Chaoyuan Chen

dblp:426/3136 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%
Software engineering, system software, and programming languages
1 paper
Operating systems · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery › fuzzing
kernel fuzzing
1.012026
Minoris: Practical Out-of-Emulator Kernel Module Fuzzing · IEEE Trans. Dependable Secur. Comput. 2026
Systems and software security
vulnerability discovery
1.012026
Minoris: Practical Out-of-Emulator Kernel Module Fuzzing · IEEE Trans. Dependable Secur. Comput. 2026
Operating systems › extensible operating systems › kernel extensibility › kernel extensions
kernel module
1.012026
Minoris: Practical Out-of-Emulator Kernel Module Fuzzing · IEEE Trans. Dependable Secur. Comput. 2026
Operating systems › kernel
linux kernel
1.012026
Minoris: Practical Out-of-Emulator Kernel Module Fuzzing · IEEE Trans. Dependable Secur. Comput. 2026

Methods — techniques the papers use, named apart from their topics

user-space memory sanitizer · 2.0out-of-emulator fuzzing · 2.0hardware-emulation library · 2.0
YearPublicationVenuePosition
2026 Minoris: Practical Out-of-Emulator Kernel Module Fuzzing
abstract
Vulnerabilities in the Linux kernel can be exploited to perform privilege escalation and take over the whole system. Fuzzing has been leveraged to detect Linux kernel vulnerabilities during the last decade. However, existing kernel fuzzing techniques highly use QEMU/KVM as the underlying infrastructure, thus suffering from unnecessary costs due to user-kernel context switch and kernel-emulator context switch. This degrades the fuzzing performance. In this paper, we propose a kernel module fuzzing framework namedMinoris. It moves the kernel module under testing (KMUT) out of both real kernel and emulator, thus eliminating unnecessary context switches. However, implementing such a system requires solving the dependency challenges. We solve these challenges by automatically linking kernel module with LKL, and performing initialization functions on-demand to prepare the required status. Besides, a hardware-emulation library is proposed to provide underlying hardware support. Our system not only improves the fuzzing speed but also can easily integrate mature fuzzing techniques, such as user-space memory sanitizer. We evaluateMinorison five different KMUTs. Compared with the state-of-the-art solution,Minorisachieves an average execution speedup from ×3.31 to ×7.38. It improves the fuzzing throughput (×102.58), explores more code coverage ($89.51\%$more branches), and detects 6 new bugs.
Yangxi Xiang, Qiang Liu 0034, Haoyu Wang 0001, Jiashui Wang, Lei Wu 0012, Chaoyuan Chen, Yajin Zhou
IEEE Trans. Dependable Secur. Comput.8