Adversarial Attack on Decoders
A deliberately crafted, often imperceptible perturbation of the input to a neural decoder that forces a chosen wrong output. EEG- and spike-based deep decoders have been shown vulnerable to such perturbations, including universal perturbations that mislead many inputs at once and that, in some settings, can be added to a signal stream in near-real-time.
The consequence differs from that for image classifiers: a fooled BCI can mean an unwanted command to a wheelchair, prosthesis, or communication device, so an integrity failure is a safety failure. Studied defenses include adversarial training, input denoising, and detection, but as elsewhere in machine learning no defense is complete, and the constrained, physiological structure of neural inputs both limits and enables specific attack forms.
Most demonstrations are digital-domain (perturbing already-recorded data); physically injecting an effective perturbation into a real electrode stream is harder and overlaps with signal injection and spoofing.