在脑电数据中加入用户专属扰动,可隐藏身份信息而不影响脑机接口性能。
User-wise Perturbations for User Identity Protection in EEG-Based BCIs
- 为脑电信号添加四类用户专属扰动,使身份信息无法被学习。
- 六组数据实验验证:身份信息不可识别,任务准确率保持不变。
- 适合关注脑机接口隐私保护的研究者与开发者。
基于脑电图(EEG)的脑机接口(BCI)是人脑与计算机之间的直接通信路径。现有研究多聚焦于提升准确性,却较少关注伦理问题。除任务相关信号外,EEG还包含丰富的个人隐私信息,如身份、情绪、疾病等,亟需保护。本文首次证明,通过添加用户专属扰动,可使EEG中的身份信息不可学习。提出四类隐私保护扰动:随机噪声、合成噪声、误差最小化噪声和误差最大化噪声。在训练数据中加入这些扰动后,用户身份信息变得无法被模型学习,而原始的BCI任务信息仍能保持。在六个公开EEG数据集上,使用三种神经网络分类器及多种传统机器学习模型进行实验,结果表明该方法具有强鲁棒性与实用性。本研究证实,在不影响主要任务性能的前提下,隐藏用户身份信息是可行的。
原文摘要 · Abstract (English)
Objective: An electroencephalogram (EEG)-based brain-computer interface (BCI) is a direct communication pathway between the human brain and a computer. Most research so far studied more accurate BCIs, but much less attention has been paid to the ethics of BCIs. Aside from task-specific information, EEG signals also contain rich private information, e.g., user identity, emotion, disorders, etc., which should be protected. Approach: We show for the first time that adding user-wise perturbations can make identity information in EEG unlearnable. We propose four types of user-wise privacy-preserving perturbations, i.e., random noise, synthetic noise, error minimization noise, and error maximization noise. After adding the proposed perturbations to EEG training data, the user identity information in the data becomes unlearnable, while the BCI task information remains unaffected. Main results: Experiments on six EEG datasets using three neural network classifiers and various traditional machine learning models demonstrated the robustness and practicability of the proposed perturbations. Significance: Our research shows the feasibility of hiding user identity information in EEG data without impacting the primary BCI task information.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。