We provide below links to academic research papers publications which mention grsecurity and/or PaX. If the full text PDF of the publication was not available, a link to its abstract is given. If you know of, or are the author of a research paper which should be included here, please contact me.
7. Address obfuscation: An efficient approach to combat a broad range of memory error exploits, 2003
10. A Methodology for Designing Countermeasures Against Current and Future Code Injection Attacks, 2005
19. Secure computing: SELinux, 2007
20. Attacking Signed Binaries, 2005
21. Distributed control enabling consistent MAC policies and IDS based on a meta-policy approach, 2006
22. Formalisation et garantie de propriétés de sécurité système: application à la détection d'intrusions, 2007
33. A novel approach for distributed updates of MAC policies using a meta-protection framework, 2004
36. Playing with ptrace() for fun and profit, 2006
43. Alternative Xbox copy protection designs, 2005
49. Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities, 2008
54. Improved Network Security and Disguising TCP/IP Fingerprint through Dynamic Stack Modification, 2005
61. Reverse Stack Execution, 2007
62. Secure and practical defense against code-injection attacks using software dynamic translation, 2006
79. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86), 2007
86. Data space randomization, 2008
87. The Evolution of System-Call Monitoring, 2008
97. Hardened OS exploitation techniques, 2004
102. Address space layout permutation (ASLP): Towards fine-grained randomization of commodity software, 2006
103. Bezoar: Automated Virtual Machine-based Full-System Recovery from Control-Flow Hijacking Attacks, 2007
105. Binary rewriting and call interception for efficient runtime protection against buffer overflows, 2006
107. Randomized instruction set emulation, 2005
108. Implementation vulnerabilities and detection, 2007
109. Proactive Obfuscation, 2009
111. An Integrated Framework for Dependable and Revivable Architectures Using Multicore Processors, 2006
120. Breaking the memory secrecy assumption, 2009
121. Security by Design, 2009
124. Specification and evaluation of polymorphic shellcode properties using a new temporal logic, 2009
126. Protecting Xen hypercalls, 2009
130. Surgically returning to randomized lib (c), 2009
134. Program Differentiation, 2010
142. Security Systems Design and Analysis Using an Integrated Rule-Based Systems Approach [abstract], 2005
146. Design and Implementation of an Extended Reference Monitor for Trusted Operating Systems [abstract], 2006
149. Return Address Randomization Scheme for Annuling Data-Injection Buffer Overflow Attacks [abstract], 2006
152. A Theory of Secure Control Flow [abstract], 2005
156. Linux 2.6 kernel exploits [abstract], 2007
157. A Policy Language for the Extended Reference Monitor in Trusted Operating Systems [abstract], 2007
158. Intrusion detection and security policy framework for distributed environments [abstract], 2005
160. Towards the specification of access control policies on multiple operating systems [abstract], 2004
162. A Collaborative Approach for Access Control, Intrusion Detection and Security Testing [abstract], 2006
166. Model-driven configuration of os-level mandatory access control: research abstract [abstract], 2008