Muhammad Hammad Bashir

PhD Student in Computer Science · PSec Lab, Penn State University

prof_pic.jpg

PSec Lab

Penn State University

I am a PhD student in Computer Science at Penn State University and a member of PSec Lab, advised by Prof. Arslan Khan.

My research is on firmware and embedded-system security — firmware rehosting, binary analysis, and side-channel attacks. My work on BoardRunner will appear at ACM CCS 2026.

Before the PhD I spent two years at 10xEngineers on RISC-V compliance verification and open-source ISA tooling, contributing to RISCOF, RISC-V ISAC, the RISC-V Sail model, and the official RISC-V Architecture Tests.

I am currently looking for cybersecurity research internships in systems security, firmware security, hardware/software interface security, and microarchitectural attacks.

research interests

  • Firmware rehosting, emulation, and peripheral/MMIO modeling
  • Binary analysis and reverse engineering of embedded firmware
  • Side-channel and microarchitectural attacks
  • Security at the hardware/software interface
  • RISC-V architecture, privileged specification, and compliance verification

security competitions

  • DARPA FIRE Hackathon (2026) — reverse-engineered 100 corrupted and obfuscated embedded binaries to recover architecture, vendor/platform, and firmware family; part of the winning team.
  • MITRE embedded Capture the Flag (eCTF) (2026) — led Penn State’s team and designed the security architecture for a hardware security module; placed 22nd of 119 teams.
  • CyberAuto Challenge (2026) — authorized security analysis of EV charging infrastructure, reported under NDA.

academic service

education

  • PhD in Computer Science, The Pennsylvania State University, 2025–present
  • BSc in Electrical Engineering, University of Engineering and Technology (UET), Lahore, 2020–2024

news

Sep 04, 2026 BoardRunner: Automatic Firmware Rehosting using High-Fidelity Compositional Device Models was accepted at ACM CCS 2026.
Jul 01, 2026 Serving on the Artifact Evaluation Committee for USENIX WOOT 2026.
Jun 01, 2026 Our team won the DARPA FIRE Hackathon, reverse-engineering 100 corrupted and obfuscated embedded binaries to recover architecture, vendor/platform, and firmware family.

selected publications

  1. BoardRunner: Automatic Firmware Rehosting using High-Fidelity Compositional Device Models
    Muhammad Hammad Bashir, Michael Rooney, Colin Smith, Dongyan Xu, and Arslan Khan
    In Proceedings of the 33rd ACM Conference on Computer and Communications Security (CCS). Accepted; to appear. , 2026
  2. µLEAK: Bypassing MPU Isolation on Cortex-M7 via Cache-Timing Attacks
    Muhammad Hammad Bashir, Taegyu Kim, Arslan Khan, and Kyungtae Kim
    In Non-Volatile Memories Workshop (NVMW) 2026, 2026
  3. Verification of CoreSwap: Replacing ARM Cortex-A5 with RISC-V CVA6 in ARM SoC Environment
    Muhammad Hammad Bashir, Umer Shahid, Muhammad Tahir, Yazan Hussnain, and Fatima Saleem
    In RISC-V Summit Europe 2025 - Posters, Jun 2025
  4. Comprehensive Verification of the RISC-V Memory Management Unit: Challenges and Solutions
    Huda Sajjad, Muhammad Hammad Bashir, Yazan Hussnain, and Fatima Saleem
    In RISC-V Summit Europe 2025 - Posters, Apr 2025
  5. Enhancing Privilege Architecture Support in RISC-V ISAC
    Muhammad Hammad Bashir, Umer Shahid, Allen Baum, and Pawan Kumar Sanjaya
    In RISC-V Summit Europe 2024 - Posters, Jun 2024