Neural-Data Security, Privacy & Cryptography

Neural-Data Privacy Attack

An umbrella for adversarial procedures that recover information a user did not intend to disclose, either from neural recordings or from a model trained on them. The target may be explicit (a password, a PIN, a diagnosis) or implicit (identity, emotional or cognitive state, political or religious leanings, health conditions). Attacks are usually classified by what the adversary can access: the raw signal, extracted features, the decoder's parameters, or only its outputs (black-box).

The threat is amplified by three properties of neural data: it is high-dimensional and richly informative, it is largely involuntary (a person cannot fully suppress an evoked response), and it is stable enough over time to act as a biometric. Standard de-identification (stripping names and metadata) is therefore weak, because the signal itself carries identity and attribute information.

Also called
privacy inference attack