On-Device (Edge) Decoding
A privacy-and-latency architecture in which feature extraction and decoding run on the implant or a body-worn processor, so that raw neural signals never leave the trusted device and only minimal, task-relevant outputs (a cursor velocity, a selected letter) are transmitted. Because raw data is the most sensitive and most re-identifying representation, keeping it local sharply narrows what an attacker or a curious cloud service can obtain.
On-device decoding is also driven by closed-loop latency and wireless-bandwidth limits, aligning privacy with engineering need. Its constraints are power and compute at the edge — which is where neuromorphic co-processors and trusted execution environments become relevant — and data minimization is only partial, since even a low-rate output stream can leak state over time.
Data minimization at the edge is a strong default, but the residual output stream still warrants protection — outputs can be aggregated into sensitive inferences.