Malicious Stimulus Probing
An active side-channel attack in which a malicious application deliberately injects probe stimuli — sometimes subliminal, sometimes embedded in ordinary content — to elicit evoked responses that reveal private attributes, while the user believes they are doing something benign. Where passive side-channel inference reads whatever responses happen to occur, malicious probing chooses the questions, turning the BCI into an involuntary interrogation channel.
Subliminal variants aim to keep the probes below conscious detection so the user cannot decline to respond, which raises acute consent and mental-integrity concerns. Proposed defenses include a trusted intermediary or BCI anonymizer layer that inspects and sanitizes the stimulus stream and rate-limits or blocks response readout, analogous to a firewall between apps and the neural interface.
Demonstrations exist mainly on consumer EEG in the lab; nonetheless the class is a design driver for permission models in any app-programmable BCI.