Muhammad Hammad Bashir
PhD Student in Computer Science · PSec Lab, Penn State University
PSec Lab
Penn State University
I am a PhD student in Computer Science at Penn State University and a member of PSec Lab, advised by Prof. Arslan Khan.
My research is on firmware and embedded-system security — firmware rehosting, binary analysis, and side-channel attacks. My work on BoardRunner will appear at ACM CCS 2026.
Before the PhD I spent two years at 10xEngineers on RISC-V compliance verification and open-source ISA tooling, contributing to RISCOF, RISC-V ISAC, the RISC-V Sail model, and the official RISC-V Architecture Tests.
I am currently looking for cybersecurity research internships in systems security, firmware security, hardware/software interface security, and microarchitectural attacks.
research interests
- Firmware rehosting, emulation, and peripheral/MMIO modeling
- Binary analysis and reverse engineering of embedded firmware
- Side-channel and microarchitectural attacks
- Security at the hardware/software interface
- RISC-V architecture, privileged specification, and compliance verification
security competitions
- DARPA FIRE Hackathon (2026) — reverse-engineered 100 corrupted and obfuscated embedded binaries to recover architecture, vendor/platform, and firmware family; part of the winning team.
- MITRE embedded Capture the Flag (eCTF) (2026) — led Penn State’s team and designed the security architecture for a hardware security module; placed 22nd of 119 teams.
- CyberAuto Challenge (2026) — authorized security analysis of EV charging infrastructure, reported under NDA.
academic service
education
- PhD in Computer Science, The Pennsylvania State University, 2025–present
- BSc in Electrical Engineering, University of Engineering and Technology (UET), Lahore, 2020–2024
news
| Sep 04, 2026 | BoardRunner: Automatic Firmware Rehosting using High-Fidelity Compositional Device Models was accepted at ACM CCS 2026. |
|---|---|
| Jul 01, 2026 | Serving on the Artifact Evaluation Committee for USENIX WOOT 2026. |
| Jun 01, 2026 | Our team won the DARPA FIRE Hackathon, reverse-engineering 100 corrupted and obfuscated embedded binaries to recover architecture, vendor/platform, and firmware family. |
selected publications
- BoardRunner: Automatic Firmware Rehosting using High-Fidelity Compositional Device ModelsIn Proceedings of the 33rd ACM Conference on Computer and Communications Security (CCS). Accepted; to appear. , 2026