Authors propose to mess with circuit board runs by adding components and modifying connections. There is no security on the design files, so they are trivially modified, though it is annoying to do so if you don't have the original design files. The outputs - Gerbers or ODB++ databases - can be imported into a design tool and modified.
They also propose to detect such changes by looking for missing refdes. That's farcical. Duplicate refdes are much harder to identify, or a new one could be added. But the true way to hide a "hack" in a PCB is to replace an IC with a counterfeit part.
A combination of a modern APT - even some of the things published around the same time as Stuxnet - could be used to activate a hidden feature in a counterfeit IC, and would be undetectable by almost any method short of high-resolution xray comparison to a golden board.
Fun stuff to think about though.