Side channels are unintended sources of information leakage from a system that may be exploited to infer otherwise hidden and sensitive information. Side-channel sources can be physical (i.e., relying on timing variations, power consumption, electromagnetic emanations, or acoustic signals) or microarchitectural (i.e., relying on observable effects caused by shared hardware resources and processor performance optimizations). This thesis focuses on microarchitectural side channels because of their practical relevance in modern computing systems, their accessibility to attackers, and the extensive research they have attracted over the past two decades. This sustained research effort has produced a vast literature describing new attack techniques, vulnerabilities, and mitigations, often evaluated using diverse methodologies and metrics. Despite these advances, the practical adoption of side-channel analysis tools by developers remains limited. In parallel, the rise of LLM-based bots is creating new threats for websites and online services and raising questions about the effectiveness of existing defenses. This thesis addresses these challenges through three complementary contributions. First, this thesis presents a systematic study of evaluation methodologies used in the microarchitec- tural side-channel literature, analyzing 83 papers from leading security and architecture venues. The study identifies recurring flaws that limit the completeness, relevance, soundness, and reproducibility of published results. Based on these observations, the thesis derives key evaluation principles and proposes recommendations to improve future side-channel research. Second, the thesis explores how developers can be encouraged to adopt constant-time program- ming practices. Second, this thesis explores how side-channel analysis tools can be made more accessible to developers and how to encourage them to adopt constant-time programming practices. It enhances Microwalk, a JavaScript side-channel analysis framework, with support for modern language features, semi-automatically generated analysis templates, and an interpretable reporting system combining vulnerability findings with code-coverage information. These improvements reduce the effort required to integrate side-channel analysis into development workflows, provide insights applicable to other tools and programming languages, and lead to the discovery of previously unknown vulnerabilities in modern JavaScript cryptographic libraries. Third, this thesis evaluates the effectiveness of modern anti-bot mechanisms and multi-layer fingerprinting against emerging LLM-based Web Agents. A large-scale honeypot infrastructure is used to assess multiple protection mechanisms and collect network and browser fingerprints from human users, traditional bots, and Web Agents. While some Web Agents successfully bypass all evaluated defenses, they consistently expose identifiable characteristics in at least one fingerprinting layer. By combining these signals, the proposed classification approach achieves near-perfect identification accuracy, highlighting the effectiveness of multi-layer fingerprinting for detecting LLM-based Web Agents. Taken together, these contributions advance the state of the art in side-channel research by address- ing challenges related to attack benchmarking practices, vulnerability detection, and fingerprinting- based anti-bot mechanisms. They improve our understanding of side channels across multiple layers of modern computing systems, while providing methodological guidance for the community, practical tools to facilitate the adoption of secure development practices, and new insights into the detection of increasingly sophisticated bots.
Mme Clémentine MAURICE Chargée de recherche CNRS Directrice de thèse, Mme Tamara REZK Directrice de recherche INRIA Sophia Antipolis Rapporteure, M. Davide BALZAROTTI Full professor EURECOM Rapporteur, M. Gilles GRIMAUD Professeur des universités Université de Lille Examinateur, M. Herbert BOS Full professor Vrije Universiteit Amsterdam Examinateur, M. Olivier LEVILLAIN Maître de conférences Télécom SudParis Examinateur, M. Walter RUDAMETKIN Université de Rennes Invité.
Thesis of the team Spirals defended on 01/10/2026