Firewall3D Watches Printer Hardware for Firmware Tampering

By on July 21st, 2026 in news, research

Tags: , , , , , ,

Firewall strategy for 3D printers [Source: arXiv]

A proposed hardware firewall could independently catch a 3D printer behaving differently from its GCODE.

The system, called Firewall3D, comes from researchers Seyed Ali Ghazi Asgar and Narasimha Reddy. Their paper addresses a difficult but increasingly relevant additive manufacturing security problem: firmware that has been altered to change what a machine does.

That is a different threat from a bad STL file, an incorrect slicer setting, or an operator loading the wrong material. Firmware sits far closer to the machine hardware. If it is compromised through a malicious update, an insider, or a supply chain breach, it could manipulate motion, thermal control, or other printer behavior while appearing to process an ordinary job.

For a desktop FFF machine, the immediate consequences might be a failed print, a clogged nozzle, or damaged electronics, all of which can be easily fixed. But for production operations, the concern gets considerably more serious. A subtly altered toolpath or process condition could compromise a functional printed component while leaving the operator with no obvious evidence of the change.

Checking Physical Behavior Instead of Trusting Firmware

Firewall3D takes an independent approach. Rather than relying on the printer firmware to report its own condition honestly, it continuously monitors physical layer signals and compares the observed behavior with the intended GCODE execution.

The signals identified in the abstract include stepper motor currents, end stop switches, nozzle and bed temperatures, and cooling fans. In other words, the proposed device looks for a mismatch between the job that should be running and electrical or thermal activity that suggests something else is happening.

Many existing printer safeguards are implemented in firmware itself, including thermal protection and motion limits. They are very useful controls, but they become questionable if the firmware is compromised. An external monitor potentially creates a separate chain of trust.

The researchers report experimental detection of a wide range of firmware attacks that could affect print integrity, harm printer components, or leak intellectual property. When it detects abnormal behavior, Firewall3D can trigger an alarm and halt the print, limiting the time available for an attack to cause damage.

A Useful Concept With Important Open Questions

Note that this is a research prototype, not an announced commercial product, and the paper abstract leaves several practical details unstated.

This is a new and strong idea. 3D printer operators increasingly protect design files and network access, yet a print job ultimately becomes a physical object through the use of motors, heaters, and sensors. Checking those signals against the expected command sequence is an eminently sensible way to make sabotage harder to hide.

Security in 3D printing may ultimately require watching not only the STL file and network, but also the machine itself.

Via arXiv

By Kerry Stevenson

Kerry Stevenson, aka "General Fabb" has written over 8,000 stories on 3D printing at Fabbaloo since he launched the venture in 2007, with an intention to promote and grow the incredible technology of 3D printing across the world. So far, it seems to be working!