The paper introduces SW-ProxyCE, a zero-query adversarial attack that exploits publicly released EEG foundation encoders to generate transferable adversarial examples for private downstream models. By using a small labeled reference set and shrinkage-whitened class prototypes, the method recovers task-level decision geometry without training a surrogate classifier. Experiments across three EEG tasks and multiple encoders show that SW-ProxyCE consistently outperforms task-agnostic attacks, demonstrating that the strong transferability of EEG foundation models does not guarantee adversarial robustness.
By Linhua Cong, Dingkun Liu, Dongrui Wu
arXiv:2607. 06630v1 Announce Type: new Abstract: Formal robustness certificates for embedded neural-interface models can pass while task accuracy collapses: at perturbation budget e=0.
By Jasmeet Singh Bindra
arXiv:2608. 13285v1 Announce Type: new Abstract: Motor imagery (MI) brain--computer interfaces (BCIs) have emerged as a promising approach for establishing flexible communication pathways between the human brain and external devices , particularly for individuals affected by stroke or neurodegenerative disorders.
By Athanasios Karagounis
arXiv:2606. 01437v1 Announce Type: cross Abstract: Deep Neural Networks (DNNs) are highly susceptible to adversarial perturbations, leading to extensive research on robustness for safety-critical applications.
By Daniel Sadig, Mohammadreza Maleki, Hamed Karimi, Reza Samavi
The study evaluates how low‑precision compression affects adversarial robustness in EEG decoders used for brain‑computer interfaces. Using BCI Competition IV‑2a data, the authors compare 32‑bit floating‑point models (EEGNet and ShallowConvNet) with models pruned to 50 % and quantized to INT8 via post‑training quantization (PTQ) or quantization‑aware training (QAT). Results show that accuracy‑preserving compression does not improve direct robustness—PGD attack accuracy remains 22–24 % across all variants—yet pruning reduces bidirectional transfer efficiency more than PTQ, indicating that robustness, transferability, and deployment efficiency are distinct properties of compressed EEG decoders.
By Saim Rehman, Muhammad Shafique
Motor imagery (MI) brain--computer interfaces (BCIs) have emerged as a promising approach for establishing flexible communication pathways between the human brain and external devices , particularly for individuals affected by stroke or neurodegenerative disorders. Reliable decoding of motor-imagery electroencephalography (MI-EEG) remains challenging because EEG recordings contain substantial noise and exhibit complex, weakly informative relationships with the underlying brain activity.
RobustSeiz is an open‑source, model‑agnostic framework designed to benchmark the robustness of EEG seizure detection models under realistic clinical stressors. It standardizes four public scalp‑EEG corpora into BIDS‑EEG trees, applies controlled distribution shifts—including environmental, noise, and adversarial transforms—across predefined hyperparameter grids, and reports comprehensive performance metrics such as sensitivity, precision, F1, false positives per 24 h, onset timing, and predictive agreement. The framework offers a Dockerized GPU pipeline, experiment registry, and both full‑evaluation and research‑subset modes, and demonstrates its utility by evaluating a contemporary detector on TUSZ across the full shift grid.
By Mohammad Mohammadi, Alireza Zarei
The paper introduces a benchmark for out‑of‑distribution (OOD) detection in electroencephalography (EEG) machine learning, evaluates a wide range of OOD methods, and assesses their impact on two clinical downstream prediction tasks. It distinguishes between OOD detection and model uncertainty estimation, which are often conflated, and shows how combining complementary methods can create a robust safety net for deploying EEG‑based models in high‑risk settings.
By Philipp Bomatter, Henry Gouk
arXiv:2601. 07556v2 Announce Type: replace-cross Abstract: Electroencephalogram (EEG)-based brain-computer interfaces (BCIs) face significant deployment challenges due to inter-subject variability, signal non-stationarity, and computational constraints.
By Siyang Li, Jiayi Ouyang, Zhenyao Cui, Ziwei Wang, Tianwang Jia, Feng Wan, Dongrui Wu
arXiv:2504. 08469v3 Announce Type: replace-cross Abstract: Current methods for detecting artifacts in sleep EEG range from threshold-based algorithms to machine learning approaches, yet applications remain limited for single-channel mobile EEG.
By Khrystyna Semkiv, Jia Zhang, Maria Laura Ferster, Walter Karlen
arXiv:2606. 02267v1 Announce Type: new Abstract: The vulnerability of deep neural networks to adversarial examples poses a significant challenge for real-world deployment.
By Nicolas Stalder, Benjamin F. Grewe, Matteo Saponati, Pau Vilimelis Aceituno
The paper reviews one‑pixel attacks (OPAs), highlighting their extreme adversarial fragility across domains such as medical diagnosis, autonomous driving, biometrics, and quantum communication. It presents a PRISMA‑guided synthesis of studies from 2017 to 2026, offering a unified taxonomy that covers algorithmic foundations, black‑box evolutionary optimization, hybrid and program‑synthesis attacks, defence mechanisms, interpretability tools, and domain‑specific vulnerabilities. The review identifies dominant Differential Evolution strategies, emerging efficiency‑optimized and saliency‑guided methods, and gaps in dataset diversity, transferability, and evaluation standards, while proposing future research directions and a regulatory framework for robustness testing and AI security governance.
By Mirza Niaz Morshed, Md. Masudul Islam, Galib Muhammad Shahriar Himel, Md. Aslam Uddin, Hui Liu, Md. Shafiqul Islam