DrawnApart: GPU Manufacturing Variances Enable Persistent Device Fingerprinting
Key Takeaways
- ▸DrawnApart exploits GPU manufacturing variances for persistent device fingerprinting, solving the temporal decay problem in traditional methods
- ▸The technique effectively differentiates between devices with identical hardware and software configurations
- ▸Introduces GPU renderer verification to detect spoofing attempts and prevent device impersonation in authentication scenarios
Summary
Researchers have developed DrawnApart, a breakthrough technique for device identification that exploits GPU manufacturing variances to create persistent, unforgeable device fingerprints. Published in ACM Transactions on Privacy and Security, the work significantly advances traditional browser fingerprinting by leveraging unique GPU rendering characteristics that emerge from hardware manufacturing tolerances, enabling differentiation between devices with identical hardware and software configurations.
The research addresses a fundamental limitation of existing fingerprinting methods: temporal decay, where device fingerprints evolve over time and become confused with other similarly-configured devices. DrawnApart's GPU-based approach maintains accuracy in diverse hardware scenarios, particularly when combined with traditional fingerprinting techniques like FP-Stalker.
The technique also introduces GPU renderer string verification to detect spoofing attempts, with direct applications in two-factor authentication. This prevents attackers from bypassing security by mimicking a victim's device attributes, creating a new defense mechanism against device impersonation attacks.
- Represents an extended journal version of work originally presented at NDSS 2022
Editorial Opinion
DrawnApart represents impressive technical progress in device identification, but it raises urgent privacy concerns. While the spoofing detection capabilities enhance security, the technique's ability to create nearly-persistent device fingerprints enables sophisticated tracking users may not consent to or understand. As fingerprinting techniques grow more sophisticated, browser vendors and regulators must weigh security gains against the surveillance risks and implement stronger privacy protections.



