arXiv:2609.00390v1 Announce Type: cross
Abstract: Wearable EEG systems may expose sensitive information beyond their intended health function, creating substantial risks to neuroprivacy. In this work...
By Sarmistha Sarna Gomasta, Bhawana Chhaglani, Prashant Shenoy
arXiv:2607. 28191v1 Announce Type: cross Abstract: Federated learning enables multiple institutions to train shared models without exchanging raw clinical EEG data, but it does not fully prevent privacy leakage from individual model updates.
By Pouya Rajabi, Mohsen Toorani
arXiv:2607. 06037v1 Announce Type: cross Abstract: A shared electrocardiogram (ECG) is itself a biometric fingerprint that can re-identify a patient and reveal personal information.
By Taerin Ki, Sunghwan Park, Junyoung Park, Jaewoo Lee
arXiv:2503. 10945v3 Announce Type: replace-cross Abstract: Current practices for reporting differential privacy (DP) guarantees for machine learning (ML) algorithms such as DP-SGD provide an incomplete and potentially misleading picture.
By Juan Felipe Gomez, Bogdan Kulynych, Georgios Kaissis, Flavio P. Calmon, Jamie Hayes, Borja Balle, Antti Honkela
The paper compares four audit methods for assessing identity‑level differential privacy in pre‑trained, black‑box face generators. Each method—GaussMech, KDE‑LR, MMD‑TV, and ROC‑HT—has distinct assumptions, hyperparameters, and finite‑sample limitations, and they produce markedly different epsilon estimates when applied to FaceFusion and InstantID. The study finds that all methods reveal significant identity distinguishability, but none can be reliably ranked in this high‑distinguishability regime, suggesting that future work should evaluate them on partially private mechanisms.
By Arman Zareian Jahromi, Vishnu Bondalakunta, Mohammad Akbar Bin Shah, Naimul Haque, Shuangqing Wei, George T. Amariucai
arXiv:2601. 07556v2 Announce Type: replace-cross Abstract: Electroencephalogram (EEG)-based brain-computer interfaces (BCIs) face significant deployment challenges due to inter-subject variability, signal non-stationarity, and computational constraints.
By Siyang Li, Jiayi Ouyang, Zhenyao Cui, Ziwei Wang, Tianwang Jia, Feng Wan, Dongrui Wu
arXiv:2606. 11556v1 Announce Type: cross Abstract: Continuous electrocardiography (ECG) monitoring could surface rhythm abnormalities before they escalate into cardiovascular events.
By Kaan Arda Akyol, Jakub Kacper Szel\k{a}g, Aydin Abadi, Maha Alghamdi, Ghadah Albalawi, Ghouse Ibrahim Kaleelullah, Hilal Tutus, Sarah Al Subaiei, Shardul Kapse, Syed Mohammed Raheeb, Mujeeb Ahmed, Rehmat Ullah
arXiv:2603. 17109v2 Announce Type: replace Abstract: Decoding brain activity into natural language is a major challenge in AI with important applications in assistive communication, neurotechnology, and human-computer interaction.
By Akshaj Murhekar, Christina Liu, Abhijit Mishra, Shounak Roychowdhury, Jacek Gwizdka
arXiv:2508.04800v2 Announce Type: replace-cross
Abstract: We introduce a novel privatization framework for high-dimensional controlled variable selection. Our framework enables rigorous False Discove...
By Yuxuan Tao, Adel Javanmard
The paper introduces SW-ProxyCE, a zero-query adversarial attack that exploits publicly released EEG foundation encoders to generate transferable adversarial examples for private downstream models. By using a small labeled reference set and shrinkage-whitened class prototypes, the method recovers task-level decision geometry without training a surrogate classifier. Experiments across three EEG tasks and multiple encoders show that SW-ProxyCE consistently outperforms task-agnostic attacks, demonstrating that the strong transferability of EEG foundation models does not guarantee adversarial robustness.
By Linhua Cong, Dingkun Liu, Dongrui Wu
arXiv:2606. 09582v1 Announce Type: new Abstract: Recent work argues for using Gaussian differential privacy (GDP) to report the privacy guarantees in privacy-preserving machine learning.
By Bogdan Kulynych, Antti Honkela
The paper introduces Differential Privacy Representation Geometry for Medical Imaging (DP‑RGMI), a framework that interprets differential privacy as a structured transformation of representation space. DP‑RGMI decomposes performance loss into encoder geometry—measured by representation displacement and spectral effective dimension—and task‑head utilization, quantified by the gap between linear‑probe and end‑to‑end utility. Across 594,000 chest X‑ray images from four datasets, the study finds that differential privacy consistently creates a utilization gap even when linear separability remains, while displacement and spectral dimension vary non‑monotonically with initialization and dataset, indicating that privacy alters representation anisotropy rather than uniformly collapsing features.
By Soroosh Tayebi Arasteh, Marziyeh Mohammadi, Sven Nebelung, Daniel Truhn