Full Professor
University of Rennes [ESIR] · IRISA · Inria · IUF
Walter Rudametkin
Software Engineering for Privacy and Security:
Device Fingerprinting, Software Diversity, Supply Chain Security.
About
I am a Full Professor at the University of Rennes, a member of the Institut Universitaire de France, and a researcher at IRISA and Inria in the DiverSE team. I teach at ESIR, the university's engineering school.
My research lies at the intersection of software engineering, web security and online privacy. I am best known for work on browser and device fingerprinting: with colleagues I co-created Am I Unique, a reference platform for studying browser diversity that has collected millions of fingerprints, and our recent work extends device fingerprinting to the Android platform. This work has appeared at IEEE S&P, USENIX Security, PETS and WWW, and received the CNIL–Inria Privacy Protection Award in 2018.
Before Rennes I was an Associate Professor at the University of Lille (Polytech Lille, Spirals team) from 2014 to 2022, and before that a postdoctoral researcher in the DiverSE team at Inria Rennes. My PhD, at the University of Grenoble in partnership with Bull, was about keeping dynamic, component-based applications consistent while they are reconfigured — a theme that still shapes how I think about software diversity today.
News
- Very happy that “EXADPrinter: Semi-Exhaustive Permissionless Device Fingerprinting Within the Android Ecosystem”, written with Sihem Bouhenniche and Pierre Laperdrix, was accepted at PETS 2026 in Calgary.
- The journal version of DrawnApart is out: “A Device Identification and Spoofing Detection Technique Based on Remote GPU Fingerprinting”, with Tomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk, Pierre Laperdrix, Clémentine Maurice, Yossi Oren, Romain Rouvoy and Yuval Yarom, in ACM Transactions on Privacy and Security.
- New preprint: “On the Internet, Nobody Knows You’re an LLM Bot: Unmasking Web Agents with Multi-Layer Fingerprinting”, with Iliana Fayolle, Sihem Bouhenniche, Samuel Pélissier, Pierre Laperdrix and Clémentine Maurice. Six LLM-based web agents against honeysites: some bypass every anti-bot mechanism we tried, all can be told apart from humans — and from each other — with network, HTTP and browser fingerprinting, and stealth features tend to make them more detectable.
- Proud that our paper “FP-Rainbow: Fingerprint-Based Browser Configuration Identification”, written with Maxime Huyghe and Clément Quinton, was accepted at WWW 2025 in Sydney.
- Our paper “The Price to Play: a Privacy Analysis of Free and Paid Games in the Android Ecosystem”, with Pierre Laperdrix, Naif Mehanna and Antonin Durey, was accepted at the ACM Web Conference 2022 in Lyon — free games come with a hidden price.
- Very proud that “DrawnApart: A Device Identification Technique based on Remote GPU Fingerprinting” was accepted at NDSS 2022. A joint work with Tomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk, Pierre Laperdrix, Clémentine Maurice, Yossi Oren, Romain Rouvoy and Yuval Yarom — see also the explainer on the Am I Unique blog. Read more ›
- Happy to announce that “FP-Redemption: Studying Browser Fingerprinting Adoption for the Sake of Web Security”, written with Antonin Durey, Pierre Laperdrix and Romain Rouvoy, was accepted at DIMVA 2021.
Research
Modern software is diverse, and that diversity leaks. The same variety that makes systems adaptable also makes each browser, phone and machine recognisable. I study both sides: how to measure and exploit that diversity, and how to engineer software so that it protects people instead.
Browser & device fingerprinting
How much does a browser or a phone give away about itself? Enough to identify it without a single cookie. We measure this at scale, follow how fingerprints evolve over time, and probe hardware-level signals down to the GPU.
- Am I Unique — browser diversity in the wild, since 2014
- Browser fingerprinting: Beauty and the Beast (2016), FP-Stalker, FP-Scanner, FP-Tester (2018), FP-Crawlers (2020), FP-Redemption (2021), FP-Rainbow (2025)
- Hardware fingerprinting from unprivileged web APIs: DrawnApart (2022, explainer; follow-up, 2026)
- Android: Price to Play — trackers (2022); EXADPrinter — device fingerprinting (2026)
Software engineering for privacy & security
Privacy properties are decided in code. We analyse the fingerprinting surface of browsers and applications at the source level, evaluate the protections that browsers actually ship, and design countermeasures that break tracking without breaking the web.
- Source-level analysis of the fingerprinting surface
- Countermeasures and how to evaluate them — e.g. Blink (2015), fingerprint randomisation with virtual machines
- Privacy as a software-engineering concern: variability, diversification, tooling
Software diversity & dynamic systems
My thesis, Robusta, and the self-adaptive systems work that followed dealt with keeping component-based software consistent while it is reconfigured at runtime. Today that same diversity is the raw material of fingerprinting.
Career
- Member, Institut Universitaire de France (IUF), October 2022 – September 2027.
- Habilitation à diriger des recherches (HDR), University of Lille: Improving the Security and Privacy of the Web through Browser Fingerprinting. Manuscript (HAL) Slides
- Associate Professor, University of Lille — Polytech Lille; Spirals team (Inria / CRIStAL).
- Postdoctoral researcher, Inria Rennes — DiverSE (formerly Triskell) team.
- Studies — B.Sc. in Computer Science, Universidad Autónoma de Baja California (Mexico); engineering degree, Grenoble INP–ENSIMAG, and M.Sc., Université Joseph Fourier (Grenoble), through the Programa de Ingenieros en Francia exchange. Master's thesis Slides
Get in touch
For teaching and administrative matters: walter.rudametkin@univ-rennes.fr
University of Rennes
263 avenue du Général Leclerc
35000 Rennes, France
Office F333