arXiv:2606. 09315v1 Announce Type: cross Abstract: BCI-to-agent pipelines turn decoded neural activity into an authorization channel for tool-use agents, exposing a new attack surface we call \emph{brain-prompt injection}: signal-side perturbations, context-only injections, and adaptive dual-decoder attacks can all change the routed action while EEG-side or text-side monitors remain blind.
By Jianwei Tai
The study evaluates how low‑precision compression affects adversarial robustness in EEG decoders used for brain‑computer interfaces. Using BCI Competition IV‑2a data, the authors compare 32‑bit floating‑point models (EEGNet and ShallowConvNet) with models pruned to 50 % and quantized to INT8 via post‑training quantization (PTQ) or quantization‑aware training (QAT). Results show that accuracy‑preserving compression does not improve direct robustness—PGD attack accuracy remains 22–24 % across all variants—yet pruning reduces bidirectional transfer efficiency more than PTQ, indicating that robustness, transferability, and deployment efficiency are distinct properties of compressed EEG decoders.
By Saim Rehman, Muhammad Shafique
arXiv:2606. 02597v1 Announce Type: new Abstract: The development of brain-computer interfaces (BCIs) based on electroencephalograms (EEGs) has advanced significantly mainly to machine learning.
By Md Fahimul Kabir Chowdhury, Gahangir Hossain
The paper introduces SW-ProxyCE, a zero-query adversarial attack that exploits publicly released EEG foundation encoders to generate transferable adversarial examples for private downstream models. By using a small labeled reference set and shrinkage-whitened class prototypes, the method recovers task-level decision geometry without training a surrogate classifier. Experiments across three EEG tasks and multiple encoders show that SW-ProxyCE consistently outperforms task-agnostic attacks, demonstrating that the strong transferability of EEG foundation models does not guarantee adversarial robustness.
By Linhua Cong, Dingkun Liu, Dongrui Wu
arXiv:2609.23924v1 Announce Type: new
Abstract: Pretrained EEG foundation models are increasingly proposed as general-purpose encoders for brain-computer interfaces, yet recent benchmarks disagree ab...
By Kevin Zhou, Sparsh Roy
EEG-Xplain introduces a unified attribution framework to interpret EEG foundation models such as BIOT, LaBraM, and EEGMamba. The framework combines gradient, perturbation, and activation-based methods to analyze model behavior across spatial, temporal, and frequency dimensions, identifying critical channels, decision-relevant signal segments, and contributions of canonical EEG rhythms. It evaluates explanation reliability with population-level metrics and uses large language models to convert structured attributions into natural-language reports, demonstrating consistency with known neurophysiological markers on benchmark datasets.
By Hansong Ma, Junxiao Wang