Ahmed Tanvir Mahdad
Dr. Ahmed Tanvir Mahdad is an Assistant Professor in the School of Electrical Engineering and Computer Science at Ohio University. Prior to joining Ohio University, Dr. Mahdad earned his Ph.D. in Computer Science and Engineering from Texas A&M University. He also has over eight years of industry experience in software engineering.
Research Interests: Dr. Mahdad’s research focuses on identifying and mitigating security and privacy issues in modern authentication systems and smart devices (e.g., smartphones and AR/VR devices).
His work has been published in top-tier security and systems conferences and journals, including ACM CCS, IEEE S&P, ACM MobiCom, WWW, IEEE ICDCS, and ACM TOPS. Additionally, his research has been featured in various news media outlets worldwide.
Degrees Earned:
- Ph.D., Computer Science and Engineering, Texas A&M University
- B.S., Computer Science and Engineering, Bangladesh University of Engineering and Technology
Journal Article, Academic Journal (1)
- Shrestha, P., Mahdad, A., Saxena, N. (2024). Sound-based Two-factor Authentication: Vulnerabilities and Redesign. 1. ACM Transactions on Privacy and Security; 27: 1-27. https://doi.org/10.1145/3632175.
Conference Proceeding (13)
- Zhang, T., Ji, Q., Akanda, M., Ye, Z., Mahdad, A., Shi, C., Wang, Y., Saxena, N., Chen, Y. (2025). Harnessing Vital Sign Vibration Harmonics for Effortless and Inbuilt XR User Authentication. ACM; 3520-3534. https://dl.acm.org/doi/10.1145/3719027.3765060.
- Huq, M., Mahdad, A., Saxena, N. (2025). Encryption Struggles Persist: When Tech-Savvy Students Face Challenges with PGP in Thunderbird. IEEE; 1-10. https://doi.org/10.1109/pst65910.2025.11268857.
- Ye, Z., Mahdad, A., Wang, Y., Shi, C., Chen, Y., Saxena, N. (2025). BPSniff: Continuously Surveilling Private Blood Pressure Information in the Metaverse via Unrestricted Inbuilt Motion Sensors. IEEE; 4356-4374. https://doi.org/10.1109/sp61157.2025.00049.
- Akanda, M., Mahdad, A., Saxena, N. (2025). Broken Access: On the Challenges of Screen Reader Assisted Two-Factor and Passwordless Authentication. ACM; 1116 - 1128. https://dl.acm.org/doi/abs/10.1145/3696410.3714579.
- Mahdad, A., Saxena, N. (2024). Mobile Login Bridge: Subverting 2FA and Passwordless Authentication via Android Debug Bridge. IEEE; 1-12. https://ieeexplore.ieee.org/abstract/document/10788081.
- Mahdad, A., Jubur, M., Saxena, N. (2024). Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display Authenticators. ACM; 1686-1700. https://doi.org/10.1145/3658644.3690286.
- Zhang, T., Ji, Q., Ye, Z., Akanda, M., Mahdad, A., Shi, C., Wang, Y., Saxena, N., Chen, Y. (2024). SAFARI: Speech-Associated Facial Authentication for AR/VR Settings via Robust VIbration Signatures. ACM; 153-167. https://doi.org/10.1145/3658644.3670358.
- Zhang, T., Ye, Z., Mahdad, A., Akanda, M., Shi, C., Wang, Y., Saxena, N., Chen, Y. (2023). FaceReader: Unobtrusively Mining Vital Signs and Vital Sign Embedded Sensitive Info via AR/VR Motion Sensors. ACM; 446-459. https://doi.org/10.1145/3576915.3623102.
- Mahdad, A., Shi, C., Ye, Z., Zhao, T., Wang, Y., Chen, Y., Saxena, N. (2023). EmoLeak: Smartphone Motions Reveal Emotions. IEEE; 316-326. https://ieeexplore.ieee.org/abstract/document/10272395.
- Mahdad, A., Jubur, M., Saxena, N. (2023). Breaking Mobile Notification-based Authentication with Concurrent Attacks Outside of Mobile Devices. ACM; 1-15. https://doi.org/10.1145/3570361.3613273.
- Mahdad, A., Saxena, N. (2023). SoK: A Comprehensive Evaluation of 2FA-based Schemes in the Face of Active Concurrent Attacks from User Terminal. ACM; 175-186. https://doi.org/10.1145/3558482.3590183.
- Shi, C., Zhao, T., Zhang, W., Mahdad, A., Ye, Z., Wang, Y., Saxena, N., Chen, Y. (2022). Defending against Thru-barrier Stealthy Voice Attacks via Cross-Domain Sensing on Phoneme Sounds. IEEE; 680-690. https://ieeexplore.ieee.org/abstract/document/9912174.
- Mahdad, A., Jubur, M., Saxena, N. (2021). Analyzing the Security of OTP 2FA in the Face of Malicious Terminals. Springer International Publishing; 97-115. https://doi.org/10.1007/978-3-030-86890-1_6.
Conference, Poster (3)
- Ye, Z., Mahdad, A., Wang, Y., Shi, C., Chen, Y., Saxena, N. (2025). VR Testbed-based Blood Pressure Privacy Leakage Analysis. ACM; 1-2. https://doi.org/10.1145/3769102.3774707.
- Zhang, T., Yes, Z., Mahdad, A., Akanda, M., Shi, C., Saxena, N., Wang, Y., Chen, Y. (2023). Poster: Unobtrusively Mining Vital Sign and Embedded Sensitive Info via AR/VR Motion Sensors. ACM; 308-309. https://dl.acm.org/doi/abs/10.1145/3565287.3623624.
- Zhao, T., Ye, Z., Zhang, T., Shi, C., Mahdad, A., Wang, Y., Chen, Y., Saxena, N. (2022). Continuous blood pressure monitoring using low-cost motion sensors on AR/VR headsets. ACM; 589-590. https://doi.org/10.1145/3498361.353879.