| 2026 | NDSS | Bullseye: Detecting Prototype Pollution in NPM Packages with Proof of Concept Exploits. | Tariq Houis, Shaoqi Jiang, Mohammad Mannan, Amr Youssef |
| 2025 | SecureComm | Login, Logout, Reset: Measuring Security and Privacy Issues in Real-World Web Logins. | Kazi Farhat Lamisa, Mohammad Mannan, Amr M. Youssef |
| 2025 | SecureComm | On Analyzing SSO Permissions Across Web and Android Platforms. | Fahimeh Rezaei, Matteo Lupinacci, Mohammad Mannan, Amr M. Youssef |
| 2024 | CCS | Poster: Detecting Ransomware Attacks by Analyzing Replicated Block Snapshots Using Neural Networks. | Seok Min Hong, Beom Heyn Kim, Mohammad Mannan |
| 2024 | SecureComm | TEE-Receipt: A TEE-Based Non-repudiation Framework for Web Applications. | Mahmoud Hofny, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
| 2023 | ESORICS | Try On, Spied On?: Privacy Analysis of Virtual Try-On Websites and Android Apps. | Abdelrahman Ragab, Mohammad Mannan, Amr M. Youssef |
| 2023 | RAID | Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The WeChat Case. | Supraja Baskaran, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
| 2023 | WWW | All Your Shops Are Belong to Us: Security Weaknesses in E-commerce Platforms. | Rohan Pagey, Mohammad Mannan, Amr M. Youssef |
| 2022 | AsiaCCS | On Measuring Vulnerable JavaScript Functions in the Wild. | Maryna Kluban, Mohammad Mannan, Amr M. Youssef |
| 2022 | CCS | Hidden in Plain Sight: Exploring Encrypted Channels in Android Apps. | Sajjad Pourali, Nayanamana Samarasinghe, Mohammad Mannan |
| 2022 | ESORICS | No Salvation from Trackers: Privacy Analysis of Religious Websites and Mobile Apps. | Nayanamana Samarasinghe, Pranay Kapoor, Mohammad Mannan, Amr M. Youssef |
| 2022 | FC | Not so Immutable: Upgradeability of Smart Contracts on Ethereum. | Mehdi Salehi, Jeremy Clark, Mohammad Mannan |
| 2022 | WWW | Et tu, Brute? Privacy Analysis of Government Websites and Mobile Apps. | Nayanamana Samarasinghe, Aashish Adhikari, Mohammad Mannan, Amr M. Youssef |
| 2022 | SecureComm | Silver Surfers on the Tech Wave: Privacy Analysis of Android Apps for the Elderly. | Pranay Kapoor, Rohan Pagey, Mohammad Mannan, Amr M. Youssef |
| 2021 | FC | Red-Black Coins: Dai Without Liquidations. | Mehdi Salehi, Jeremy Clark, Mohammad Mannan |
| 2021 | SecureComm | Horus: A Security Assessment Framework for Android Crypto Wallets. | Md Shahab Uddin, Mohammad Mannan, Amr M. Youssef |
| 2020 | ACSAC | Betrayed by the Guardian: Security and Privacy Risks of Parental Control Solutions. | Suzan Ali, Mounir Elgharabawy, Quentin Duchaussoy, Mohammad Mannan, Amr M. Youssef |
| 2020 | ACSAC | Reboot-Oriented IoT: Life Cycle Management in Trusted Execution Environment for Disposable IoT devices. | Kuniyasu Suzaki, Akira Tsukamoto, Andy Green, Mohammad Mannan |
| 2020 | TrustCom | LURK: Server-Controlled TLS Delegation. | Ioana Boureanu, Daniel Migault, Stere Preda, Hyame Assem Alamedine, Sanjay Mishra, Frederic Fieau, Mohammad Mannan |
| 2020 | SecureComm | ByPass: Reconsidering the Usability of Password Managers. | Elizabeth Stobert, Tina Safaie, Heather Molyneaux, Mohammad Mannan, Amr M. Youssef |
| 2019 | ACSAC | AppVeto: mobile application self-defense through resource access veto. | Tousif Osman, Mohammad Mannan, Urs Hengartner, Amr M. Youssef |
| 2019 | DSN | DeviceVeil: Robust Authentication for Individual USB Devices Using Physical Unclonable Functions. | Kuniyasu Suzaki, Yohei Hori, Kazukuni Kobara, Mohammad Mannan |
| 2019 | ESORICS | On Privacy Risks of Public WiFi Captive Portals. | Suzan Ali, Tousif Osman, Mohammad Mannan, Amr M. Youssef |
| 2019 | FC | One-Time Programs Made Practical. | Lianying Zhao, Joseph I. Choi, Didem Demirag, Kevin R. B. Butler, Mohammad Mannan, Erman Ayday, Jeremy Clark |
| 2019 | NDSS | TEE-aided Write Protection Against Privileged Data Tampering. | Lianying Zhao, Mohammad Mannan |
| 2019 | PST | On the null relationship between personality types and passwords. | Amit Maraj, Miguel Vargas Martin, Matthew Shane, Mohammad Mannan |
| 2018 | CCS | To Intercept or Not to Intercept: Analyzing TLS Interception in Network Appliances. | Louis Waked, Mohammad Mannan, Amr M. Youssef |
| 2018 | DBSEC | On Understanding Permission Usage Contextuality in Android Apps. | Md Zakir Hossen, Mohammad Mannan |
| 2018 | WWW | SafeKeeper: Protecting Web Passwords using Trusted Execution Environments. | Klaudia Krawiecka, Arseny Kurnikov, Andrew Paverd, Mohammad Mannan, N. Asokan |
| 2018 | WWW | Using SafeKeeper to Protect Web Passwords. | Arseny Kurnikov, Klaudia Krawiecka, Andrew Paverd, Mohammad Mannan, N. Asokan |
| 2017 | FC | Short Paper: TLS Ecosystems in Networked Devices vs. Web Servers. | Nayanamana Samarasinghe, Mohammad Mannan |
| 2016 | CCS | Sixth Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM 2016). | Long Lu, Mohammad Mannan |
| 2016 | CCS | Hypnoguard: Protecting Secrets across Sleep-wake Cycles. | Lianying Zhao, Mohammad Mannan |
| 2016 | NDSS | Killed by Proxy: Analyzing Client-end TLS Interception Software. | Xavier de Carn de Carnavalet, Mohammad Mannan |
| 2015 | NDSS | Gracewipe: Secure and Verifiable Deletion under Coercion. | Lianying Zhao, Mohammad Mannan |
| 2015 | NSPW | Peace vs. Privacy: Leveraging Conflicting Jurisdictions for Email Security. | Mohammad Mannan, Arash Shahkar, Atieh Saberi Pirouz, Vladimir Rabotka |
| 2014 | ACSAC | Challenges and implications of verifiable builds for security-critical open-source software. | Xavier de Carn de Carnavalet, Mohammad Mannan |
| 2014 | NDSS | From Very Weak to Very Strong: Analyzing Password-Strength Meters. | Xavier de Carn de Carnavalet, Mohammad Mannan |
| 2013 | NDSS | On Implementing Deniable Storage Encryption for Mobile Devices. | Adam Skillen, Mohammad Mannan |
| 2013 | NSPW | Explicit authentication response considered harmful. | Lianying Zhao, Mohammad Mannan |
| 2012 | WISA | Lightweight Client-Side Methods for Detecting Email Forgery. | Eric Lin, John Aycock, Mohammad Mannan |
| 2011 | CCS | Unicorn: two-factor attestation for data security. | Mohammad Mannan, Beom Heyn Kim, Afshar Ganjali, David Lie |
| 2011 | FC | Mercury: Recovering Forgotten Passwords Using Personal Devices. | Mohammad Mannan, David Barrera, Carson D. Brown, David Lie, Paul C. van Oorschot |
| 2008 | FC | Weighing Down "The Unbearable Lightness of PIN Cracking". | Mohammad Mannan, Paul C. van Oorschot |
| 2008 | NSPW | Localization of credential information to address increasingly inevitable data breaches. | Mohammad Mannan, Paul C. van Oorschot |
| 2008 | WWW | Privacy-enhanced sharing of personal content on the web. | Mohammad Mannan, Paul C. van Oorschot |
| 2007 | FC | Using a Personal Device to Strengthen Password Authentication from an Untrusted Computer. | Mohammad Mannan, Paul C. van Oorschot |
| 2007 | NSPW | Security and usability: the gap in real-world online banking. | Mohammad Mannan, Paul C. van Oorschot |
| 2006 | FC | A Protocol for Secure Public Instant Messaging. | Mohammad Mannan, Paul C. van Oorschot |
| 2004 | PST | Secure Public Instant Messaging. | Mohammad Mannan, Paul C. van Oorschot |