Neural-Data Security, Privacy & Cryptography

Side-Channel Inference from Neural Data

Extraction of a secret that the BCI was never intended to convey, by exploiting information incidentally present in the neural signal. The canonical demonstration used a consumer EEG headset and a game-like interface to elicit P300 responses to images of banks, faces, PIN digits, and locations; the presence or absence of a recognition response leaked which stimulus was personally meaningful, allowing better-than-chance guessing of private items.

The attack is powerful because the informative response is partly involuntary and can be evoked under cover of an unrelated task. It generalizes to any interface able to present stimuli and observe evoked activity, and it motivates defenses at the application layer (limiting what a decoder may present and query) rather than only at the transport layer.

The original studies used low-cost consumer hardware and simple classifiers; they establish feasibility of the leak, not a turnkey exploit, and defenses that randomize or throttle stimulus presentation reduce it.

Also called
incidental information leakage