Actuator Current Monitoring for Stealthy ALM Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-security measures in additive layer manufacturing (ALM) are inadequate to detect stealthy tampering attacks that alter machine behavior, posing risks to safety-critical systems, as they are costly, time-consuming, and prone to evasion by sophisticated adversaries.

Innovation Solution

A probabilistic model using Hall effect sensors and Bayesian logistic regression is deployed to monitor actuator current signals, analyzing phase synchrony to distinguish between normal and altered machine behavior, providing real-time anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional quality control methods (X-ray imaging, non-destructive stress testing) are used to detect alterations, then detection capability is improved, but cost and time consumption increase significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces physical inspection methods (X-ray imaging, stress testing) with electrical signal analysis. By monitoring actuator current signals and comparing them against expected patterns, the system detects alterations without physical intervention, thereby reducing both time and cost while maintaining detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates an electrical signature (copy) of normal machine behavior through current signal patterns. This signature serves as a reference model that can be quickly compared against actual operation signals to detect deviations, eliminating the need for time-consuming physical verification methods.

Inventive Principle:
Principle #26Copying

2Measurement precision

If current quality control methods are used, then some alterations can be detected, but sophisticated attackers can evade detection through carefully tailored alterations

Engineering Contradiction:
Improvedetection capabilityVSAvoidevasion by attackers
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors actuator current signals and provides real-time feedback against the electrical signature. This continuous feedback loop enables detection of subtle, sophisticated alterations that deviate from expected behavior patterns, making it difficult for attackers to evade detection through carefully tailored modifications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system analyzes multiple electrical parameters (current magnitude, frequency content, temporal patterns) simultaneously rather than relying on a single measurement. This multi-dimensional analysis exceeds the capability of simple alteration techniques and detects even subtle deviations in machine behavior.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If next-generation quality control techniques with high-resolution sensors are deployed, then measurement resolution is improved, but visibility gaps and bias in sensor placement remain

Engineering Contradiction:
Improvesensor resolutionVSAvoidvisibility gaps
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system uses existing actuator current signals that are already present in the control system for multiple purposes: both for normal motor control and for security monitoring. This eliminates the need for additional sensors and their associated placement issues, while still achieving high-resolution detection of alterations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system leverages the machine's own operational signals (actuator currents) to monitor its own health and security status. By using signals that naturally exist during operation, the system avoids visibility gaps associated with external sensor placement while maintaining continuous monitoring capability.

Inventive Principle:
Principle #25Self-service

4Productivity

If process verification solutions are developed to be fast and automated, then productivity is improved, but detection accuracy may be compromised

Engineering Contradiction:
Improveautomation speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary analysis by continuously maintaining the electrical signature model and pre-processing signal patterns during normal operation. When an alteration is suspected, the comparison against the pre-established signature can be performed rapidly, achieving both high speed and high accuracy without compromising either parameter.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The system offers fast, accurate, and cost-effective detection of stealthy sabotage in ALM processes, reducing the risk of compromised part performance in safety-critical systems.

Implementation Method 1

A Hall effect sensor (or other suitable sensor) is clamped on to, at one end, a lead between the driver and the additive manufacturing component

Methodology Applied
Scientific EffectHall effect: Hall Effect

Data Source

PatentUS12423416B2Stealthy process attack detection for automated manufacturing
Publication Date: 2025.09.23 UT BATTELLE LLC
  • US12423416B2 patent drawing
  • US12423416B2 patent drawing
  • US12423416B2 patent drawing

AI summary

Additive manufacturing's reliance on embedded computing renders it vulnerable to tampering through cyber-attacks. Sensor instrumentation of additive manufacturing devices allows for rigorous process and security monitoring, but also results in a massive volume of noisy data for each run. As such, in-situ, near-real-time anomaly detection is challenging. A probabilistic-model-based approach addresses this challenge.