeng Zhou, Wenbo Shen, Changhee Jung, Ahmed M. Azab, Ruowen Wang, Peng Ning, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |