Research
My research focuses on Operating System Kernel Security, specifically in the areas of kernel vulnerabilities prevention and isolation/compartmentalization techniques. Recently I am researching on eBPF—an innovative in-kernel virtual machine—and its integration with AI models, to enhance both the security and performance aspects of the kernel. Currently, I am particularly interested in data-driven performance optimization in operating systems and applying machine learning techniques to improve system performance.
In the News
Reconsidering the Multi-Generational LRU
A discussion on the future of MGLRU in the Linux kernel—the alternative memory reclamation mechanism that uses multiple generations to decide which memory pages to keep in RAM. The article covers the challenges, maintenance status, and path forward for this critical kernel subsystem, to be discussed at the 2026 Linux Storage, Filesystem, Memory-Management and BPF Summit.
Experience
-
2024 – now
Honor Device
Senior Operating System Engineer -
2023 – 2024
University of Colorado Boulder
Visiting Scholar, Computer Science DepartmentAdvisor: Prof. Yueqi Chen -
2018 – 2024
Nanjing University
Ph.D., State Key Lab for Novel Software TechnologyAdvisor: Prof. Qingkai Zeng · Outstanding Ph.D. Graduate -
2014 – 2018
Jilin University
B.Sc., College of Software EngineeringCum Laude
Publications
-
Ph.D. Thesis, 2024Outstanding Ph.D. Thesis, NJU CS Department
-
USENIX Security Symposium (Security), 2024
-
USENIX Security Symposium (Security), 2023NJU International Conference Funding
-
BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKSNetwork and Distributed System Security (NDSS), 2025
-
BlackHat USA 2024 Briefing · Linux Security Summit Europe 2024
-
An Infrastructure For Preventing Compromise of Operating System Kernels Due to Discovered ErrorsProvisional US Patent Application No.: 63/464,887
-
arXiv:2401.05641
-
BlackHat USA 2023 Briefing
-
Linux Security Summit North America, 2023Linux Foundation $1,600 Travel Fund
-
软件学报, 2023
-
Annual Computer Security Applications Conference (ACSAC), 2022
-
AttnCall: Refining Indirect Call Targets in Binaries with AttentionEuropean Symposium on Research in Computer Security (ESORICS), 2023
-
ICT Systems Security and Privacy Protection (ICT SEC), 2022
-
中国Linux内核开发者大会 (CLK), 2022
-
第三届 eBPF开发者大会, 2025
-
Evolving Beyond Pressure: RL-enhanced Camera Launch for Resource-Critical Scenarios4th Workshop on Practical Adoption Challenges of ML for Systems (PACMI '25)
-
Data Knows What the App Needs: An Intelligent Resource Watermark for Mobile Systems4th Workshop on Practical Adoption Challenges of ML for Systems (PACMI '25)
Awards
- Nanjing University Outstanding Ph.D. Graduate
- Nanjing University Outstanding Graduate Student
- 2023 Nanjing University Funding for International Academic Conferences
- Linux Foundation $1,600 Travel Funding
Teaching Assistant
- Advanced Object Oriented Programming, 2018 Fall
- Assembly Programming, 2019 Summer
Services
- Peer Review: IEEE Transactions on Information Forensics and Security
Open Source
SeaK
Rethinking the Design of a Secure Allocator for OS Kernel
O2C
On-the-fly compartmentalization for kernel vulnerabilities
ERA
eBPF assisted Randomization Allocator to prevent kernel heap vulnerabilities
PET
eBPF framework to prevent discovered errors from being triggered
TA-BattleEinsteinChess
Einstein Chess Battle Server, supports 200+ players
CCFrank4dblp
Displays CCF rank of conferences and journals with ConnectedPapers support