Professional Documents
Culture Documents
Scanners
Zhengxiong Li*1 , Aditya Singh Rathore*1 , Chen Song1 , Sheng Wei2 , Yanzhi Wang3 , Wenyao Xu1
1 CSE Department, SUNY University at Buffalo, Buffalo, NY, USA
2 ECE Department, Rutgers University, Piscataway, NJ, USA
3 ECE Department, Northeastern University, Boston, MA, USA
ABSTRACT Security (CCS ’18), October 15–19, 2018, Toronto, ON, Canada. ACM,
As 3D printing technology begins to outpace traditional manufac- New York, NY, USA, 18 pages. https://doi.org/
turing, malicious users increasingly have sought to leverage this 10.1145/3243734.3243735
widely accessible platform to produce unlawful tools for crimi-
nal activities. Therefore, it is of paramount importance to identify 1 INTRODUCTION
the origin of unlawful 3D printed products using digital forensics. Additive manufacturing, also known as 3D printing, has become the
Traditional countermeasures, including information embedding main driving force of the third industrial revolution by fundamen-
or watermarking, rely on supervised manufacturing process and tally evolving product design and manufacturing [18, 31, 72, 93].
are impractical for identifying the origin of 3D printed tools in Due to the wide accessibility, 3D printers are increasingly exploited
criminal applications. We argue that 3D printers possess unique by malicious users to manufacture unethical (e.g., counterfeiting
fingerprints, which arise from hardware imperfections during the a patented product) and illegal products (e.g., keys and gun parts),
manufacturing process, causing discrepancies in the line formation shown in Figure 1 [42, 80, 88, 90]. To date, 3D printing has raised a
of printed physical objects. These variations appear repeatedly and host of unprecedented legal challenges since it could be utilized for
result in unique textures that can serve as a viable fingerprint on fabricating potential untraceable crime tools, making the conven-
associated 3D printed products. To address the challenge of tradi- tional forensic techniques infeasible in identifying the adversary.
tional forensics in identifying unlawful 3D printed products, we
present PrinTracker, the 3D printer identification system, which can
precisely trace the physical object to its source 3D printer based on
its fingerprint. Results indicate that PrinTracker provides a high ac-
curacy using 14 different 3D printers. Under unfavorable conditions
(e.g. restricted sample area, location and process), the PrinTracker
can still achieve an acceptable accuracy of 92%. Furthermore, we
examine the effectiveness, robustness, reliability and vulnerability
of the PrinTracker in multiple real-world scenarios.
KEYWORDS
Embedded Systems; Manufacturing Security; Forensics
ACM Reference Format: Zhengxiong Li, Aditya Singh Rathore, Figure 1: Potential untraceable 3D printed objects acquired
Chen Song, Sheng Wei, Yanzhi Wang, and Wenyao Xu. 2018. PrinT- from the crime scene [4, 15].
racker: Fingerprinting 3D Printers using Commodity Scanners. In
2018 ACM SIGSAC Conference on Computer and Communications Concerned about the misuse of 3D printing technology, the U.S.
Department of State urged International Traffic in Arms Regula-
* The first two authors contribute equally to this work. tion (ITAR) to limit the proliferation of 3D printed criminal tools.
However, these regulations have a varying degree of efficacy and
Permission to make digital or hard copies of all or part of this work for personal or
classroom use is granted without fee provided that copies are not made or distributed are inadequate to deal with the rapid growth of 3D printers [27].
for profit or commercial advantage and that copies bear this notice and the full citation Given the deficiency of law-enforcement agencies in preventing
on the first page. Copyrights for components of this work owned by others than ACM high-impact criminal activities [11, 13, 54, 55], the ability to iden-
must be honored. Abstracting with credit is permitted. To copy otherwise, or republish,
to post on servers or to redistribute to lists, requires prior specific permission and/or a tify the source 3D printer, similar to digital image forensics [77], can
fee. Request permissions from permissions@acm.org. immensely aid the forensic investigation. Unfortunately, no tool ex-
CCS ’18, October 15–19, 2018, Toronto, ON, Canada ists for this application in either the computing or manufacturing
© 2018 Association for Computing Machinery.
ACM ISBN 978-1-4503-5693-0/18/10. . . $15.00 literature. It is possible to alter the 3D printing process and add iden-
https://doi.org/10.1145/3243734.3243735 tifiable watermarks in either material [21, 63] or process patterns
(e.g., object tagging [68]). Nevertheless, these techniques are not intrinsically “contained" in its printed objects. By utilizing the fin-
applicable to the 3D printing forensics because the adversary can gerprint extracted via a commodity 2D scanner, PrinTracker can pre-
conveniently access the 3D printer, including design files, and op- cisely trace a printed object to its source printer. More importantly,
erate it himself without any external supervision. Moreover, these it can be immediately applied in real-world forensic applications
techniques lack support for existing 3D printed objects that have without any additional components or design modifications.
already been manufactured without any watermarks [10]. Summary: Our contribution in this work is three-fold:
It is a known fact that the variations arising from the mecha- • We conduct the first investigation of a 3D printer’s fingerprint.
tronic process are inevitable. In every manufacturing technique, Specifically, we empirically model the intrinsic connection be-
these variations, typically observable on the resulting products, tween the 3D printer hardware imperfections and the textures
can serve as an intrinsic signature or fingerprint of the source on the associated printed product, which can be utilized as a
manufacturing device. Existing studies demonstrate the presence viable fingerprint.
of a concise signature on each paper that uniquely identifies the • We explore and implement an end-to-end 3D printing foren-
source document [28, 34, 70]. Furthermore, complementary metal- sic system, PrinTracker, which is an immediately deployable
oxide-semiconductor (CMOS) process variations can be utilized as a solution and pertinent to 3D printed objects universally and
physically unclonable method for silicon device identification [86]. economically.
Based on the mentioned literature, we hypothesize that each 3D • We demonstrate the effectiveness, reliability and robustness of
printed product should possess a unique fingerprint and products PrinTracker through extensive experiments using 14 3D print-
from the same 3D printer will observe shared features in their fin- ers. Under unfavorable conditions (e.g. restricted sample area,
gerprints. If the hypothesis holds, a forensic identification system location and process), PrinTracker can achieve an acceptable
can be developed to retrieve the provenance of the criminal tool, i.e., accuracy of 92%. We conduct further experiments to demon-
the 3D printed product, acquired from the crime scene. The system strate the resilience of PrinTracker against multiple attacks with
can provide unprecedented advantages in forensic applications: varying threat levels.
(1) it benefits the law-enforcement and intelligence agencies by
identifying the source 3D printer leveraged by the adversary; (2) it 2 3D PRINTER PRELIMINARIES
serves as a fundamental solution for authentication of counterfeited
products, preventing the substantial loss of intellectual property. 2.1 Background and Fingerprint Hypothesis
To realize this, the fingerprint of a 3D printer should possess spe- Presently, 3D printers based on the Fused Deposition Modeling
cific properties that are consistent across the 3D printing domain. (FDM) technology are the most widely used type in commodity
Firstly, 3D printed products fabricated from the same 3D printer 3D printers [53]. As our work is a consolidation of empirical and
need to comprise common features in their fingerprint. Secondly, theoretical efforts, we describe the fingerprint hypothesis using
distinct features would be observed in the 3D printed products an FDM-type printer for better understanding. Our approach is
from distinct 3D printers. Finally, the fingerprint should be uni- also compatible with other printing technologies since every 3D
versal and cannot be spoofed by the adversary. To validate this printer possesses unique variations based on the corresponding
hypothesis, we address the three main challenges in the current mechatronic structure. These variations are inevitable and originate
3D printing paradigm: (1) there is no in-depth study to prove the from the hardware imperfections in the mechanical components.
presence of a fingerprint on a 3D printed object that can establish 3D printing is an add-on process where the successive extrusion
its correlation to a corresponding printer. Moreover, the 3D printer of material forms the lines and stack of these lines build the ob-
is a complex system comprising numerous hardware interactions, ject. In addition, the superposition of lines determines the surface
thereby increasing the challenge in identifying the precise source attribute of the printed object. The hardware architecture of the
of the fingerprint; (2) for developing a universal and cost-effective FDM-type printer is shown in Figure 2. It primarily includes three
3D printing forensic tool, the fingerprint must exist in each printed parts according to different physical functions, i.e., Feeder, Posi-
object and can be retrieved without damaging the physical object. tioner and Hot end. The control system regulates Feeder, Hot end
In addition, the fingerprint must be resilient to the potential at- and Positioner and governs the working process, according to the
tacks employed by the adversary; (3) in forensic applications, it is instructions present in the design file, commonly known as G-code,
strenuous to design a robust forensic tool while ensuring low com- and the sensor feedback.
putational cost, operational correctness and exceptional accuracy. Variation from Feeder: The role of the Feeder is to feed the spec-
In this work, we first validate the existence of the fingerprint ified material, varying for each printer type, into the material con-
by studying the source of inevitable variations during the printing veyance channel. It includes the feed motor which uniformly moves
process. We investigate a low-cost fingerprint extraction technique filament through Hot end. However, there are limitations in pre-
capable of precisely measuring the minute textures of the object’s cision, such as the motor step size that results in variations [9].
surface while causing no damage to the physical object. Subse- Moreover, the feeding friction varies due to the irregular V-shaped
quently, we perform an extensive attack evaluation to assess the slots on the friction wheel, thereby inciting fluctuations in the
security of our proposed system and the underlying fingerprint. steady-state error and response time of the Feeder [91]. These
Finally, we present PrinTracker, an end-to-end 3D printer identifi- discrepancies lead to unsteady volumetric flow (line width) of the
cation system, which can effectively reveal the 3D printer identity extruded filament during the printing process.
Variation from Positioner: It governs the spatial movement of
the nozzle in the X-Y-Z direction. Its primary components include
belt transmission, a screw rod, three stepper motors (X, Y, Z axis) skimmer, cartridge case or magazine) or is unable to retrieve the
and a platform. During the printing process, the fluctuations in broken object due to certain circumstances (e.g., grenade debris
the rotor position of the stepper motor and the synchronous belt or broken key in the lock cylinder). He may also employ various
transmission affect the line trajectory vector (XY axis) of the noz- preventive strategies, further discussed in Section 9. Meanwhile,
zle, while the error in the screw rod disturbs the positioning of the forensic team investigating the crime scene discovers the object
the platform (Z axis) [71]. Moreover, the kinematics of Positioner and needs to track down the adversary. For instance, a malicious
determines the trajectory of Hot end, implying that imperfections card reader (with a 3D printed card skimmer) has been discovered
in Positioner misalign Hot end to some extent. attached to the real payment terminals [3] shown in Figure 3. A
Variation from Hot End: As a primary component of the 3D list of prominent suspects is prepared from the limited evidence
printer, Hot end comprises a nozzle through which the melted ma- acquired from the crime scene and stranded 3D printers are secured
terial is extruded forming a line, repeatedly. To control the heating from the suspects’ locality. However, the forensic team encounters
temperature of the filament, the most optimal and widely used several challenges in narrowing down the scope of the investigation.
algorithm is the proportional-integral-derivative (PID) control or PrinTracker is proposed to solve the issue. Specifically, PrinTracker
the fuzzy control [89]. However, both of them can dynamically utilizes the object’s texture and extracts the associated 3D printer’s
stabilize the heating temperature only within an accepted range, fingerprint contained inside, which acts as a traceable identifier for
which results in non-uniform material fusion and unsteady extrusion its source 3D printer. After obtaining the 3D printer ID, the forensic
amount. team can match it with the secured printers to reveal the 3D printer
Hypothesis: Owing to the hardware imperfections in the above Jack used to fabricate the criminal tool. It is worth mentioning that
mechanical components, the variation caused by the system inte- PrinTracker can provide the auxiliary information in the presence
gration leads to a substantial impact on the printing [83]. While of other conclusive evidence to identify the adversary.
the printing performance might remain unaffected, these discrep- In our work, we assume that the 3D printed object can be re-
ancies are sufficient to alter the line formation of the printed object trieved from the crime scene and it contains a measurable finger-
and induce a unique and measurable fingerprint which is associ- print. Furthermore, we assume that the adversary will not destroy
ated with the mechatronic structure of the source 3D printer. Each the 3D printer prior or after committing the crime. These assump-
printing process on a specific 3D printer is different; however, the tions are practical since even prominent biometric applications
fingerprint is consistent and repeatable due to the inevitability of (e.g., face, fingerprint) are infeasible under the identical scenario. A
hardware imperfections in the mechanical components according non-invasive solution to address the sabotage of 3D printer would
to their processing level [66]. We further illustrate the influence of be to ensure that the proprietors of 3D printers, including Jack,
3D printer variation on a 3D printed object in Section 3. pre-register the associated printers, along with the images of its
printed models, in the PrinTracker database. These images will be
updated at frequent intervals to ensure that the contained finger-
print is consistent with any alterations of the respective 3D printer.
The update frequency is out of scope for this paper and is retained
for the future work. During the investigation, the forensic team can
easily compare the criminal tool’s fingerprint with the PrinTracker
database to identify the adversary.
6 3D PRINTER IDENTIFICATION including the use of a foreign device by the adversary that is not
In our work, we employ a surface-based classification model instead previously registered by the identification system. To address these
of image-based, due to the distinction of a scanned image from challenges, we introduce an alien device detection model to evaluate
the one obtained using a camera or a smartphone. In practical the performance of the classification model.
forensic application, we face a variety of constrained situations,
K-Nearest Neighbor (KNN), that can be leveraged to identify 3D
printers based on the fingerprint. Previously, SVM and KNN have
been successfully applied in scanner and printer identification [65]
and multi-touch authentication [73], respectively. SVM locates an
optimal hyper-plane in a high-dimensional space to perform the
classification, while KNN stores all available cases and classifies
new cases based on a similarity measure.
During the training phase, n scanned images of printed objects
are obtained from m 3D printers. Each scanned image has a feature
vector, and nm sets of feature vectors are used to train the classifier.
We employ an ensemble classification approach for training, mainly
to achieve robustness over any single classification model. For the
Figure 7: The two types of texture on a 3D printed object. testing phase, the system processes the overall predicted result for
k test scanned images to output either a positive match with one
of the 3D printers that it has been trained with or an alien device,
6.1 ID Provenance Method implying that the concerned printer is not included in the training
3D printer identification can be formulated as a multi-class clas- database. In such a case, the system initiates a training request that
sification problem. We begin by defining the key terms in the 3D collects n scanned images from the alien printer, inserts a new entry
printed objects and then formulate the 3D printer identification to the classifier database, and re-trains the system. Although false
problem. negatives might occur, additional side-information can be leveraged
Definition 1 (Object Surface Set): For a 3D printing process, let to exercise caution before re-training.
s denote an area of the object’s surface that is attained by a certain
sample method. We define surface set S to contain every possible Algorithm 1 Alien 3D printer detection model
object surfaces. Specifically, we define s 0 as a complete object’s Input: I (k): K test scan images from an object
surface that has the entire information about intrinsic signature of Thd: a threshold to distinguish the alien device
the source 3D printer. Figure 5(a) illustrates four distinct examples Output: A: A judgment if it is an alien device
of s. Therefore, R I D : The predicted classification result for the object
∀s ∈ S, ∅ ⊂ s ⊆ s 0 . (4) 1: Ci ,Ti , I ← 0 ▷ Init the parameter
Definition 2 (Surface Analysis Function): We denote the sur- 2: for i ∈ {1, . . . , K } do C(i) = Classi f y(I (k)) ▷ Classify each
face analysis function p as any function that can reflect the surface image and get K predicted results
characteristics. Therefore, let set P represent a collection of selected 3: end for
surface analysis functions: 4: T = tabulate(C(:)); ▷ Statistical analysis predicted results
5: score = max(T (:, 3)); ▷ Find the maximum probability value as
P = {p1 (), ..., pk ()}. (5)
the classification score
Definition 3 (3D Printer Classification Function): Assume C() 6: if score < Thd then
to be a classification function that utilizes several 3D printer fea- 7: disp( ′It is an alien device! ′ ) ▷ If the classification score is
tures to predict the 3D printer ID. The specific implementation of less than the threshold, it is considered as the alien device
C() responds to the real-world scenarios and the applied database 8: else
mentioned in Section 2.2. 9: I = f ind(T (:, 3) == score); ▷ Otherwise, find the one with
Formulation 1 (Fingerprint Extraction): The goal of fingerprint the maximum probability value as the final predicted result
extraction is to acquire the texture features set from the surface s. 10: R I D = T (I, 1);
Specifically, a surface analysis function, denoted by set P, is applied. 11: disp([ ′The result is : ′, R I D ]);
We define I as the result set after applying P on s: 12: end if
I(s) = {i 1 ← p1 (s), ..., i k ← pk (s)}. (6) 13: return F
Figure 8: The threshold margin for detection of alien 3D 8 MakerBot Replicator 2X FDM ABS
printers. XYZ Printing Da Vinci
9 FDM ABS
Mini Maker
XYZ Printing Da Vinci
alien. Figure 8 plots the classification scores for both alien and 10 FDM ABS
Mini Maker
trained 3D printers (the first half of the X-axis are the fingerprints
on the objects from alien devices and the second half is from trained 11 Formlabs Form 1+ SLA Photopolymer
devices). It is observed that the alien printers present a relatively 12 Formlabs Form 1+ SLA Photopolymer
low score, and a threshold for reliable segregation is not hard to 13 Formlabs Form 1+ SLA Photopolymer
find. In PrinTracker, we empirically pick one threshold (such as 90%)
14 Formlabs Form 1+ SLA Photopolymer
to separate the alien devices with high accuracy and robustness.
7 BENCHMARKING AND EVALUATION with the dimensions of 640 × 250px and the size of 90KB in PNG
In this section, we comprehensively evaluate the performance of format. In addition, to obtain substantial results, we evaluate our
PrinTracker using 14 different 3D printers. We also describe the system under each setting 10 times. Unless specified, each time we
experimental setup and performance metrics in the evaluation. randomly choose three keys out of the five keys from the individual
3D printer as our training sample set and use the rest for testing.
7.1 Test-Bench Preparation Thus, 3 × 14 × 50 = 2100 randomly chosen images are used for
Model Fabrication: 3D Printers can be leveraged to produce illegal training and 2 × 14 × 50 = 1400 images for testing individually.
tools for malicious use. To proof the concept of illegal fabrication in
3D printing, we employ the standard bump keys as the key sample
model to evaluate PrinTracker performance because (1) bump keys
are widely used but subject to counterfeiting in daily life; (2) bump
key models contain a rich set of geometric features in different
granularity levels to examine the sensitivity of PrinTracker. For the
sake of generality, we also test the performance with other object
models in Section 8.3. We employ 14 commercially off-the-shelf
3D printers, including four Ultimaker series, four MakerBot series,
two XYZ printing series and four Formlabs series. These printers
operate on two categories of most commonly used working types
(i.e., FDM and SLA) and three types of materials (i.e., PLA, ABS and
Photopolymer), as presented in Table 2. Each printer produces five
key samples with the common printing configurations. Specifically,
FDM printers support layer thickness from 60 to 600 microns, while
for SLAs it could be from 25 to 100 microns. Each key sample takes Figure 9: Experimental setup for 3D printer identification
from 40 to 60 minutes to fabricate. where bump keys are fabricated and scanned via a commod-
ity scanner.
Sample Digital Database: As shown in Figure 9, in order to ac-
quire the texture on the bump key, we employ a conveniently acces-
sible commodity scanner Canon MG2922 (US $60), equipped with
CIS, whose highest scan resolution is 1200dpi. Manually, we scan
7.2 Performance Metrics and Configuration in
the entire set of keys, one at a time, where each key is scanned for 50 Forensic Applications
times with a 600dpi resolution in an indoor environment. Thus, the Metrics: As a potential forensic tool, PrinTracker will have a sig-
sample database contains 70 bump keys and 3500 scanned images. nificant role in 3D printing forensics if it can reveal valuable infor-
Each scanned image is resized to s 0 (refer to Section 6.1), and stored mation during an unlikely scenario where it barely identifies the
3D printer. Therefore, we evaluate the classification performance 7.3 Overall Performance of Identifying 3D
from two views: V iew1: Identification of 3D printers; and V iew2: Printers
Recognition of 3D printer working types. V iew1 shows the ability
To maximize the efficiency of PrinTracker for 3D printer identifica-
to track the source 3D printer and V iew2 aids to narrow the scope
tion, a fingerprint comprising of sufficient textural characteristics,
for investigation. To evaluate PrinTracker in the following sections,
i.e., the banding and attachment texture, needs to be extracted from
we study the metrics of precision, recall, F1-measure and accuracy
the 3D printed object. However, it is not uncommon to discover only
to indicate the performance in different angles. Specifically, Preci-
a segment of an object during the forensic investigation. Therefore,
sion is the ratio of correctly predicted positive observations to the
it would be ideal for the PrinTracker to precisely identify the source
total predicted positive observations. Recall is the ratio of correctly
3D printer (V iew1) in a scenario where only one of the two textural
predicted positive observations to all observations in actual posi-
information is available. To this end, we evaluate the performance
tive class. F1-measure is the harmonic mean of precision and recall,
of V iew1 by considering individual textures for 14 printer classes. In
which is a significant measure, especially with an uneven class
the testing sample set, each class owns 100 scanned images. The re-
distribution. Accuracy is the most intuitive performance measure
sulting classification score is shown as a confusion matrix in Figure
and it is simply a ratio of correctly predicted observation to the
12(a) and 12(b). In the confusion matrix plot, the darker the color
total observations [99]. Besides, we also adopt the Equal Error Rate
contrast of a cell, the higher is the classification score. Seemingly,
(EER) and the Receiver Operating Characteristic (ROC) since these
the diagonal cells are the darkest, indicating that the fingerprint
are the optimal metrics for evaluating identification systems [26].
from a 3D printer was accurately classified to its associated class.
The ROC curve is created by plotting the true positive rate (TPR)
against the false positive rate (FPR) at various threshold settings. Performance of Banding Texture: The 3D printer identification
EER is the operating point in ROC, where FAR and the false re- results from Figure 12(a) demonstrate an average precision and
ject rate (FRR=1-TPR) are equal. The lower EER value, the better recall of 91.81% and 92.59% respectively. The F1-measure is 92.20%,
performance. while the EER is observed to be 0.076, as illustrated in Figure 11(a).
Upon careful analysis, we notice that No.5 3D printer is misclassified
McNemar Test: The performance of PrinTracker depends on the
as No.9 and No.10 3D printer even though it utilizes visibly different
design of recognition approaches. To investigate the sensitivity of
material from the other two printers. The reason is due to the nature
classification model, we perform McNemar Test towards two mostly
of our algorithm which statistically describes the textures, primarily
used classification configurations, i.e., SVM and KNN. For SVM,
based on the interleaving of material filaments, rather than their
considering the sample database is linearly inseparable, we use the
visual characteristics.
radial basis function (RBF) kernels [65]. For KNN, we test the K
configuration from 1 to 15, and K=3 achieves the best performance.
We configure KNN as K=3 in the following analysis.
Predicted
FDM SLA Recall
FDM 997 3 99.70%
Actual
SLA 0 400 100%
Precision 100% 99.26%
(a) Based on banding texture.
Area num. B1 B2 B3 B4 B5
Banding (mm2 ) 64 49 36 16 4
Area num. F1 F2 F3 F4 F5
Attachment (mm 2 ) 10 8 6 4 2
Figure 16: The classification performance for respective tex- 8.2 Reliability Analysis
tures on the keys with variation in sample locations (a)
8.2.1 Effect of Working Environment: Manufacturing room envi-
within a specific area; (b) across the whole object.
ronment control is noticeably vital in standard industry working
process. However, the individual workshop can also be the con-
8.1.3 Effect of Feature Selection: As the size and dimensionality ventional workplaces for 3D printing. To investigate the impact of
of database containing 3D printer samples increases, accessing variation in a working environment on the fingerprint, we design
which features has the greatest outcome on the PrinTracker perfor- the following experiment. We evaluate the performance of No.1,
mance can aid in saving time and resources, which is an essential 2 and 3 3D printers in four environmental setups with different
advantage during forensic investigations. In this experiment, we humidity and temperature settings. Specifically, each printer fab-
investigate the impact of feature dimension on the performance ricates three keys in each environment and each key is scanned
of our system for V iew1 and V iew2. In our work, we extract 20 15 times for the testing set. We use the training set from the sam-
features. We start with the entire set of 20 features and reduce the ple database. The results of our experiment are shown in Table
number gradually. The precision and recall for each test feature 5. The precision and recall are all 100%. Similarly, the F1-measure
are described in Figure 17. For V iew1, the precision of classifica- is 100%. The fingerprint possesses a strong tolerance to working
tion decreases from 100% to 97.92%, with the feature dimension environment within the range of 10-20◦ C temperature and 30-70%
decreasing from 20 to 5. Afterward, the precision quickly decreases humidity, and the performance of PrinTracker remains unaffected.
to 81.11%, when the feature number reduces to three. The variation 8.2.2 Effect of Printing Process Configuration: In the manufactur-
of the precision/recall increases with the decrease in the number of ing domain, a mindful selection of printing process parameters
features. A similar turning point, around the feature number 5, is is crucial for ensuring ideal product quality. Furthermore, in the
observed for V iew2. For V iew2, the precision is 99.28%, 98.25% and real-world application, the nature of these configurations are un-
86.50% for 20, 5, 3 features respectively. known for the criminal tool, i.e., the 3D printed object acquired
We further analyze the two V iews based on the five features. For from the crime scene. Therefore, it is critical for PrinTracker to
V iew1, Contrast, Cluster Prominence, Sum average, Sum Entropy precisely identify the source 3D printer, regardless of the printing
and Information Measure of Correlation1 are the essential features. parameters utilized to manufacture the 3D object. We employ the
For V iew2, we choose Cluster Prominence Maximum Probability, No.1, 2 and 3 3D printers and consider three situations with varying
Sum of Squares: Variance, Information Measure of Correlation2 and speed, resolution and print materials. There are three settings under
Sum Variance. All features are scrutinized in Table 1. Compared to each situation. In each setting, we produce three keys. Each key is
V iew2, V iew1 excessively utilizes the texture homogeneity, while scanned three times (totally 81 scanned images for each situation)
V iew2 takes advantage of deviation value among the texture [92]. and the images are then tested against the training set in the sample
Table 5: The recognition result of PrinTracker in external
environments. Note: 10◦ C=50◦ F, 20◦ C=68◦ F.
Temp. (◦ C)
10 20
30 100& 100 100& 100
Humid. (%)
70 100& 100 100& 100
*In the cell: Precision(%) & Recall(%).
database. In the speed situation, we set the nozzle speed at 120mm/s Figure 19: The system performance along the entire work
(S1), 110mm/s (S2) and 100mm/s (S3). In the resolution situation, we duration under different situations.
set the layer thickness at 0.06mm (R1), 0.1mm (R2) and 0.15mm
(R3). In the materials situation, we select three material, one 3D
Universe 2.85mm PLA in white (M1), two Ultimaker 2.85mm PLA 8.3 Robustness Analysis
in white (M2) and gray (M3). Figure 18 describes the results with 8.3.1 Effect of Objects with Different Geometries: In forensic ap-
accuracy in every situation to be higher than 99%, thereby implying plications, valuable evidence can include objects with different
that PrinTracker is resistant to the variation in printing parameters geometric shapes, such as unexploded bombs [1] and cartridge
within 120-100mm/s nozzle speed and 0.06-0.15mm layer thickness cases [55]. Therefore, it is important to investigate the robustness
in different materials. Out-of-range configuration might pose a risk of PrinTracker with various 3D prints. To this end, we conduct the
of spoofing our solution, but the products will suffer from severe further evaluation with five designs of distinct shapes and curva-
deformation and poor quality, which compromises the usability. tures, including standard car key, handcuff key, grenade, magazine
and bullet (see samples in Figure 20). For ease of evaluation, each
design is fabricated with three selected 3D printers, and each 3D
printer produces five sample copies. Other experimental procedures
are the same with above experiments, and the experimental setup is
with Table 2. As shown in Figure 20, both precision and recall in the
case of the car key, grenade and magazine are close to 100%. For all
objects, the average F1-measure is 92.20%. In comparison, the pre-
cision and recall in the case of handcuff key and bullet drop down
Figure 18: The system performance of 3D printed keys with to around 83% due to limited effective areas in scanned samples. It
different printing process parameters. is because that these two samples both have cylindrical-shape, and
commodity scanner cannot provide a high imaging quality with
8.2.3 Effect of Working Status: In practical manufacturing, the objects with the large curvature. We further discuss the specific
3D printer functions favorably without interruption. However, it solution for these curved objects in Section 10. These results show
may confront some unexpected scenarios. Three situations are an encouraging indication that PrinTracker is scalable to a large
summarized. Firstly, the 3D printer works continually without any number of objects.
interruption or intermission. Secondly, the material suffers from a
fracture during the extrusion, and new material needs to be reloaded.
Lastly, the printing process is paused owing to certain accidents and
is resumed after the situation is resolved. To examine the impact
of 3D printer working statuses on the fingerprint, we conduct the
following experiment.
We manipulate No.1, 2, 3 3D printers for 10 hours in identical
fashion. In the first six hours, we continuously produce nine keys
and have a 40 minutes break to avoid “machine fatigue” on the next
part. Then, we reload the material and continue to fabricate two
keys and have another 40 minutes break. In the last 80 minutes, we
fabricate the last two keys, while pausing in the middle of each task Figure 20: The identification performance of 3D printed ob-
for one minute. Eventually, we scan each key 15 times as the testing jects with different geometric shapes, implying the strong
set and use the training set from the sample dataset. The results of robustness of our PrinTracker.
the experiment are shown in Figure 19. The precision and recall are
both 100%, implying that the fingerprint remains consistent during
an extensive working period and is insensitive to the 3D printer’s 8.3.2 Effect of Scalability: To ensure an immediate and effective
working status. real-world deployment of PrinTracker, it is necessary to evaluate the
Photocopying Attack: In the scenario where the attacker is not
able to obtain the authorized 3D printer but acquires the texture
of associated object’s surface, he copies it onto another object to
surpass the authentication. To evaluate its effectiveness, we utilize
six 3D printers (i.e., No.2, 4, 6, 8, 10 and 12) to manufacture five keys
individually. Subsequently, we generate three photocopies of each
bump key (totally 90 photocopies) at the highest print resolution
(1200 × 1200 dots per inch) on a commodity printer. An example of a
Figure 21: The identification performance with increasing photocopy from a key is illustrated in Figure 22. During testing, the
3D printers as test dataset. PrinTracker refuses the entire set of photocopies and identifies them
as an alien device. Due to the halftoning effects of the photocopying
process [98], the scanned texture would differ from the original one,
scalability with increasing 3D printers. We conduct an experiment
which significantly depletes the possibility to break the system. In
where we increase the number of objects gradually and measure
real practice, this attack can be easily detected by the investigator
the performance of PrinTracker at each stage. In the first stage, we
due to a significant change in the exterior of the object.
consider only three randomly chosen devices to train and evaluate
the system with their traces. Next, we increase the scope to six Forgery Attack: We assume that the attacker has access to the
devices and again evaluate the performance of our system. We specification of an authorized 3D printer, rather than machine itself,
gradually increase the number of devices in each stage and measure and exploits another printer to produce an identical fingerprint
the PrinTracker performance. with the authorized one. There are two methods to achieve this
Figure 21 shows that the precision and recall of the system for goal. First, he can utilize a fine-grained printer to mimic the coarse
different objects considered is nearly 100%. The performance of one. By using millions of dollars worth of advanced manufacturing
PrinTracker and the fingerprint remains consistent across a broad machine, it is possible to imitate a few hundred dollars worth of
set of objects. desktop 3D printer. However, it is not economically feasible and
the investigator can easily verify the trading record to acquire
9 ATTACK ANALYSIS the details of this extraordinary 3D printer’s purchase. Moreover,
given the extensive detail of all texture elements, computing or
In this section, we examine the security of our PrinTracker in the simulating the texture pattern is computationally expensive, where
following attack scenarios. the complexity increases exponentially with the texture area.
Second, he can modify the 3D printer with some components
from the authorized printer. We believe this to be the most plausible
attack. To explore this, we consider three 3D printers (No.1, 2 and
3) and remove their Hot ends. Progressively, we install the Hot end
of the No.1 onto the No.2, the Hot end of the No.2 onto the No.3 and
Hot end of the No.3 onto the No.1. An example of a modified 3D
printer can be seen in Figure 22. For each modified 3D printer, we
manufacture five bump keys (total 15 newly printed keys) and scan
each new key five times (total 75 scanned images). Upon testing the
scanned images using PrinTracker, we observe that the entire set of
these images is refused and classified as an alien device. The reason
is that the fingerprint not only generates from the manufacture
variations but also from the complex integrated effect of mechanical
components. Thus, PrinTracker would remain unaffected.