Hasan Al Shaikh

dblp:316/4063 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0002-6142-7329ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 GEmFuzz: Uncovering System-Level Vulnerabilities in SoCs via Emulation-Based Grey-Box Fuzzing
abstract
Security verification of modern System-on-Chip (SoC) designs is becoming increasingly challenging due to the growing integration of third-party IPs and the complexity of hardware-software (HW/SW) interactions. This escalating complexity broadens the attack surface, leading to a higher number of potential vulnerabilities and longer detection times. Consequently, verification engineers face increasing pressure to ensure robust security within tight development schedules. Traditional techniques such as formal verification and information flow tracking often suffer from poor scalability, state space explosion, and significant manual effort, necessitating expert-level design knowledge. Fuzzing-based methodologies, while promising, typically rely on the availability of a golden reference model and struggle to scale effectively, which limits their applicability. Furthermore, the increasing intricacy of HW/SW stacks in modern SoCs introduces new classes of system-level vulnerabilities that remain largely unaddressed by existing approaches. To address these challenges, we propose GEmFuzz, a hardware emulation-based greybox fuzzing framework for SoC security verification. GEmFuzz uses a hardware emulation server to run the design under test (DUT) at near real-time speed, effectively addressing the scalability challenges. Also, it leverages a cost-function-guided fuzzer to generate intelligent input patterns for system-level vulnerability detection. We evaluate GEmFuzz on a RISC-V-based SoC and demonstrate its effectiveness in detecting a set of known system-level vulnerabilities. Additionally, it identifies two previously unknown vulnerabilities, highlighting the capability and promise of the proposed framework.
Shuvagata Saha, Ahmed Alhurubi, Tanvir Rahman, Hasan Al Shaikh, Sujan Kumar Saha, Farimah Farahmandi, Mark Tehranipoor
ASP-DAC4
2025 Special Session: ThreatLens: LLM-guided Threat Modeling and Test Plan Generation for Hardware Security Verification
abstract
Current hardware security verification processes predominantly rely on manual threat modeling and test plan generation, which are labor-intensive, error-prone, and struggle to scale with increasing design complexity and evolving attack methodologies. To address these challenges, we propose ThreatLens, an LLM-driven multi-agent framework that automates security threat modeling and test plan generation for hardware security verification. ThreatLens integrates retrieval-augmented generation (RAG) to extract relevant security knowledge, LLM-powered reasoning for threat assessment, and interactive user feedback to ensure the generation of practical test plans. By automating these processes, the framework reduces the manual verification effort, enhances coverage, and ensures a structured, adaptable approach to security verification. We evaluated our framework on the NEORV32 SoC, demonstrating its capability to automate security verification through structured test plans and validating its effectiveness in real-world scenarios.
Dipayan Saha, Hasan Al Shaikh, Shams Tarek, Farimah Farahmandi
VTS2
2025 Re-Pen: Reinforcement Learning-Enforced Penetration Testing for SoC Security Verification
abstract
Due to the increasingly complex interaction between the tightly integrated components, reuse of various untrustworthy third-party IPs (3PIPs), and security-unaware design practices, there have been a rising number of reports of system-on-chip (SoC) hardware (HW) vulnerabilities that compromise the security of critical assets. SoC security verification, therefore, is an indispensable part of the verification effort. The existing hardware verification methodologies either presuppose white-box knowledge or scale poorly with increasing design complexity. Hardware penetration testing (pentest) is an emerging gray-box security verification methodology at the register-transfer level (RTL) that is applicable across a wide variety of threat models and addresses many shortcomings of the existing methodologies. In this work, we propose Re-Pen, a novel hardware pentest framework that requires minimal gray-box information from the design specification to achieve significantly better security vulnerability (SV) detection performance than state-of-the-art pentest techniques. At the core of this framework lies a mutation engine that combines the strengths of reinforcement learning (RL) and binary particle swarm optimization (BPSO) in its test pattern mutation strategy to generate intelligent test patterns without manual supervision. This framework significantly reduces the requirement for detailed, manual, expertise-driven adaptations specific to the SoC under test. Through extensive experiments conducted on multiple SoCs, we demonstrate that Re-Pen can reduce vulnerability detection time by up to$3\times $and achieve a markedly improved consistency compared with the state of the art. Furthermore, Re-Pen was able to detect native security bugs in an open-source SoC. It successfully identified a scenario where, despite a functionally correct hardware implementation, a mistake in the architectural specification allowed privilege escalation from the software layer.
Hasan Al Shaikh, Shuvagata Saha, Kimia Zamiri Azar, Farimah Farahmandi, Mark Tehranipoor, Fahim Rahman
IEEE Trans. Very Large Scale Integr. Syst.1
2024 TDM: Time and Distance Metric for Quantifying Information Leakage Vulnerabilities in SoCs
abstract
Protecting assets against information leakage is crucial to ensure System-on-Chip (SoC) security. This paper introduces a Time and Distance-based security metric (TDM) to assess information leakage risks across hardware Intellectual Properties (IPs) in SoC architectures. TDM quantifies both asset exposure time and spatial proximity to external threats, identifying vulnerable locations and critical timings. Using graph-based analysis, we map data flow, evaluating risk based on how long and how closely sensitive data resides near output ports. Applied to five open-source designs, TDM effectively enhances SoC security by measuring susceptibility to threats.
Avinash Ayalasomayajula, Henian Li, Hasan Al Shaikh, Sujan Kumar Saha, Farimah Farahmandi
ICCD3
2023 SHarPen: SoC Security Verification by Hardware Penetration Test
abstract
As modern SoC architectures incorporate many complex/heterogeneous intellectual properties (IPs), the protection of security assets has become imperative, and the number of vulnerabilities revealed is rising due to the increased number of attacks. Over the last few years, penetration testing (PT) has become an increasingly effective means of detecting software (SW) vulnerabilities. As of yet, no such technique has been applied to the detection of hardware vulnerabilities. This paper proposes a PT framework, SHarPen, for detecting hardware vulnerabilities, which facilitates the development of a SoC-level security verification framework. SHarPen proposes a formalism for performing gray-box hardware (HW) penetration testing instead of relying on coverage-based testing and provides an automation for mapping hardware vulnerabilities to logical/mathematical cost functions. SHarPen supports both simulation and FPGA-based prototyping, allowing us to automate security testing at different stages of the design process with high capabilities for identifying vulnerabilities in the targeted SoC.
Hasan Al Shaikh, Arash Vafaei, Mridha Md Mashahedur Rahman, Kimia Zamiri Azar, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor
ASP-DAC1