Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology
Bryce-Allen Bagley, Nathaniel Rose, Quintus Kilbourn, Matthew Canham
cs.CR, cs.ET, cs.HC, q-bio.NC
Submitted: 2026-07-11
License: http://creativecommons.org/licenses/by/4.0/
The gist: Brain-computer interfaces (BCIs) are a class of diverse hardware modalities, associated software, and connected devices which are widely used in a variety of fields, including neurosurgery,
Terminology
Abstract
Brain-computer interfaces (BCIs) are a class of diverse hardware modalities, associated software, and connected devices which are widely used in a variety of fields, including neurosurgery, biomedical data analysis, and neuroimaging. Recent years have seen rapid advancements in BCI technology, and neurotechnology more broadly, with the first devices now passing clinical trials, early examples of consumer hardware entering the market, and many variants of consumer and medical hardware with increasingly extensive capabilities being developed rapidly. However, research and development in security for BCIs--known as neurosecurity--lags significantly behind the capabilities of BCIs themselves. In an effort to address as many vulnerabilities as feasible immediately, in this paper we review the current state of the art in neurosecurity, thoroughly survey the breadth and complexity of both firmly established and highly probable security threats to BCI systems, and provide recommendations of existing methods from cybersecurity, hardware security, and machine learning which can immediately be applied to address some of these gaps in neurosecurity.
Sources
- MindEye2: Shared-Subject Models Enable fMRI-To-Image With 1 Hour of Data
- Professor X: Manipulating EEG BCI with Invisible and Robust Backdoor Attack
- Approximating the Mathematical Structure of Psychodynamics
- MAGNETO: Covert Channel between Air-Gapped Systems and Nearby Smartphones via CPU-Generated Magnetic Fields
- ODINI : Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields
- Fansmitter: Acoustic Data Exfiltration from (Speakerless) Air-Gapped Computers
- AiR-ViBeR: Exfiltrating Data from Air-Gapped Computers via Covert Surface ViBrAtIoNs
- MOSQUITO: Covert Ultrasonic Transmissions between Two Air-Gapped Computers using Speaker-to-Speaker Communication
- Poisoning Attacks against Support Vector Machines
- Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples
- Adversarial Robustness of Deep Learning: Theory, Algorithms, and Applications
- Explaining and Harnessing Adversarial Examples
- Differentially Private Federated Learning: A Client Level Perspective
- Differentially Private Federated Learning: A Systematic Review
- Fiduciary AI for the Future of Brain-Technology Interactions
- Enhancing the Security & Privacy of Wearable Brain-Computer Interfaces
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs