Signature checks can be fooled, but silicon cannot. Researchers at the University of Michigan-Dearborn show that counterfeit or swapped ECUs still betray themselves through analog artifacts in their electrical output, even when the hardware passes every cryptographic verification.
Their framework, presented at VehicleSec 2026, relies on manufacturing variation. Each time a chip flips a signal, whether a CAN bit, an ECU command pulse, or a GPIO toggle, tiny differences in output drivers, clock sources, and passive components leave distinctive marks on the waveform. The team captures those traces, pulls 211 features from them, and classifies the result with a hybrid of a cycle-based random forest and an OVA stacked ensemble, hitting 99.5 percent accuracy in real time.
A live demo identified eight embedded devices across four hardware types without touching firmware or requiring protocol access, and it told same-model clone pairs apart. The supply chain implication is direct: a cloned control unit that defeats signature checks still exposes its analog identity every time it talks on the bus.
Fleets and OEMs could use the technique as a non-intrusive check that the hardware in a vehicle matches what left the factory. The method also extends beyond ECUs to CAN bus nodes and sensor modules.