EDBT 2026 Demo / reviewers in the wild / expert
Samuel Pélissier
dblp:320/0145
· DBLP profile ↗
6ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-3554-2585ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Users Pay Twice: The Hidden Energy Cost of Web AdvertisingabstractInternational audience Samuel Pélissier, Naif Mehanna, Sterenn Roux, Quentin Perez, Walter Rudametkin, Johann Bourcier, Pierre Laperdrix |
WWW | 1 |
| 2026 | Gotta Catch 'em all: On the Web Tracking Practices of a Deal-Sharing Conglomerate and their Heavy Reliance on Redirect ChainabstractAffiliate marketing is a growing performance-based marketing arrangement in which affiliates are rewarded for getting users to register, purchase, or visit a shopping website [ 16 , 38 ]. This marketing strategy is valued at $18.5 billion USD for 2025 [ 31 , 67 ]. Deal-sharing platforms take advantage of this marketing strategy by acting as storefronts for sellers that showcase promotions and deals. As the service is free to use, they earn commissions through affiliate links [ 36 ] when they lead to sales. We perform an in-depth, end-to-end study of the tracking techniques leveraged by Pepper [ 1 ] and its extended environment, a key player in deal-sharing platforms. Through a systematic 1-month crawl, we analyze the tracking ecosystem of 10 deal-sharing websites active in a diverse range of countries abiding by different privacy laws. Our analysis reveals that a significant part of the tracking occurs during redirect chains [ 40 ] between the deal-sharing platform and the shopping website. We quantify the tracking-specific use of cookies, CNAME cloaking [ 14 ], and link decorations [ 52 , 58 ] within redirect chains. We find that 67.9% of redirect chains leverage at least one of these additional tracking techniques. We show that redirect chains examined in prior work (limited to HTTP-based redirects) are significantly more constrained than those observed in our study (HTTP-, HTML-, and JS-based), which enable more aggressive behavior by dynamically loading additional tracking resources at runtime. Finally, by analyzing the ecosystem of third-party services and the privacy policies of deal-sharing websites, we reveal the omission of numerous actors involved in redirect chains. Sterenn Roux, Samuel Pélissier, Johann Bourcier, Walter Rudametkin, Pierre Laperdrix, Naif Mehanna |
ACM Trans. Web | 2 |
| 2025 | Efficiently linking LoRaWAN identifiers through multi-domain fingerprintingabstractLoRaWAN is a leading IoT technology worldwide, increasingly integrated into pervasive computing environments through a growing number of sensors in various industrial and consumer applications. Although its security vulnerabilities have been extensively explored in the recent literature, its ties to human activities warrant further privacy research. Existing device identification and activity inference attacks are only effective with a stable identifier. We find that the identifiers in LoRaWAN exhibit high variability, and more than half of the devices use them for less than a week. For the first time in the literature, we explore the feasibility of device fingerprinting in LoRaWAN, allowing long-term device linkage, i.e. associating various identifiers of the same device. We introduce a novel holistic fingerprint representation utilizing multiple domains, namely content, timing, and radio information, and present a machine learning-based solution for linking identifiers. Through a large-scale experimental evaluation based on real-world datasets containing up to 41 million messages, we study multiple scenarios, including an attacker with limited resources. We reach 0.98 linkage accuracy, underscoring the need for privacy-preserving measures. We showcase countermeasures including payload padding, random delays, and radio signal modulation, and conclude by assessing their impact on our fingerprinting solution. Samuel Pélissier, Abhishek Kumar Mishra 0001, Mathieu Cunche, Vincent Roca, Didier Donsez |
Pervasive Mob. Comput. | 1 |
| 2024 | Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short?abstractRecent years have seen widespread adoption of consumer Internet of Things (IoT) devices, offering diverse benefits to end-users, from smart homes to healthcare monitoring, but raising serious privacy concerns. To address this, securing efforts, such as encrypting DNS, have been proposedIn this paper, we study the effectiveness of such measures in the specific context of ensuring IoT privacy. We introduce a device identification attack against DNS-over-HTTPS-enabled IoT devices. We conduct more than 25,000 automated experiments across 6 public DNS resolvers and find that the proposed attack can identify devices via DNS-over-HTTPS (DoH) traffic with a 0.98 balanced accuracy. We point out padding as a mitigation technique that reduces identification by a significant 33%. Additionally, we find that half of the evaluated DNS resolvers do not adhere to the relevant specification, substantially compromising user privacy. Samuel Pélissier, Gianluca Anselmi, Abhishek Kumar Mishra 0001, Anna Maria Mandalari, Mathieu Cunche |
TrustCom | 1 |
| 2024 | Privacy-Preserving Pseudonyms for LoRaWANabstractLoRaWAN, a widely deployed LPWAN protocol, raises privacy concerns due to metadata exposure, particularly concerning the exploitation of stable device identifiers. For the first time in literature, we propose two privacy-preserving pseudonym schemes tailored for LoRaWAN: resolvable pseudonyms and sequential pseudonyms. We extensively evaluate their performance and applicability through theoretical analysis and simulations based on a large-scale real-world dataset of 71 million messages. We conclude that sequential pseudonyms are the best solution. Samuel Pélissier, Jan Aalmoes, Abhishek Kumar Mishra 0001, Mathieu Cunche, Vincent Roca, Didier Donsez |
WISEC | 1 |
| 2022 | Device Re-identification in LoRaWAN through Messages LinkageabstractIn LoRaWAN networks, devices are identified by two identifiers: a globally unique and stable one called DevEUI, and an ephemeral and randomly assigned pseudonym called DevAddr. The association between those identifiers is only known by the network and join servers, and is not available to a passive eavesdropper. Samuel Pélissier, Mathieu Cunche, Vincent Roca, Didier Donsez |
WISEC | 1 |