When I started reading on BPF there weren’t many academic papers to describe how it worked, how it didn’t, or how it is used.
There are many blog posts and informal articles out there, but it’s harder to find self-contained papers with references to older, sometimes unsuspected, related works.
They have become more frequent though, so I wanted to draw up a list with one-sentence summaries for anyone looking for related works or otherwise interested.
I expect this list to only grow with time.
If I want to keep things manageable, I need a way to select papers.
Except I’d rather not be the one having to decide which papers are the “best papers”1.
So I opted to follow the selection from CSRankings: I will only list papers from conference listed by CSRankins by default.
CSRankins tends to put the bar fairly high, but I think there is at least consensus on the top conferences they selected.
I’ve sorted papers according to their type of contribution and the field or area they focus on.
For example, papers improving either the JIT compilers or verifier of eBPF will have improving, jit, and verifier
(see those papers).
If you notice any bug in the selectors, missing papers, or other opportunity for improvement, as usual, don’t hesitate to reach out via one of the contacts at the bottom of the page.
Type selector
Areas selector
Selected 64 papers.
SoK: Challenges and Paths Toward Memory Safety for eBPF
S&P'25 PaperK. Huang, J. Sampson, M. Payer, G. Tan, Z. Qian, T. Jaeger analysissecurityverifier
Surveys and evaluates existing work on eBPF memory safety.
SwiftSweeper: Defeating Use-After-Free Bugs Using Memory Sweeper Without Stop-the-World
S&P'25 PaperJ. Ahn, K. Lee, C. Park, H. Moon, Y. Kwon usingmiscsecurity
Designs a memory-sweeping allocator to prevent use-after-free bugs, with a BPF-based custom page fault handler to improve performance.
eBPF Misbehavior Detection: Fuzzing with a Specification-Based Oracle
SOSP'25 PaperT. Lyu, K. K. Dwivedi, T. Bourgeat, M. Payer, M. Xu, S. Kashyap improvingverifier
Introduces a specification-based oracle to fuzz the BPF verifier.
FlexGuard: Fast Mutual Exclusion Independent of Subscription
SOSP'25 PaperV. Laforet, S. Kashyap, C. Iorgulescu, J. Lawall, J.-P. Lozi usingmisc
Improves lock handover time by using eBPF to detect critical section preemptions.
cache_ext: Customizing the Page Cache with eBPF
SOSP'25 PaperT. Zussman, I. Zarkadas, J. Carin, A. Cheng, H. Franke, J. Pfefferle, A. Cidon usingmisc
Extends the kernel with new BPF hooks, kfuncs, and per-cgroup struct_ops to be able to customize the page cache policies.
SIGCOMM'25 Paper TalkT. Pan, E. Song, Y. Zuo, S. Zhang, Y. Song, J. Zhao, W. Hou, J. Lu, X. Sun, S. Zhang, Y. Yang, J. Zhang, T. Huang, B. Lyu, X. Li, R. Wen, Z. Zong, S. Zhu usingnetworking
Improves the performance of their L7 load balancer by customizing the kernel's connection dispatch using sk_reuseport BPF programs.
Extending Applications Safely and Efficiently
OSDI'25 Paper TalkY. Zheng, T. Yu, Y. Yang, Y. Hu, X. Lai, D. Williams, A. Quinn usingtracingmisc
Proposes to implement safe userspace extension mechanisms and observability tools using the bpftime userspace eBPF VM for better efficiency.
Rex: Closing the language-verifier gap with safe and usable kernel extensions
ATC'25 Paper TalkJ. Jia, R. Qin, M. Craun, E. Lukiyanov, A. Bansal, M. Phan, M. V. Le, H. Franke, H. Jamjoom, T. Xu, D. Williams improvingverifier
Reduces false positives by replacing the verifier by a language-based safety approach, with the Rust compiler and runtime checks.
Accelerating Nested Virtualization with HyperTurtle
ATC'25 Paper TalkO. B. Zur, J. Krebs, S. A. Bergman, M. Silberstein usingmisc
Improves nested virtualization performance by offloading logic from the guest hypervisor to the host hypervisor using eBPF.
PageFlex: Flexible and Efficient User-space Delegation of Linux Paging Policies with eBPF
ATC'25 Paper TalkA. Yelam, K. Wu, Z. Guo, S. Yang, R. Shashidhara, W. Xu, S. Novakovic, A. C. Snoeren, K. Keeton usingmisc
Extends the kernel, including with new writable tracepoints, to allow users to customize paging policies.
VEP: A Two-stage Verification Toolchain for Full eBPF Programmability
NSDI'25 Paper TalkX. Wu, Y. Feng, T. Huang, X. Lu, S. Lin, L. Xie, S. Zhao, Q. Cao improvingverifier
Implements a proof-carrying code process for the verification of eBPF using annotations on the C source code.
eTran: Extensible Kernel Transport with eBPF
NSDI'25 Paper TalkZ. Chen, Q. Meng, C. Lao, Y. Liu, F. Ren, M. Yu, Y. Zhou usingnetworking
Designs a framework based on AF_XDP and new networking hooks to allow users to implement custom transport protocols on top of Linux.
NSDI'25 Paper TalkQ. Xu, S. Miano, X. Gao, T. Wang, A. Murugadass, S. Zhang, A. Sivaraman, G. Antichi, S. Narayana usingnetworking
Proposes a method to scale the processing of single-flow traffic on multiple cores using XDP.
BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from Kernel
Sec'24 Paper TalkJ. Ahn, J. Lee, K. Lee, W. Gwak, M. Hwang, Y. Kwon usingmiscsecurity
Designs a one-time allocator to detect use-after-free bugs, with a BPF-based custom page fault handler to improve performance.
BeeBox: Hardening BPF Against Transient Execution Attacks
Sec'24 Paper TalkD. Jin, A. J. Gaidis, V. P. Kemerlis improvingverifiersecurity
Combines the verifier's static analysis with SFI-like runtime checks and memory copies to mitigate transient execution attacks.
Toss a Fault to BpfChecker: Revealing Implementation Flaws for eBPF runtimes with Differential Fuzzing
CCS'24 PaperC. Peng, M. Jiang, L. Wu, Y. Zhou improvingverifierjit
Designs a fuzzer for userspace eBPF runtimes, including Windows's, using differential fuzzing, verifier logs, and an intermediate representation of the eBPF bytecode.
NetEdit: An Orchestration Platform for eBPF Network Functions at Scale
SIGCOMM'24 Paper TalkT. A. Benson, P. Kannan, P. Gupta, B. Madhavan, K. S. Arora, J. Meng, M. Lau, A. Dhamija, R. Krishnamurthy, S. Sundaresan, N. Spring, Y. Zhang usingnetworking
Describes an orchestration system for eBPF programs designed to tune the network stack of Meta's services.
Merlin: Multi-tier Optimization of eBPF Code for Performance and Compactness
ASPLOS'24 Paper TalkJ. Mao, H. Ding, J. Zhai, S. Ma usingmisc
Proposes new compiler optimization tailored to the eBPF bytecode.
DINT: Fast In-Kernel Distributed Transactions with eBPF
NSDI'24 Paper TalkY. Zhou, X. Xiang, M. Kiley, S. Dharanipragada, M. Yu usingnetworkingoffload
Designs a new distributed transaction system that offloads common operations to tc and XDP.
BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low Energy
CCS'24 PaperX. Che, Y. He, X. Feng, K. Sun, K. Xu, Q. Li usingsecuritymisc
Proposes to use a userspace eBPF VM to facilitate the distribution of security patches to Bluetooth Low Energy (BLE) devices, to mitigate session-based attacks.
SeaK: Rethinking the Design of a Secure Allocator for OS Kernel
Sec'24 Paper TalkZ. Wang, Y. Guang, Y. Chen, Z. Lin, M. Le, D. K Le, D. Williams, X. Xing, Z. Gu, H. Jamjooml usingsecuritymisc
Builds a secure allocator for the kernel, to separate security-sensitive objects, using new BPF helpers.
Rethinking Process Management for Interactive Mobile Systems
MobiCom'24 PaperJ. Zheng, Z. Li, F. Qian, W. Liu, H. Lin, Y. Liu, T. Xu, N. Zhang, J. Wang, C. Zhang usingmisc
Leverages eBPF to measure the usage of hardware resources by Android applications and investigate slow UI responsiveness problems.
MegaTE: Extending WAN Traffic Engineering to Millions of Endpoints in Virtualized Cloud
SIGCOMM'24 Paper TalkC. Miao, Z. Zhong, Y. Xiao, F. Yang, S. Zhang, Y. Jiang, Z. Bai, C. Lu, J. Geng, Z. He, Y. Wang, X. Zou, C. Yang usingnetworking
Relies on eBPF to identify traffic sources and enforce traffic engineering via segment routing across the WAN.
FetchBPF: Customizable Prefetching Policies in Linux with eBPF
ATC'24 Paper TalkX. Cao, S. Patel, S. Y. Lim, X. Han, T. Pasquier usingmisc
Extends the kernel with new BPF hooks and helpers to be able to customize memory prefetching policies.
Validating the eBPF Verifier via State Embedding
OSDI'24 Paper TalkH. Sun, Z. Su improvingverifier
Devises a test oracle to fuzz the eBPF verifier by embedding correctness checks in the BPF program.
Hive: A Hardware-assisted Isolated Execution Environment for eBPF on AArch64
Sec'24 Paper TalkP. Zhang, C. Wu, X. Meng, Y. Zhang, M. Peng, S. Zhang, B. Hu, M. Xie, Y. Lai, Y. Kang, Z. Wang improvingverifiersecurity
Proposes to replace the static analysis of the verifier with a hardware-based runtime isolation for ARM64.
End-to-End Mechanized Proof of a JIT-Accelerated eBPF Virtual Machine for IoT
CAV'24 PaperS. Yuan, F. Besson, and J.-P. Talpin improvingjit
Correctness proof for the eBPF JIT compiler used in the micro-controller RIOT kernel.
Fast, Flexible, and Practical Kernel Extensions
SOSP'24 PaperK. K. Dwivedi, R. Iyer, S. Kashyap improvingverifier
Extends the Linux verifier with limited runtime checks and in a backward compatible way, significantly improving eBPF's expressibility.
MOAT: Towards Safe BPF Kernel Extension
Sec'24 Paper TalkH. Lu, S. Wang, Y. Wu, W. He, F. Zhang improvingverifiersecurity
Hardens eBPF in Linux by leveraging Intel MPK and adding runtime checks for helpers.
Cross Container Attacks: The Bewildered eBPF on Clouds
Sec'23 Paper TalkY. He, R. Guo, Y. Xing, X. Che, K. Sun, Z. Liu, K. Xu, Q. Li analysissecurity
Highlights that eBPF tracing programs can be used to escape container boundaries and the impact on cloud and online coding platforms.
λ-IO: A Unified IO Stack for Computational Storage
FAST'23 Paper TalkZ. Yang, Y. Lu, X. Liao, Y. Chen, J. Li, S. He, J. Shu usingstorage
Modifies eBPF to implement a unified IO stack spanning the kernel and storage devices, in the context of in-storage computing.
eHDL: Turning eBPF/XDP Programs into Hardware Designs for the NIC
ASPLOS'23 Paper TalkA. Rivitti, R. Bifulco, A. Tulumello, M. Bonola, S. Pontarelli usingnetworking
Introduces a synthesis tool that generates FPGA pipelines for NICs from unmodified XDP programs.
Fuzz on the Beach: Fuzzing Solana Smart Contracts
CCS'23 PaperS. Smolka, J.-R. Giesen, P. Winkler, O. Draissi, L. Davi, G. Karame, K. Pohl improvingsecuritymisc
Fuzzes Solana smart contracts, including those compiled to eBPF bytecode, by extending Solana's userspace eBPF VM with six bug oracles and coverage feedback.
xBGP: Faster Innovation in Routing Protocols
NSDI'23 Paper TalkT. Wirtgen, T. Rousseaux, Q. De Coninck, N. Rybowski, R. Bush, L. Vanbever, A. Legay, O. Bonaventure usingnetworking
Designs an extension mechanism for BGP using a userspace implementation of eBPF and several C verification tools to replace and extend the Linux verifier.
Taking 5G RAN Analytics and Control to a New Level
MobiCom'23 PaperX. Foukas, B. Radunovic, M. Balkwill, Z. Lai usingnetworking
Proposes to extend virtualized Radio Access Network (vRAN) functions using a userspace BPF implementation and the PREVAIL verifier, with a new runtime check to bound the execution time.
Network-Centric Distributed Tracing with DeepFlow: Troubleshooting Your Microservices in Zero Code
SIGCOMM'23 Paper TalkJ. Shen H. Zhang, Y. Xiang, X. Shi, X. Li, Y. Shen, Z. Zhang, Y. Wu, X. Yin, J. Wang, M. Xu, Y. Li, J. Yin, J. Song, Z. Li, R. Nie usingtracing
Presents a distributed tracing framework for troubleshooting microservices that leverages eBPF for data collection.
Tigger: A Database Proxy That Bounces with User-Bypass
VLDB'23 PaperM. Butrovich, K. Ramanathan, J. Rollinson, W. S. Lim, W. Zhang, J. Sherry, A. Pavlo usingnetworkingoffload
Offloads PostgreSQL connection pooling and mirroring to the kernel using sockmap BPF programs.
Electrode: Accelerating Distributed Protocols with eBPF
NSDI'23 Paper TalkY. Zhou, Z. Wang, S. Dharanipragada, M. Yu usingnetworkingoffload
Offloads common Paxos networking operations to tc and XDP to improve performance.
Verifying the Verifier: eBPF Range Analysis Verification
CAV'23 PaperH. Vishwanathan, M. Shachnai, S. Narayana, S. Nagarakatte improvingverifier
Automatically and formally proves the ranges analysis of the Linux verifier.
EPF: Evil Packet Filter
ATC'23 Paper TalkD. Jin, V. Atlidakis, V. P. Kemerlis analysissecurity
Presents an approach to bypass various kernel isolation techniques by abusing the cBPF infrastructure.
Domain Specific Run Time Optimization for Software Data Planes
ASPLOS'22 Paper TalkS. Miano, A. Sanaee, F. Risso, G. Rétvári, G. Antichi usingnetworking
Optimizes datapath binaries, including eBPF bytecodes, based on traffic patterns.
End-to-end Mechanized Proof of an eBPF Virtual Machine for Micro-controllers
CAV'22 PaperS. Yuan, F. Besson, J.-P. Talpin, S. Hym, K. Zandberg, E. Baccelli improvingverifier
Correctness proof for the eBPF interpreter and verifier used in the micro-controller RIOT kernel.
OSDI'22 Paper TalkS. Park, D. Zhou, Y. Qian, I. Calciu, T. Kim, S. Kashyap usingmisc
Allows Linux users to customize kernel lock policies using eBPF and according to the applications' needs and hardware characteristics.
RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices
Sec'22 Paper TalkY. He, Z. Zou, K. Sun, Z. Liu, K. Xu, Q. Wang, C. Shen, Z. Wang, Q. Li usingmisc
Implements a hotpatching mechanism for real-time OSes using eBPF, a modified verifier, and additional runtime checks.
SPRIGHT: Extracting the Server from Serverless Computing! High-Performance eBPF-Based Event-Driven, Shared-Memory Processing
SIGCOMM'22 Paper TalkS. Qi, L. Monis, Z. Zeng, I.-C. Wang, K. K. Ramakrishnan usingnetworking
Leverages various eBPF hooks to improve the performance of Knative, a container-based serverless platform.
Faster Software Packet Processing on FPGA NICs with eBPF Program Warping
ATC'22 Paper TalkM. Bonola, G. Belocchi, A. Tulumello, M. Spaziani Brunella, G. Siracusano, G. Bianchi, R. Bifulco usingnetworking
Improves the performance of hXDP, an eBPF processor for FPGA NICs, via peephole optimization, thereby replacing series of instructions with optimized hardware implementations.
XRP: In-Kernel Storage Functions with eBPF
OSDI'22 Paper TalkY. Zhong, H. Li, Y. J. Wu, I. Zarkadas, J. Tao, E. Mesterhazy, M. Makris, J. Yang, A. Tai, R. Stutsman, A. Cidon usingstorageoffload
Offloads processing to the NVMe drivers using BPF, to reduce kernel overhead in storage applications
Sound, Precise, and Fast Abstract Interpretation with Tristate Numbers
CGO'22 Paper TalkH. Vishwanathan, M. Shachnai, S. Narayana, S. Nagarakatte improvingverifier
Formally proves and improves the Linux verifier operations on tristate numbers for the range analysis.
Synthesizing Safe and Efficient Kernel Extensions for Packet Processing
SIGCOMM'21 Paper TalkQiongwen Xu, M. D. Wong, T. Wagle, S. Narayana, A. Sivaraman usingnetworking
Proposes a synthesis-based compiler that optimizes eBPF programs while ensuring they still pass the Linux verifier.
BMC: Accelerating Memcached using Safe In-Kernel Caching and Pre-Stack Processing
NSDI'21 Paper Talk SummaryY. Ghigoff, J. Sopena, K. Lazri, A. Blin, G. Muller usingnetworkingoffload
Speeds up Memcached with an XDP-based, transparent, first-level cache.
An Analysis of Speculative Type Confusion Vulnerabilities in the Wild
Sec'21 Paper TalkO. Kirzner, A. Morrison analysissecurity
Describes how eBPF can be leveraged to create speculative type confusion gadgets in the kernel.
Syrup: User-Defined Scheduling Across the Stack
SOSP'21 Paper TalkK. Kaffes, J. Humphries, D. Mazières, C. Kozyrakis usingnetworking
Proposes an eBPF-based framework to enable users to write application-specific scheduling policies for threads, network packets, and network connections.
Revisiting the Open vSwitch Dataplane Ten Years Later
SIGCOMM'21 PaperW. Tu, Y.-H. Wei, G. Antichi, B. Pfaff usingnetworking
Describes how production experience with Open vSwitch over a decade led to the development of its new AF_XDP-based datapath.
Synthesizing JIT Compilers for In-Kernel DSLs
CAV'20 PaperJ. Van Geffen, L. Nelson, I. Dillig, X. Wang, E. Torlak improvingjit
Synthesizes eBPF and cBPF JIT compilers, which are proven to be formally correct, from DSL interpreters.
hXDP: Efficient Software Packet Processing on FPGA NICs
OSDI'20 Paper Talk SummaryM. Spaziani Brunella, G. Belocchi, M. Bonola, S. Pontarelli, G. Siracusano, G. Bianchi, A. Cammarano, A. Palumbo, L. Petrucci, R. Bifulco usingnetworking
Investigates the execution of XDP programs on FPGA NICs by implementing an interpreter.
Specification and Verification in the Field: Applying Formal Methods to BPF Just-in-Time Compilers in the Linux Kernel
OSDI'20 Paper TalkL. Nelson, J. Van Geffen, E. Torlak, X. Wang improvingjit
Applies formal verification techniques to the eBPF JIT compilers and implements a new formally-verified JIT compiler for 32-bit RISC-V.
Scaling Symbolic Evaluation for Automated Verification of Systems Code with Serval
SOSP'19 PaperL. Nelson, J. Bornholt, R. Gu, A. Baumann, E. Torlak, X. Wang improvingverifier
Proposes a framework to developing verifiers for system software, including eBPF, by lifting existing interpreters under symbolic execution.
Extension Framework for File Systems in User Space
ATC'19 Paper TalkA. Bijlani, U. Ramachandran usingstorageoffload
Enables eBPF support in the FUSE interface to improve the performance of user-space file systems by offloading operations to the kernel.
Pluginizing QUIC
SIGCOMM'19 PaperQ. De Coninck, F. Michel, M. Piraux, F. Rochet, T. Given-Wilson, A. Legay, O. Pereira, O. Bonaventure usingnetworking
Designs an extension mechanism for QUIC using a userspace implementation of eBPF with SFI-like runtime checks.
Simple and Precise Static Analysis of Untrusted Linux Kernel Extensions
PLDI'19 Paper Talk SummaryE. Gershuni, N. Amit, A. Gurfinkel, N. Narodytska, J. A. Navas, N. Rinetzky, L. Ryzhyk, M. Sagiv improvingverifier
Introduces PREVAIL, an alternative to the Linux eBPF verifier based on abstract interpretation and now used in Windows.
The Design and Implementation of Hyperupcalls
ATC'18 PaperN. Amit, M. Wei usingmisc
Leverages eBPF to bridge the semantic gap of virtualization, by letting hypervisors execute verified code from the guests.
Jitk: A Trustworthy In-Kernel Interpreter Infrastructure
OSDI'14 Paper TalkX. Wang, D. Lazar, N. Zeldovich, A. Chlipala, Z. Tatlock improvingjit
Proposes a formally-verified infrastructure to compile high-level rules into cBPF bytecode and machine code.
Safe Kernel Extensions Without Run-Time Checking
OSDI'96 PaperG. C. Necula, P. Lee improvingverifier
Proposes kernel extensions in the form of proof-carrying code and compares it to cBPF.
The BSD Packet Filter: A New Architecture for User-level Packet Capture
USENIX Winter'93 PaperS. McCanne, V. Jacobson foundationnetworking
The original cBPF paper, describing a register-based packet filter for BSD.
Thanks to Kahina for her reviews and for reporting multiple bugs with the early version of the selectors.
Of course, I can’t really escape chosing a method to select papers, so it’s not as if this is completely objective either. ↩