Protecting Additive Manufacturing: How Digital Twins Combat Cyberattacks
For the past five years, the IBM X-Force Threat Intelligence Index has consistently identified manufacturing as the most vulnerable industry to cyberattacks. In 2026, this sector experienced 27.7% of all cyber incidents, a slight increase from the previous year’s 26%. The financial consequences of these attacks are substantial. According to Arctic Wolf, the median cost of a ransomware attack on a manufacturing company, as managed by their Incident Response team, reached $600,000 in 2026. However, total losses can easily escalate into the millions when considering downtime, reputational damage, and other associated expenses.
Given these escalating threats, what proactive measures can manufacturers take to bolster their defenses? A team of engineers at Rutgers University has developed a novel approach to safeguard additive manufacturing systems, particularly those involved in producing critical components for national security and essential infrastructure. Rajiv Malhotra, an associate professor in the Rutgers School of Engineering’s Department of Mechanical and Aerospace Engineering, co-authored a research paper on this topic, published in the Journal of Manufacturing Systems. The research introduces a digital twin framework meticulously designed to enhance manufacturing resilience against cyber threats. To fully appreciate the significance of this approach, it is essential to first understand the underlying reasons why manufacturing has become such a prime target for cybercriminals.
The digital twins were able to ensure that printing was corrected. (Image credit: Cleeman et al.).
The Allure of Manufacturing: Why Cyberattacks Target the Industry
Several key factors contribute to the manufacturing industry’s vulnerability and attractiveness to cyberattacks. Cybersecurity experts at Arctic Wolf highlight the industry’s dependence on highly interconnected systems as a significant weakness. Many of these systems rely on legacy software that was not originally designed with modern cybersecurity protocols in mind, making them susceptible to exploitation by malicious actors.
Furthermore, the manufacturing sector occupies a pivotal position within global supply chains. A successful cyberattack on a manufacturing entity can have cascading effects, disrupting operations for thousands of downstream suppliers and customers. This widespread disruption places immense pressure on affected companies to swiftly restore operations, often leading them to consider paying ransom demands to expedite the recovery process. Beyond the immediate ransom payment, the cost of downtime can quickly accumulate, reaching millions of dollars. This combination of factors – the potential for lucrative ransom payments and the high cost of operational disruptions – makes the manufacturing sector an appealing target for cybercriminals. Another significant aspect is the value of intellectual property. Sensitive design files, detailed blueprints, and proprietary manufacturing processes hold considerable monetary value. When stolen and resold on the black market, this intellectual property can prove to be just as profitable as direct ransom payments, further incentivizing cyberattacks on manufacturing companies.
The Impact of Cyberattacks on Additive Manufacturing
In the context of additive manufacturing (AM), the consequences of cyberattacks can manifest in subtle and insidious ways. According to the research team at Rutgers University, attackers can manipulate digital design files to introduce geometric imperfections, such as the omission of fillets, which are crucial for stress distribution. Alternatively, they can alter critical process parameters, leading to the creation of internal voids or other structural flaws within the printed part. These seemingly minor alterations can be extremely difficult to detect through conventional inspection methods but can significantly compromise the overall performance and reliability of the final product.
Professor Malhotra explained that traditional cybersecurity approaches typically rely on identifying and reporting the security breach, followed by a complete shutdown of the production line. While this method aims to contain the damage, it can be extremely time-consuming, potentially delaying production for weeks before operations can be safely resumed. This extended downtime can have severe repercussions for manufacturers, especially those involved in time-sensitive projects or those with demanding production schedules.
The innovative method proposed by the Rutgers researchers offers a fundamentally different approach. Instead of halting production entirely, the focus is on maintaining operational continuity, even while a cyberattack is in progress and has not yet been fully resolved. This proactive and resilient strategy aims to minimize disruptions and ensure that critical manufacturing processes can continue uninterrupted, thereby mitigating the potential financial and operational losses associated with cyberattacks.
These digital twins “work in tandem to create resilience at key points of the manufacturing digital chain where cyberphysical attacks might occur – such as the part model, machine firmware and the process plan generation software,” Malhotra said. By creating a virtual representation of the entire manufacturing process, these digital twins can provide real-time monitoring and detection of any anomalies or deviations that may indicate a cyberattack.
The Power of Dual Digital Twins: Geo-DT and Pro-DT
To achieve this unprecedented level of resilience, the researchers have developed a sophisticated dual digital twin (DT) framework capable of detecting and correcting defects during the additive manufacturing process in real-time. This framework comprises two distinct but interconnected components: the geometry-focused digital twin (Geo-DT) and the process digital twin (Pro-DT).
The Geo-DT leverages a physics-based soft sensing approach, coupled with advanced topology optimization techniques, to identify and rectify any shape deviations that may occur during the printing process. This component acts as a virtual inspector, continuously monitoring the geometry of the printed part and automatically correcting any discrepancies that arise due to cyberattacks or other unforeseen events. Crucially, the Geo-DT can function effectively even without access to the original design file or knowledge of the specific alterations introduced by an attacker.
The Pro-DT, on the other hand, integrates defect detection capabilities with a sophisticated reinforcement learning model. This allows the system to adapt to changing conditions and respond to defects in real-time, optimizing process parameters to mitigate the impact of cyberattacks. The Pro-DT is capable of learning from experience, constantly refining its strategies to minimize the occurrence of defects and improve the overall quality of the printed parts. By combining defect detection with adaptive process control, the Pro-DT ensures that the manufacturing process remains stable and reliable, even in the face of unexpected disruptions.
The researchers rigorously tested the performance of their dual digital twin system on a real additive manufacturing setup. The results demonstrated that the Geo-DT was capable of effectively correcting geometric flaws, even when the original design file was unavailable or when the nature of the attack was unknown. Simultaneously, the Pro-DT demonstrated its ability to quickly respond to and mitigate defects, even when the process was subjected to unpredictable changes and disruptions. This adaptability to unknown attacks is a critical feature of the system, ensuring that it can remain effective against a wide range of cyber threats.
A graphical abstract of the study (Image Credit: Cleeman et al.)
Looking ahead, Professor Malhotra indicated that the research team plans to expand the scope of their investigations to address attacks targeting sensor signals, as well as broader safety concerns related to both machine operation and operator safety. They also intend to explore the potential of hybrid manufacturing systems, combining additive and subtractive manufacturing processes, to provide even more comprehensive protection against defects caused by cyberattacks. The integration of multiple manufacturing techniques could offer a multi-layered defense strategy, making it significantly more difficult for cybercriminals to compromise the integrity of the manufacturing process.
The research project was initiated in September 2024, with generous funding and support from the National Science Foundation and the U.S. Department of Energy. For a more in-depth examination of the research underpinning this groundbreaking approach to cybersecurity in additive manufacturing, the complete study can be accessed here. This study provides a detailed account of the methodology, experimental setup, and results, offering valuable insights for researchers and practitioners in the field of additive manufacturing and cybersecurity.
What are your thoughts on this cutting-edge cybersecurity method? Share your opinions in the comments section below or on our LinkedIn and Facebook pages. Don’t forget to subscribe to our free weekly Newsletter to receive the latest updates and insights on 3D printing directly to your inbox. You can also explore our extensive collection of videos on our YouTube channel, covering a wide range of topics related to additive manufacturing and related technologies.
*Cover Image: AI-generated illustration created with DALL·E (OpenAI)