Aug. 14, 2026
Georgia Tech doctoral candidate Will Huggins presents findings of an AMPF case study

Georgia Tech doctoral candidate Will Huggins presents findings of an AMPF case study featuring the manufacture and repair of high-value parts used by the railway industry.

Counterfeit and out-of-spec components are entering U.S. defense supply chains through thousands of small and midsized suppliers that make up the lower tiers of the industrial base. Researchers at the Georgia Tech Manufacturing Institute (GTMI) say the fix isn't just better parts, but better proof: verified digital records, secured against tampering, that travel with each component from raw material to installation.   

A landmark 2012 Senate Armed Services Committee investigation documented 1,800 cases involving more than 1 million suspect counterfeit electronic parts in the defense supply chain, traced to more than 650 companies relying on their own unvetted networks of distributors and brokers. In one case, parts changed hands five times before reaching a Raytheon subcontractor.  

The Pentagon has separately estimated that up to 15% of the spare and replacement electronic parts it buys are counterfeit. Without verification built into the supply chain, officials warn, a single bad part, or a single exposed manufacturing controller, can compromise a weapons system or halt a production line. That risk hasn't eased: a 2025 Government Accountability Office report found that Department of Defense now depends on more than 200,000 suppliers, and a deeper look at the MQ-9 Reaper drone's supply chain found Chinese components at the lower tiers despite U.S.- and Europe-based top-tier suppliers. 

Manufacturers are adopting a QR-coded digital record, sometimes called a digital passport, that documents a part's full production history and can be scanned at any point in the supply chain. According to GTMI Executive Director Tom Kurfess, a member of the National Academy of Engineering who previously oversaw federal manufacturing R&D policy at the White House, the core requirement of this digital infrastructure is straightforward: apart must prove it is what it claims to be.  

"I am not a counterfeit part; I was made according to specifications, and you can insert me into that jet engine with high confidence that I'm going to perform as specified," Kurfess said, describing what the scan of a digital passport for a replacement jet engine turbine blade needs to confirm before it goes into an F-35. 

How the Tracking Works 

While a fighter jet represents the apex of tracking stakes, Kurfess notes that the underlying infrastructure is already proven on much more ordinary assembly lines. He points to a plumbing fixture plant near Hartsfield-Jackson Atlanta International Airport, where every unit carries a QR code that pulls up the humidity conditions during manufacturing, the processing steps, and who worked on the part. Defense components use the same method, where an untraced failure carries far higher stakes. 

The technology itself is cost-effective. Shops have swapped standard calipers for Bluetooth-enabled versions that cost only a few dollars more, Kurfess said. Paired with a smartphone or tablet and a cloud account, those calipers automatically and securely feed measurements into a spreadsheet rather than a handwritten log, building a documentation record for every part in a batch.  

"Before shipping it off, you essentially signal that you are ready. You click the print button, and a QR code prints out to go right on the shipping bin," Kurfess said. "Whoever receives that bin, whether a commercial OEM or a defense prime, scans the code and can pull up the part’s full record.” The same approach covers more complex components. Electric motors built for the automotive industry now upload test-stand performance data to the cloud before shipping; once installed, a vehicle's control system scans the motor's passport and calibrates accordingly, Kurfess said. On automotive assembly lines, cameras and scanners verify that every part in a kit is present before workers seal and code it, catching shortages before they halt the production line. 

For defense suppliers, Kurfess said the documentation lets prime contractors, and the Department of Defense confirm that a part meets specifications and traces it through its full production history. "We know it's a good blade, and you can insert it into the F-35," he said. "We can track all of it." 

The Cybersecurity Risk 

That documentation only works if the underlying systems stay secure. Saman Zonouz, associate professor in the School of Cybersecurity and Privacy and Electrical and Computer Engineering, said manufacturing is one of 16 sectors the Department of Homeland Security, through the Cybersecurity and Infrastructure Security Agency (CISA) classifies as critical infrastructure, dependent on energy and water to operate while other sectors depend on it in turn. 

His research shows adversaries can insert what his team calls "logic bombs" into design files: code that leaves a manufactured part looking normal until it fails on command, whether that part is a drone propeller or a power grid transformer. He also pointed to supply chain attacks, where imported machine tools arrive with vulnerable or deliberately compromised software already installed, the same pattern behind the SolarWinds breach that hit critical infrastructure nationwide. 

Scanning the internet, Zonouz's team found manufacturing controllers exposed and reachable by outside actors. Manufacturing hasn't developed cybersecurity measures at the pace of sectors such as finance or energy, he said, in part because engineers built legacy equipment for reliability, not to resist a deliberate attack. 

AI cuts both ways, according to Zonouz. It powers new attack-detection systems, including the Georgia AI in Manufacturing (Georgia AIM) technology corridor, a $65 million initiative that includes a pilot project at the Advanced Manufacturing Pilot Facility to enable shops to monitor for anomalies without constant human oversight. But AI systems also introduce new, often unknown vulnerabilities that attackers can exploit. 

Zonouz encourages manufacturers to build cybersecurity into systems from the start, borrow lessons from more mature sectors already operating under frameworks such as North American Electric Reliability Corporation Critical Infrastructure Protection for the power grid, and prepare for manufacturing standards, including the Department of Defense's Cybersecurity Maturity Model Certification framework, to tighten over time. 

Much of GTMI's work runs through the small and midsized manufacturers that supply nuts, bolts, and castings to prime contractors such as Lockheed Martin and General Motors, companies that typically lack the in-house IT resources of a major OEM. Kurfess said GTMI configures the same cloud tools that automate measurement tracking to meet Department of Defense documentation and cybersecurity requirements, working directly with smaller suppliers to build that capability instead of leaving them to develop it alone. 

Tracking Choke Points Before They Become Failures 

The same connectivity that verifies individual parts also shows manufacturers where a supply chain is vulnerable before a disruption hits. Kurfess cites the 2011 Fukushima disaster, which knocked out a single Japanese plant supplying a chip used in the machine tool industry worldwide, and the Covid-era shipping container shortage that forced companies to truck castings across the country when no containers were available at U.S. ports for shipping via rail. Mapping a supply chain in both directions, he said, reveals where a single supplier, region, or disruptive event such as inclement weather or a power outage could stop production. 

Kurfess compares GTMI's approach to "being the Google Maps for manufacturing," using real-time connectivity to flag bottlenecks and reroute them in the best possible manner. That logic also drives GTMI's push for distributed manufacturing: spreading production of a component, such as electric vehicle motors, across many smaller regional plants instead of one large facility so a local disruption can't affect the whole chain. GTMI's Factory Information Systems Center builds the secure supply chain architectures and machine-to-cloud connectivity behind that work. 

Chris Gaffney, managing director of Georgia Tech's Supply Chain and Logistics Institute, reached a similar conclusion in a June 2026 research brief, calling cyberattacks on physical supply chains "a defining executive risk" and trusted operational data possibly "the most valuable" asset a supply chain organization holds. 

Verifying Quality Without Shipping Parts Across the Country 

GTMI is applying AI directly to quality verification at its Advanced Manufacturing Pilot Facility (AMPF), where manufacturers can build and verify a part under one roof instead of shipping it elsewhere for testing. "Right now, in manufacturing, a piece of equipment, a turbine rotor blade, for example, is created in one place, then sent somewhere else for testing," said Aaron Stebner, an associate professor who leads AMPF's work under the Georgia AIM initiative. "Often it goes across the country to check its interior structure, then is shipped to a second location to test its chemical composition." 

AMPF's connected machines "talk" to each other using AI and a knowledge management system, verifying a part’s material composition and durability as it's made rather than after the fact, so manufacturers can confirm they're building what they intend to build without shipping delays. "No other facility in the nation is built to do this autonomously," Stebner said. "Georgia Tech will be the first." GTMI is also opening AMPF to remote materials research through a new AI-driven cloud lab (see sidebar). 

GTMI's Role 

Kurfess and Zonouz both credited close collaboration between manufacturing and cybersecurity researchers at Georgia Tech, including a dedicated School of Cybersecurity and Privacy, as the basis for GTMI's work in this area. That collaboration drives research into cyber-secure manufacturing platforms designed with security built in from the outset, and AMPF gives those systems a place to run on production-scale equipment. 

Kurfess said the next test is scale: whether digital passports, secure cloud tracking, and AI-verified quality checks can move from a handful of pilot programs and flagship facilities to the thousands of small shops that make up the defense industrial base. The technology, from Bluetooth calipers to readily available and cost-effective cloud accounts, is already cheap enough that cost isn't the barrier. What remains is installing, securing, and standardizing those tools across a supply chain that still runs largely on paper. 

To learn more about how GTMI can help defense manufacturers build supply chain resilience, visit https://manufacturing.gatech.edu/engage   

  

# # # 

GTMI to Build AI-Driven Cloud Lab for Remote Materials Research 

Georgia Tech is building a Programmable Cloud Laboratory that will let researchers across the country direct materials experiments at the Georgia Tech Manufacturing Institute's Advanced Manufacturing Pilot Facility (AMPF) without traveling on-site. The National Science Foundation is funding the project with $18.1 million as part of a planned national network of 20 AI-enabled cloud labs. 

Researchers will submit a request, and AI agents will translate it into a detailed workflow, coordinating robots, equipment, and data collection across the facility. "Researchers can ask a question, have work recommended by AI agents, have experiments carried out at the facility using robotics, and get the results back," said Aaron Stebner, GTMI associate director, Eugene C. Gwaltney Jr. Chair, and James R. and Sarah R. Borders Faculty Fellow in the George W. Woodruff School of Mechanical Engineering. "They can use AMPF resources to advance their own research without having to be experts in each piece of equipment or send students to AMPF for weeks at a time." 

AMPF is approaching autonomous workflow capability across about 38 of its 160 pieces of equipment. The cloud lab aims to push that past 100. Pascal Van Hentenryck, director of the NSF AI Institute for Advances in Optimization, said the system will rely on digital twins, virtual models of the facility, to plan and monitor experiments, and will improve its scheduling and machine tuning as it learns from each run. 

The project also integrates Duke University's Automatic FLOW for Materials Discovery platform and a knowledge and data management platform from Contextualize to connect researchers, instruments, and IT systems across the network. Organizers expect more than 400 users from 150 academic, industry, and government institutions, with more than half participating remotely. 

Tom Kurfess, GTMI's executive director, said the lab will let industry partners test new ideas before committing to large-scale deployment. "This initiative will shorten development cycles and make it easier to bring promising technologies into production, enabling our partners and us to innovate at the speed of thought," he said. 

News Contact

News Contact

Jennifer Martin
Assistant Director of Research Communications Services

Writer: Anne Wainscott-Sargent