arXiv Machine Learning

When Certificates Fail: A Unified Safety Framework for Embedded Neural Interface Models

arXiv:2607. 06630v1 Announce Type: new Abstract: Formal robustness certificates for embedded neural-interface models can pass while task accuracy collapses: at perturbation budget e=0.

arXiv AI
Jun 9

Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents

arXiv:2606. 09315v1 Announce Type: cross Abstract: BCI-to-agent pipelines turn decoded neural activity into an authorization channel for tool-use agents, exposing a new attack surface we call \emph{brain-prompt injection}: signal-side perturbations, context-only injections, and adaptive dual-decoder attacks can all change the routed action while EEG-side or text-side monitors remain blind.

By Jianwei Tai
arXiv Machine Learning
Sep 25

AERIAL: Adversarial Evaluation of Robustness in Accuracy-Preserving Low-Precision EEG Decoders

The study evaluates how low‑precision compression affects adversarial robustness in EEG decoders used for brain‑computer interfaces. Using BCI Competition IV‑2a data, the authors compare 32‑bit floating‑point models (EEGNet and ShallowConvNet) with models pruned to 50 % and quantized to INT8 via post‑training quantization (PTQ) or quantization‑aware training (QAT). Results show that accuracy‑preserving compression does not improve direct robustness—PGD attack accuracy remains 22–24 % across all variants—yet pruning reduces bidirectional transfer efficiency more than PTQ, indicating that robustness, transferability, and deployment efficiency are distinct properties of compressed EEG decoders.

By Saim Rehman, Muhammad Shafique
arXiv Machine Learning
Jun 3

Making Brain-Computer Interfaces More Secure

arXiv:2606. 02597v1 Announce Type: new Abstract: The development of brain-computer interfaces (BCIs) based on electroencephalograms (EEGs) has advanced significantly mainly to machine learning.

By Md Fahimul Kabir Chowdhury, Gahangir Hossain
arXiv Machine Learning
Aug 19

SW-ProxyCE: Zero-Query Adversarial Transfer from Public EEG Encoders to Private Downstream Models

The paper introduces SW-ProxyCE, a zero-query adversarial attack that exploits publicly released EEG foundation encoders to generate transferable adversarial examples for private downstream models. By using a small labeled reference set and shrinkage-whitened class prototypes, the method recovers task-level decision geometry without training a surrogate classifier. Experiments across three EEG tasks and multiple encoders show that SW-ProxyCE consistently outperforms task-agnostic attacks, demonstrating that the strong transferability of EEG foundation models does not guarantee adversarial robustness.

By Linhua Cong, Dingkun Liu, Dongrui Wu
arXiv AI
Sep 15

EEG-Xplain: Decoding Neural Black-Boxes of EEG Foundation Models

EEG-Xplain introduces a unified attribution framework to interpret EEG foundation models such as BIOT, LaBraM, and EEGMamba. The framework combines gradient, perturbation, and activation-based methods to analyze model behavior across spatial, temporal, and frequency dimensions, identifying critical channels, decision-relevant signal segments, and contributions of canonical EEG rhythms. It evaluates explanation reliability with population-level metrics and uses large language models to convert structured attributions into natural-language reports, demonstrating consistency with known neurophysiological markers on benchmark datasets.

By Hansong Ma, Junxiao Wang
arXiv AI
Aug 6

BrainBench: Benchmarking Large Language Models for Comprehensive EEG Understanding

arXiv:2608. 04156v1 Announce Type: new Abstract: Electroencephalography (EEG) analysis extends beyond assigning predefined labels to recordings; it requires workflows connecting natural-language instructions, signal processing, quantitative evidence, and scientific interpretation.

By Yangxuan Zhou, Sha Zhao, Yuning Chen, Chen Wu, Jiquan Wang, Shijian Li, Gang Pan
arXiv AI
Aug 26

NeuronGuard: Robust LLM Safety Alignment via Ablation-Aware Safety Signal Redistribution

NeuronGuard is a fine‑tuning defense for large language models that hardens them against both jailbreak and neuron‑level attacks. It redistributes safety signals across many neurons by identifying safety‑critical ones with per‑layer linear classifiers, enforcing refusal behavior when those neurons are ablated, and applying KL‑divergence regularization for consistency. A randomized gradient projection preserves task performance, and the authors provide a formal guarantee that NeuronGuard lowers the attack success rate upper bound, with experiments showing near‑zero success rates across multiple models and attack strategies.

By Anjun Gao, Yueyang Quan, Yufei Xia, Zhuqing Liu, Minghong Fang
arXiv Machine Learning
Aug 4

EEG-FM-Compass: Progress, Benchmarking, and Future Directions for EEG Foundation Models

arXiv:2601. 17883v3 Announce Type: replace Abstract: Electroencephalography (EEG) foundation models (FMs) have recently emerged as a promising paradigm for brain-computer interfaces, aiming to learn transferable neural representations from large-scale heterogeneous recordings.

By Dingkun Liu, Yuheng Chen, Zhu Chen, Zhenyao Cui, Yaozhi Wen, Jiayu An, Jingwei Luo, Dongrui Wu
arXiv AI
3d ago

NeuroAtlas: Benchmarking Foundation Models for Clinical EEG and Brain-Computer Interfaces

NeuroAtlas is the largest EEG benchmark to date, comprising 42 datasets and 260,000 hours of clinical EEG data across epilepsy, sleep medicine, brain age estimation, and brain‑computer interfaces. The study evaluates foundation models (FMs) for EEG against supervised baselines and generic time‑series FMs, finding that EEG‑specific FMs do not consistently outperform generic ones. It also demonstrates that standard machine‑learning metrics are inadequate for clinical relevance, advocating for task‑specific measures such as event‑level decision quality, hypnogram features, and brain‑age gap.

By Konstantinos Kontras, Trui Osselaer, Stylianos G. Mouslech, Angeliki-Ilektra Karaiskou, Guido Gagliardi, Thomas Strypsteen, Mohammad Hossein Badiei, Anku Rani, Maarten Vanmarcke, Miguel Bhagubai, Chanakya Ekbote, Jaedong Hwang, Christos Chatzichristos, Paul Pu Liang, Maarten De Vos