Pierre Laperdrix

dblp:167/2160 · DBLP profile ↗
← Back
24ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0001-6901-3596ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 3 first-author · 8 since 2021Databases, data management, data science and information retrieval · 7 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Users Pay Twice: The Hidden Energy Cost of Web Advertising
abstract
International audience
Samuel Pélissier, Naif Mehanna, Sterenn Roux, Quentin Perez, Walter Rudametkin, Johann Bourcier, Pierre Laperdrix
WWW7
2026 EXADPrinter: Semi-Exhaustive Permissionless Device Fingerprinting Within the Android Ecosystem
abstract
Android is the dominant mobile operating system, powering more than 70% of mobile devices and presenting a significant opportunity for user tracking. As privacy regulations tighten around how personal data can be used and collected, trackers are looking for alternatives that are under less scrutiny to evade detection. Device fingerprinting has emerged as a key solution, allowing trackers to create identifiers without user consent in a stealthy manner. Despite the extensive research on fingerprinting done from a web browser in the past decade, device fingerprinting on Android remains relatively understudied, with limited literature exploring its specific techniques and implications for user privacy. In this study, we introduce EXADPrinter, a novel semi-exhaustive permissionless device fingerprinting framework targeting Android devices. Without requiring permissions, our framework extracts over 200,000 properties per device by leveraging methods such as Java reflection and execution of shell commands. Through a dedicated Android application and a 13-month data collection, we gathered over 4,004 fingerprints coming from 3,143 different Android devices, covering 68 manufacturers and 9 Android versions ranging from 8 to 16. Through our framework, we demonstrate that diverse data can be collected about the hardware, the operating system and the user without requiring special permissions. We show that combining 5 attributes without any IDs or personal information is enough to identify 100% of devices of our dataset, painting a bleak picture of the current state of the Android ecosystem. Moreover, our framework highlights the negative impact of custom operating systems and manufacturer-specific customizations as they enhance the effectiveness of device fingerprinting. Furthermore, EXADPrinter uncovers some leakage of sensitive information caused essentially by manufacturer customizations, including the exposure of user emails, emergency contacts, and persistent identifiers such as SIM identifiers.
Sihem Bouhenniche, Pierre Laperdrix, Walter Rudametkin
Proc. Priv. Enhancing Technol.2
2026 Gotta Catch 'em all: On the Web Tracking Practices of a Deal-Sharing Conglomerate and their Heavy Reliance on Redirect Chain
abstract
Affiliate marketing is a growing performance-based marketing arrangement in which affiliates are rewarded for getting users to register, purchase, or visit a shopping website [ 16 , 38 ]. This marketing strategy is valued at $18.5 billion USD for 2025 [ 31 , 67 ]. Deal-sharing platforms take advantage of this marketing strategy by acting as storefronts for sellers that showcase promotions and deals. As the service is free to use, they earn commissions through affiliate links [ 36 ] when they lead to sales. We perform an in-depth, end-to-end study of the tracking techniques leveraged by Pepper [ 1 ] and its extended environment, a key player in deal-sharing platforms. Through a systematic 1-month crawl, we analyze the tracking ecosystem of 10 deal-sharing websites active in a diverse range of countries abiding by different privacy laws. Our analysis reveals that a significant part of the tracking occurs during redirect chains [ 40 ] between the deal-sharing platform and the shopping website. We quantify the tracking-specific use of cookies, CNAME cloaking [ 14 ], and link decorations [ 52 , 58 ] within redirect chains. We find that 67.9% of redirect chains leverage at least one of these additional tracking techniques. We show that redirect chains examined in prior work (limited to HTTP-based redirects) are significantly more constrained than those observed in our study (HTTP-, HTML-, and JS-based), which enable more aggressive behavior by dynamically loading additional tracking resources at runtime. Finally, by analyzing the ecosystem of third-party services and the privacy policies of deal-sharing websites, we reveal the omission of numerous actors involved in redirect chains.
Sterenn Roux, Samuel Pélissier, Johann Bourcier, Walter Rudametkin, Pierre Laperdrix, Naif Mehanna
ACM Trans. Web5
2024 The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the Web
abstract
As online privacy is cementing itself as one of the core pillars of the Internet, major changes are happening across many industries. On the technological side, users are pushing for more privacy-preserving technologies and rely on browsers and extensions that limit online tracking as much as possible. On the legal front, regulations like GDPR and the ePrivacy Directive in Europe have forced companies to change their practices and be more transparent about how they handle user data. For the ad industry, the end of third-party cookies planned for 2025 is having severe ramifications as the main source of data on which this industry is built on will be gone. In this tumultuous context, companies have come up with innovative ways to overcome current and future restrictions. A novel technique which has not received much attention called Server-side tracking (SST) moves its tracking logic away from the user's device onto an external server. In this work, our aim is to detect SST on the web and understand its lawfulness with respect to current legislation. We developed a methodology that relies on crawls spaced 2 years apart performed before and after the introduction of SST to identify trackers that moved behind SST domains and that are now hidden from view. Our results show that 389, out of 7,367 visited websites, track users behind a cloaked domain and that 28 websites perform Server-side tracking in a first-party capacity. We demonstrate that such a tracking technique can overcome the Same-Origin Policy and introduce security vulnerabilities. Together with a legal scholar, we also show that SST entails non-compliant practices and infringes the GDPR and the ePrivacy Directive.
Imane Fouad, Cristiana Teixeira Santos, Pierre Laperdrix
Proc. Priv. Enhancing Technol.3
2023 Breaking Bad: Quantifying the Addiction of Web Elements to JavaScript
abstract
While JavaScript established itself as a cornerstone of the modern web, it also constitutes a major tracking and security vector, thus raising critical privacy and security concerns. In this context, some browser extensions propose to systematically block scripts reported by crowdsourced trackers lists. However, this solution heavily depends on the quality of these built-in lists, which may be deprecated or incomplete, thus exposing the visitor to unknown trackers. In this article, we explore a different strategy by investigating the benefits of disabling JavaScript in the browser. More specifically, by adopting such a strict policy, we aim to quantify the JavaScript addiction of web elements composing a web page through the observation of web breakages. As there is no standard mechanism for detecting such breakages, we introduce a framework to inspect several page features when blocking JavaScript, that we deploy to analyze 6,384 pages, including landing and internal web pages. We discover that 43% of web pages are not strictly dependent on JavaScript and that more than 67% of pages are likely to be usable as long as the visitor only requires the content from the main section of the page, for which the user most likely reached the page, while reducing the number of tracking requests by 85% on average. Finally, we discuss the viability of currently browsing the web without JavaScript and detail multiple incentives for websites to be kept usable without JavaScript.
Romain Fouquet, Pierre Laperdrix, Romain Rouvoy
ACM Trans. Internet Techn.2
2022 DRAWN APART: A Device Identification Technique based on Remote GPU Fingerprinting
Tomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk, Pierre Laperdrix, Clémentine Maurice, Yossef Oren, Romain Rouvoy, Walter Rudametkin, Yuval Yarom
NDSS5
2022 The Price to Play: A Privacy Analysis of Free and Paid Games in the Android Ecosystem
abstract
With an ever growing number of smartphone users, the mobile gaming industry is booming and reached more than 2.6 billion players worldwide in 2020. While some mobile games charge a relatively modest fee to be played, the vast majority are free and rely exclusively on ads or tracking for their revenue streams. Over the years, Google and Apple have tightened their privacy requirements for apps. They perform thorough app scanning to detect abusive behaviours and require developers to provide a privacy policy on how they collect and handle user data. Yet, little is known about the data collection that fuels the advertising and tracking industry behind mobile games. Players can see the ads that are presented to them but they may not be aware of the invisible trackers that collect valuable data in the background.
Pierre Laperdrix, Naif Mehanna, Antonin Durey, Walter Rudametkin
WWW1
2021 Careful Who You Trust: Studying the Pitfalls of Cross-Origin Communication
abstract
In the past, Web applications were mostly static and most of the content was provided by the site itself. Nowadays, they have turned into rich client-side experiences customized for the user where third parties supply a considerable amount of content, e.g., analytics, advertisements, or integration with social media platforms and external services. By default, any exchange of data between documents is governed by the Same-Origin Policy, which only permits to exchange data with other documents sharing the same protocol, host, and port. Given the move to a more interconnected Web, standard bodies and browser vendors have added new mechanisms to enable cross-origin communication, primarily domain relaxation, postMessages, and CORS. While prior work has already shown the pitfalls of not using these mechanisms securely (e.g., omitting origin checks for incoming postMessages), we instead focus on the increased attack surface created by the trust that is necessarily put into the communication partners. We report on a study of the Tranco Top 5,000 to measure the prevalence of cross-origin communication. By analyzing the interactions between sites, we build an interconnected graph of the trust relations necessary to run the Web. Subsequently, based on this graph, we estimate the damage caused through exploitation of existing XSS flaws on trusted sites.
Gordon Meiser, Pierre Laperdrix, Ben Stock
AsiaCCS2
2021 FP-Redemption: Studying Browser Fingerprinting Adoption for the Sake of Web Security
Antonin Durey, Pierre Laperdrix, Walter Rudametkin, Romain Rouvoy
DIMVA2
2021 SoK: In Search of Lost Time: A Review of JavaScript Timers in Browsers
abstract
JavaScript-based timing attacks have been greatly explored over the last few years. They rely on subtle timing differences to infer information that should not be available inside of the JavaScript sandbox. In reaction to these attacks, the W3C and browser vendors have implemented several countermeasures, with an important focus on JavaScript timers. However, as these attacks multiplied in the last years, so did the countermeasures, in a cat-and-mouse game fashion. In this paper, we present the evolution and current situation of timing attacks in browsers, as well as statistical tools to characterize available timers. Our goal is to present a clear view of the attack surface and understand: what are the main prerequisites and classes of browser-based timing attacks and what are the main countermeasures. We focus on determining to what extent the changes on timing-based countermeasures impact browser security. In particular, we show that the shift in protecting against transient execution attacks has re-enabled other attacks such as microarchitec-tural side-channel attacks with a higher bandwidth than what was possible just two years ago.
Thomas Rokicki, Clémentine Maurice, Pierre Laperdrix
EuroS&P3
2021 Fingerprinting in Style: Detecting Browser Extensions via Injected Style Sheets
Pierre Laperdrix, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis
USENIX Security Symposium1
2021 Déjà vu: Abusing Browser Cache Headers to Identify and Track Online Users
Vikas Mishra, Pierre Laperdrix, Walter Rudametkin, Romain Rouvoy
Proc. Priv. Enhancing Technol.2
2020 Web Runner 2049: Evaluating Third-Party Anti-bot Services
Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis
DIMVA3
2020 Short Paper - Taming the Shape Shifter: Detecting Anti-fingerprinting Browsers
Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis
DIMVA3
2020 Don't Count Me Out: On the Relevance of IP Address in the Tracking Ecosystem
abstract
Targeted online advertising has become an inextricable part of the way Web content and applications are monetized. At the beginning, online advertising consisted of simple ad-banners broadly shown to website visitors. Over time, it evolved into a complex ecosystem that tracks and collects a wealth of data to learn user habits and show targeted and personalized ads. To protect users against tracking, several countermeasures have been proposed, ranging from browser extensions that leverage filter lists, to features natively integrated into popular browsers like Firefox and Brave to combat more modern techniques like browser fingerprinting. Nevertheless, few browsers offer protections against IP address-based tracking techniques. Notably, the most popular browsers, Chrome, Firefox, Safari and Edge do not offer any.
Vikas Mishra, Pierre Laperdrix, Antoine Vastel, Walter Rudametkin, Romain Rouvoy, Martin Lopatka
WWW2
2020 Browser Fingerprinting: A Survey
abstract
With this article, we survey the research performed in the domain of browser fingerprinting, while providing an accessible entry point to newcomers in the field. We explain how this technique works and where it stems from. We analyze the related work in detail to understand the composition of modern fingerprints and see how this technique is currently used online. We systematize existing defense solutions into different categories and detail the current challenges yet to overcome.
Pierre Laperdrix, Nataliia Bielova, Benoit Baudry, Gildas Avoine
ACM Trans. Web1
2019 Morellian Analysis for Browsers: Making Web Authentication Stronger with Canvas Fingerprinting
Pierre Laperdrix, Gildas Avoine, Benoit Baudry, Nick Nikiforakis
DIMVA1
2019 Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile Browsers
Meng Luo 0002, Pierre Laperdrix, Nima Honarmand, Nick Nikiforakis
NDSS2
2019 Less is More: Quantifying the Security Benefits of Debloating Web Applications
Babak Amin Azad, Pierre Laperdrix, Nick Nikiforakis
USENIX Security Symposium2
2019 Unnecessarily Identifiable: Quantifying the fingerprintability of browser extensions due to bloat
abstract
In this paper, we investigate to what extent the page modifications that make browser extensions fingerprintable are necessary for their operation. We characterize page modifications that are completely unnecessary for the extension's functionality as extension bloat. By analyzing 58,034 extensions from the Google Chrome store, we discovered that 5.7% of them were unnecessarily identifiable because of extension bloat. To protect users against unnecessary extension fingerprinting due to bloat, we describe the design and implementation of an in-browser mechanism that provides coarse-grained access control for extensions on all websites. The proposed mechanism and its built-in policies, does not only protect users from fingerprinting, but also offers additional protection against malicious extensions exfiltrating user data from sensitive websites.
Oleksii Starov, Pierre Laperdrix, Alexandros Kapravelos, Nick Nikiforakis
WWW2
2018 FP-STALKER: Tracking Browser Fingerprint Evolutions
abstract
Browser fingerprinting has emerged as a technique to track users without their consent. Unlike cookies, fingerprinting is a stateless technique that does not store any information on devices, but instead exploits unique combinations of attributes handed over freely by browsers. The uniqueness of fingerprints allows them to be used for identification. However, browser fingerprints change over time and the effectiveness of tracking users over longer durations has not been properly addressed. In this paper, we show that browser fingerprints tend to change frequently-from every few hours to days-due to, for example, software updates or configuration changes. Yet, despite these frequent changes, we show that browser fingerprints can still be linked, thus enabling long-term tracking. FP-STALKER is an approach to link browser fingerprint evolutions. It compares fingerprints to determine if they originate from the same browser. We created two variants of FP-STALKER, a rule-based variant that is faster, and a hybrid variant that exploits machine learning to boost accuracy. To evaluate FP-STALKER, we conduct an empirical study using 98,598 fingerprints we collected from 1, 905 distinct browser instances. We compare our algorithm with the state of the art and show that, on average, we can track browsers for 54.48 days, and 26 % of browsers can be tracked for more than 100 days.
Antoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain Rouvoy
IEEE Symposium on Security and Privacy2
2018 Fp-Scanner: The Privacy Implications of Browser Fingerprint Inconsistencies
Antoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain Rouvoy
USENIX Security Symposium2
2018 Hiding in the Crowd: an Analysis of the Effectiveness of Browser Fingerprinting at Large Scale
abstract
Browser fingerprinting is a stateless technique, which consists in collecting a wide range of data about a device through browser APIs. Past studies have demonstrated that modern devices present so much diversity that fingerprints can be exploited to identify and track users online. With this work, we want to evaluate if browser fingerprinting is still effective at uniquely identifying a large group of users when analyzing millions of fingerprints over a few months. We collected 2,067,942 browser fingerprints from one of the top 15 French websites. The analysis of this novel dataset sheds a new light on the ever-growing browser fingerprinting domain. The key insight is that the percentage of unique fingerprints in our dataset is much lower than what was reported in the past: only 33.6% of fingerprints are unique by opposition to over 80% in previous studies. We show that non-unique fingerprints tend to be fragile. If some features of the fingerprint change, it is very probable that the fingerprint will become unique. We also confirm that the current evolution of web technologies is benefiting users» privacy significantly as the removal of plugins brings down substantively the rate of unique desktop machines.
Alejandro Gómez-Boix, Pierre Laperdrix, Benoit Baudry
WWW2
2016 Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser Fingerprints
abstract
International audience
Pierre Laperdrix, Walter Rudametkin, Benoit Baudry
IEEE Symposium on Security and Privacy1