We provide below links to academic research papers publications which mention grsecurity and/or PaX. If the full text PDF of the publication was not available, a link to its abstract is given. If you know of, or are the author of a research paper which should be included here, please contact me.
8. Address obfuscation: An efficient approach to combat a broad range of memory error exploits, 2003
11. A Methodology for Designing Countermeasures Against Current and Future Code Injection Attacks, 2005
20. Secure computing: SELinux, 2007
21. Attacking Signed Binaries, 2005
22. Distributed control enabling consistent MAC policies and IDS based on a meta-policy approach, 2006
23. Formalisation et garantie de propriétés de sécurité système: application à la détection d'intrusions, 2007
34. A novel approach for distributed updates of MAC policies using a meta-protection framework, 2004
37. Playing with ptrace() for fun and profit, 2006
44. Alternative Xbox copy protection designs, 2005
50. Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities, 2008
55. Improved Network Security and Disguising TCP/IP Fingerprint through Dynamic Stack Modification, 2005
62. Reverse Stack Execution, 2007
63. Secure and practical defense against code-injection attacks using software dynamic translation, 2006
80. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86), 2007
87. Data space randomization, 2008
88. The Evolution of System-Call Monitoring, 2008
98. Hardened OS exploitation techniques, 2004
103. Address space layout permutation (ASLP): Towards fine-grained randomization of commodity software, 2006
104. Bezoar: Automated Virtual Machine-based Full-System Recovery from Control-Flow Hijacking Attacks, 2007
106. Binary rewriting and call interception for efficient runtime protection against buffer overflows, 2006
108. Randomized instruction set emulation, 2005
109. Implementation vulnerabilities and detection, 2007
110. Proactive Obfuscation, 2009
112. An Integrated Framework for Dependable and Revivable Architectures Using Multicore Processors, 2006
121. Breaking the memory secrecy assumption, 2009
122. Security by Design, 2009
125. Specification and evaluation of polymorphic shellcode properties using a new temporal logic, 2009
127. Protecting Xen hypercalls, 2009
131. Surgically returning to randomized lib (c), 2009
135. Program Differentiation, 2010
146. Light-weight bounds checking, 2012
152. Secure sandboxing solution for GNU/Linux, 2011
158. An Information Flow Approach for Preventing Race Conditions: Dynamic Protection of the Linux OS, 2011
163. RIPE: runtime intrusion prevention evaluator, 2011
165. Knowledge Base Model for the Linux Kernel, 2011
168. Q: Exploit Hardening Made Easy, 2011
170. Exploiting the Hard-Working DWARF: Trojan and Exploit Techniques Without Native Executable Code, 2011
171. Privilege escalation attacks on Android, 2011
172. Revisiting address space randomization, 2011
175. Effectiveness of Moving Target Defenses, 2011
184. Faults in Linux: Ten years later, 2011
187. Detecting polymorphic threats [patent], 2010
189. Dynamic out-of-process software components isolation for trustworthiness execution [patent], 2009
193. System and method for monitoring interactions between application programs and data stores [patent], 2010
198. Evaluation of Linux Security Frameworks, 2010
202. OverCovert: Using Stack-Overflow Software Vulnerability to Create a Covert Channel [abstract], 2011
204. Compiler-Generated Software Diversity, 2011
207. Spy vs. Spy: counter-intelligence methods for backtracking malicious intrusions [abstract], 2011
222. Security Systems Design and Analysis Using an Integrated Rule-Based Systems Approach [abstract], 2005
226. Design and Implementation of an Extended Reference Monitor for Trusted Operating Systems [abstract], 2006
229. Return Address Randomization Scheme for Annuling Data-Injection Buffer Overflow Attacks [abstract], 2006
232. A Theory of Secure Control Flow [abstract], 2005
236. Linux 2.6 kernel exploits [abstract], 2007
237. A Policy Language for the Extended Reference Monitor in Trusted Operating Systems [abstract], 2007
238. Intrusion detection and security policy framework for distributed environments [abstract], 2005
240. Towards the specification of access control policies on multiple operating systems [abstract], 2004
242. A Collaborative Approach for Access Control, Intrusion Detection and Security Testing [abstract], 2006
246. Model-driven configuration of os-level mandatory access control: research abstract [abstract], 2008