Neuroethics, Neurorights, Agency & Governance

Neurosecurity

Neurosecurity is the protection of neural devices and neural data against malicious interference — unauthorized reading of private information, tampering with stimulation or decoding, denial of service, and extraction of secrets via the interface. It treats a BCI as a cyber-physical system with an unusually intimate attack surface: a compromise can affect not only data but perception, movement, and mood.

Demonstrated risks span reading and writing. On the read side, side-channel attacks can extract private information from involuntary responses such as the P300. On the write side, insecure wireless stimulators raise the prospect of 'brain-hacking' that alters device behavior, perception, or mood. Defenses include encryption and authentication of telemetry, secure firmware update, anomaly detection, and adversarially robust decoders.

Martinovic and colleagues (2012) showed a 'side-channel' attack: images shown in a consumer EEG game evoked P300 responses that raised, above chance, the attacker's odds of guessing the user's PIN, bank, or recognized faces.

A benign-looking game leaked private information through an involuntary brain response.

Also called
brain-hackingBCI security神經資安