@inproceedings{ccs_2026_boardrunner,author={Bashir, Muhammad Hammad and Rooney, Michael and Smith, Colin and Xu, Dongyan and Khan, Arslan},booktitle={Proceedings of the 33rd ACM Conference on Computer and Communications Security (CCS)},title={BoardRunner: Automatic Firmware Rehosting using High-Fidelity Compositional Device Models},year={2026},}
µLEAK: Bypassing MPU Isolation on Cortex-M7 via Cache-Timing Attacks
Muhammad Hammad Bashir, Taegyu Kim, Arslan Khan, and Kyungtae Kim
In Non-Volatile Memories Workshop (NVMW) 2026, 2026
@inproceedings{nvmw_2026_uleak,author={Bashir, Muhammad Hammad and Kim, Taegyu and Khan, Arslan and Kim, Kyungtae},booktitle={Non-Volatile Memories Workshop (NVMW) 2026},title={µLEAK: Bypassing MPU Isolation on Cortex-M7 via Cache-Timing Attacks},year={2026},url={https://nvmw.ucsd.edu/program-3/#paper-33},}
@inproceedings{riscv_china_2025_static_signature,author={Bashir, Muhammad Hammad and Shahid, Umer and Baum, Allen and Shi, James},booktitle={RISC-V Summit China 2025 - Posters},title={Static Signature Embedding: Self-Verifying RISC-V Architecture Compliance Tests},year={2025},url={https://riscv-summit-china.org/en/#},}
Verification of CoreSwap: Replacing ARM Cortex-A5 with RISC-V CVA6 in ARM SoC Environment
Muhammad Hammad Bashir, Umer Shahid, Muhammad Tahir, Yazan Hussnain, and Fatima Saleem
This paper presents the verification methodology and results of the CoreSwap project, where the ARM Cortex-A5 core in ARM Educational Kit SoC was replaced with the open-source RISC-V OpenHW CVA6 core. The project demonstrates the feasibility of integrating a RISC-V core into an existing SoC ecosystem while maintaining functionality and system stability. We detail the comprehensive verification process, including core-level Architecture Compliance Tests (ACTs), manually written system-level tests, FPGA synthesis on a Kintex-7 platform, and running performance benchmarks. The verification strategy highlights the challenges and solutions to validate such a large-scale System on Chip (SoC). This seamless integration and verification of the CoreSwap underscores the potential of RISC-V in proprietary SoC environments.
@inproceedings{riscv_europe_2025_coreswap,author={Bashir, Muhammad Hammad and Shahid, Umer and Tahir, Muhammad and Hussnain, Yazan and Saleem, Fatima},booktitle={RISC-V Summit Europe 2025 - Posters},month=jun,title={Verification of CoreSwap: Replacing ARM Cortex-A5 with RISC-V CVA6 in ARM SoC Environment},url={https://riscv-europe.org/summit/2025/posters#:~:text=Verification%20of%20CoreSwap%3A%20Replacing%20ARM%20Cortex%2DA5%20with%20RISC%2DV%20CVA6%20in%20ARM%20SoC%20Environment},year={2025},}
Comprehensive Verification of the RISC-V Memory Management Unit: Challenges and Solutions
Huda Sajjad, Muhammad Hammad Bashir, Yazan Hussnain, and Fatima Saleem
The Memory Management Unit (MMU), critical for virtual memory translation and protection, demands rigorous verification due to its inherent complexity. This work details a two-step methodology to ensure MMU compliance with the RISC-V Privileged ISA specification. First, a test suite was developed using the RISCOF framework, leveraging RISC-V ISAC for coverage analysis. Second, the suite was executed on the OpenHW Core-V Wally processor, employing ImperasDV as a reference model and riscvISACOV for functional coverage development. This approach identified a critical architectural bug in Core-V Wally’s MMU implementation, demonstrating the methodology’s effectiveness in validating memory management units.
@inproceedings{riscv_europe_2025_mmu_verification,author={Sajjad, Huda and Bashir, Muhammad Hammad and Hussnain, Yazan and Saleem, Fatima},booktitle={RISC-V Summit Europe 2025 - Posters},month=apr,title={Comprehensive Verification of the RISC-V Memory Management Unit: Challenges and Solutions},url={https://riscv-europe.org/summit/2025/posters#:~:text=Comprehensive%20Verification%20of%20the%20RISC%2DV%20Memory%20Management%20Unit%3A%20Challenges%20and%20Solutions},year={2025},}
2024
Enhancing Privilege Architecture Support in RISC-V ISAC
Muhammad Hammad Bashir, Umer Shahid, Allen Baum, and Pawan Kumar Sanjaya
RISCOF, a Python-based framework, ensures RISC-V processor implementations comply with instruction set simulators like Spike and Sail. It supports both manual and automated test suite generation via RISC-V CTG, with coverage analysis performed through RISC-V ISAC. However, the coverage analysis of privilege architectural tests has been limited due to incomplete support in RISC-V ISAC. To address this, we have introduced new features in RISC-V ISAC specifically for privileged architecture, along with a more efficient method for writing coverpoints. These enhancements aim to improve compliance testing comprehensively.
@inproceedings{riscv_europe_2024_privilege_isac,author={Bashir, Muhammad Hammad and Shahid, Umer and Baum, Allen and Sanjaya, Pawan Kumar},booktitle={RISC-V Summit Europe 2024 - Posters},month=jun,title={Enhancing Privilege Architecture Support in RISC-V ISAC},url={https://riscv-europe.org/summit/2024/posters#:~:text=Enhancing%20Privileged%20Architecture%20Support%20in%20RISC%2DV%20ISAC},year={2024},}