EDBT 2026 Demo / reviewers in the wild / expert
Shams Tarek
dblp:304/0903
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0001-7671-6409ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Special Session: ThreatLens: LLM-guided Threat Modeling and Test Plan Generation for Hardware Security VerificationabstractCurrent hardware security verification processes predominantly rely on manual threat modeling and test plan generation, which are labor-intensive, error-prone, and struggle to scale with increasing design complexity and evolving attack methodologies. To address these challenges, we propose ThreatLens, an LLM-driven multi-agent framework that automates security threat modeling and test plan generation for hardware security verification. ThreatLens integrates retrieval-augmented generation (RAG) to extract relevant security knowledge, LLM-powered reasoning for threat assessment, and interactive user feedback to ensure the generation of practical test plans. By automating these processes, the framework reduces the manual verification effort, enhances coverage, and ensures a structured, adaptable approach to security verification. We evaluated our framework on the NEORV32 SoC, demonstrating its capability to automate security verification through structured test plans and validating its effectiveness in real-world scenarios. Dipayan Saha, Hasan Al Shaikh, Shams Tarek, Farimah Farahmandi |
VTS | 3 |
| 2025 | BugWhisperer: Fine-Tuning LLMs for SoC Hardware Vulnerability DetectionabstractThe current landscape of system-on-chips (SoCs) security verification faces challenges due to manual, labor-intensive, and inflexible methodologies. These issues limit the scalability and effectiveness of security protocols, making bug detection at the Register-Transfer Level (RTL) difficult. This paper proposes a new framework named BugWhisperer that utilizes a specialized, fine-tuned Large Language Model (LLM) to address these challenges. By enhancing the LLM’s hardware security knowledge and leveraging its capabilities for text inference and knowledge transfer, this approach automates and improves the adaptability and reusability of the verification process. We introduce an open-source, fine-tuned LLM specifically designed for detecting security vulnerabilities in SoC designs. Our findings demonstrate that this tailored LLM effectively enhances the efficiency and flexibility of the security verification process. Additionally, we introduce a comprehensive hardware vulnerability database that supports this work and will further assist the research community in enhancing the security verification process. Shams Tarek, Dipayan Saha, Sujan Kumar Saha, Farimah Farahmandi |
VTS | 1 |
| 2024 | The Road Not Taken: eFPGA Accelerators Utilized for SoC Security AuditingabstractTo meet the demands of diverse and rapidly evolving markets, system-on-chips (SoCs) are becoming more complex in size and functionality. More IPs and hardware accelerators are required to support a varied set of applications with faster response. In recent years, there has been a growing trend of using reconfigurable and adaptable hardware for compute-intensive kernels, e.g., neural networks, crypto-engines, and blockchains. Hence, embedded FPGA (eFPGA) technology has emerged as a standard solution incorporated into the SoC to enhance computational performance and provide reconfigurability. However, with the increasing complexity and size of modern SoCs, coupled with the integration of third-party IPs (3PIPs) and accelerators, ensuring the information security, i.e., integrity, confidentiality, and availability, of critical and sensitive data has become more challenging than ever before. Thus, a sustainable and upgradable security auditing infrastructure has become a necessity. This paper extends EnSAFe, a framework specially crafted to streamline security policy auditing while enabling upgradability within designs that leverage eFPGA-based accelerators. The EnSAFe framework enables signal monitoring in a plug-and-play fashion, and the monitoring core logic is mapped onto the eFPGA accelerator component with minimal overhead. We extend EnSAFe through novel methodologies and algorithms for security policy generation, optimization of security policy implementations, and enhancement of the reconfigurability of the Security Status Monitor (SSM). We also establish a security policy database and assess the effectiveness of the extended framework for policy checking across various use case scenarios. Our experiments show that EnSAFe can detect runtime threats/vulnerabilities at low area overhead. Mridha Md Mashahedur Rahman, Shams Tarek, Kimia Zamiri Azar, Mark Tehranipoor, Farimah Farahmandi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2024 | Exploring the Abyss? Unveiling Systems-on-Chip Hardware Vulnerabilities Beneath SoftwareabstractDue to the increasing size and complexity of system-on-chips (SoCs), new threats and vulnerabilities are emerging, mainly related to flaws at the system level. Due to the lack of decisive security requirements and properties from the perspective of the SoC designer, the system-level verification process, whose violation may lead to exploiting a hardware vulnerability, is not studied comprehensively. To enable more comprehensive verification of system-level properties, this paper presents a framework known asHUnTer(Hardware Underath Trigger) for identifying sets of instructions (sequences) at the processor unit (PU) that reveal the underlying hardware vulnerabilities. HUnTer automates (i) threat modeling, (ii) threat-based formal verification, (iii) generating counterexamples, and (iv) generating snippet code to exploit the vulnerability. Furthermore, the HUnTer framework defines a unique security coverage metric (HUnT_Coverage) to measure the performance and effectiveness of vulnerability exploits. To demonstrate the high effectiveness of the proposed framework, we conduct a wide variety of case studies using the HUnTer framework on RISC-V-based open-source SoC architecture and attains the security coverage of 86% as an average for 11 benchmarks of the Trust-Hub database. Sree Ranjani Rajendran, Nusrat Farzana, Shams Tarek, Hadi Mardani Kamali, Farimah Farahmandi, Mark Tehranipoor |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | HUnTer: Hardware Underneath Trigger for Exploiting SoC-level VulnerabilitiesabstractSystems-on-chip (SoCs) have become increasingly large and complex, resulting in new threats and vulnerabilities, mainly related to system-level flaws. However, the system-level verification process, whose violation may lead to exploiting a hardware vulnerability, is not studied comprehensively due to the lack of decisive (security) requirements and properties from the SoC designer's perspective. To enable a more comprehensive verification for system-level properties, this paper presents HUnTer (Hardware Underneath Trigger), a framework for identifying sets (sequences) of instructions at the processor unit (PU) that unveils the underneath hardware vulnerabilities. The HUnTer framework automates (i) threat modeling, (ii) threat-based formal verification, (iii) generation of counterexamples, and (iv) generation of snippet code for exploiting the vulnerability. The HUnTer framework also defines a security coverage metric (HUnT_Coverage) to measure the performance and efficacy of the proposed approach. Using the HUnTer framework on a RISC-V-based open-source SoC architecture, we conduct a wide variety of case studies of Trust-HUB vulnerabilities to demonstrate the high effectiveness of the proposed framework. Sree Ranjani Rajendran, Shams Tarek, Benjamin M. Hicks, Hadi Mardani Kamali, Farimah Farahmandi, Mark Tehranipoor |
DATE | 2 |