A team of researchers from the University at Buffalo in New York has discovered an attack on 3D printers that uses just a smartphone.
Attackers only need to "tweak" their smartphone's software and place the device up to 30 centimeters away from a 3D printer.
The phone's sensors collect electromagnetic information and related sound waves coming from the 3D printer and the printing nozzle.
After collecting the data on their phone, an attacker can later download it and reconstruct it into a 3D model.
Researchers say that during tests they were able to steal data from a 3D printer with 94 percent accuracy for simple objects, such as a door stopper.
For more complex objects, such as car parts or medical devices, the accuracy was lower, but still above 90 percent.
The researchers also report that the majority of the data coming from the electromagnetic waveswas recorded outside the 3D printer nozzle. This represented 80 percent of the total data collected.
As 3D printing is expected to become a multi-billion dollar business, the researchers recommend that 3D printer companies and vendors implement defenses against the attack they are facing.
First of all, 3D printers should be isolated and businesses should not allow staff to easily get close to these devices. The researchers noted that accuracy was only high when the smartphone was placed up to 30 centimeters away from a device. When the distance was increased to 40 centimeters, accuracy dropped to 66 percent.
Another way to improve the safety of 3D printers is for 3D printer vendors to develop software that varies the speed of the printer's nozzle. By varying the speed, there will be a wide variety of electromagnetic and noise levels coming from the device, rather than the uniform levels that devices emit now. Scientists say that the faster the speed, the harder it is for smartphone sensors to collect the necessary data.
The research paper, titled “My Smartphone Knows What You Print: Exploring Smartphone-Based Side-Channel Attacks Against 3D Printers,” was written by Xu et al. and will be presented at the 23rd Annual Conference on Computer and Communications Security of the Association for Computing Machinery in October in Austria.

