arXiv:2606. 09189v1 Announce Type: cross Abstract: EEG foundation-model releases are usually audited one endpoint at a time: raw-reconstruction, membership inference, identity linkage, or DP-SGD on the downstream head.
By Jianwei Tai
arXiv:2606. 09315v1 Announce Type: cross Abstract: BCI-to-agent pipelines turn decoded neural activity into an authorization channel for tool-use agents, exposing a new attack surface we call \emph{brain-prompt injection}: signal-side perturbations, context-only injections, and adaptive dual-decoder attacks can all change the routed action while EEG-side or text-side monitors remain blind.
By Jianwei Tai
arXiv:2607. 24519v2 Announce Type: replace Abstract: Pretrained EEG foundation models are proposed for clinical decoding, but whether reported gains transfer across populations or survive negative controls is unclear.
By Marzieh Zare
arXiv:2606. 06647v1 Announce Type: new Abstract: Objective.
By Jun-You Lin, Ying Choon Wu, Tzyy-Ping Jung
arXiv:2607. 11950v1 Announce Type: cross Abstract: Brain field potentials are scale-free: their power spectra follow a $1/f^{\beta}$ law whose aperiodic exponent $\beta$ tracks cortical state, and sleep depth in particular is a shift in $\beta$.
By Dibakar Sigdel
arXiv:2607. 24519v1 Announce Type: cross Abstract: Pretrained EEG foundation models are increasingly proposed for clinical decoding, but their transfer across populations and robustness to negative controls remain unclear.
By Marzieh Zare
arXiv:2607. 11950v2 Announce Type: replace-cross Abstract: Brain field potentials are scale-free: their power spectra follow a $1/f^{\beta}$ law whose aperiodic exponent $\beta$ tracks cortical state, and sleep depth in particular is a shift in $\beta$.
By Dibakar Sigdel
arXiv:2607. 24519v3 Announce Type: replace-cross Abstract: EEG foundation-model gains may depend on cohort, montage, or probe design.
By Marzieh Zare
arXiv:2607. 06596v1 Announce Type: cross Abstract: Trusted monitoring is a central defense in AI control: a cheaper trusted model scores an untrusted model's actions for sabotage, and the most suspicious are audited or deferred.
By Lucas Pinto
arXiv:2606. 10154v1 Announce Type: new Abstract: Quantized checkpoints are often screened first with quality metrics and only later, if at all, with direct safety tests.
By Sahil Kadadekar
The paper introduces SW-ProxyCE, a zero-query adversarial attack that exploits publicly released EEG foundation encoders to generate transferable adversarial examples for private downstream models. By using a small labeled reference set and shrinkage-whitened class prototypes, the method recovers task-level decision geometry without training a surrogate classifier. Experiments across three EEG tasks and multiple encoders show that SW-ProxyCE consistently outperforms task-agnostic attacks, demonstrating that the strong transferability of EEG foundation models does not guarantee adversarial robustness.
By Linhua Cong, Dingkun Liu, Dongrui Wu
arXiv:2607. 19442v1 Announce Type: cross Abstract: Machine unlearning is commonly evaluated by matching a retrained oracle on trained probes.
By Sen Yang, Yuen-Hei Yeung