提出简易的对抗滤波攻击,威胁脑机接口安全
Adversarial Filtering Based Evasion and Backdoor Attacks to EEG-Based Brain-Computer Interfaces
- 用对抗滤波实现对脑机接口的逃避与后门攻击
- 在三个不同范式的数据集上均验证攻击有效性
- 首个针对脑机接口的对抗滤波研究,警示安全风险
脑机接口(BCI)实现大脑与外部设备的直接通信。脑电图(EEG)因便捷性和低成本,常被用作BCI输入信号。当前大多数研究聚焦于脑电信号的准确解码,忽视了其安全性。近期研究表明,基于机器学习的BCI模型易受对抗攻击。本文提出一种基于对抗滤波的逃避攻击与后门攻击方法,实现简单且有效。在三个来自不同BCI范式的数据集上进行实验,验证了所提攻击方法的有效性。据我们所知,这是首个针对基于EEG的脑机接口开展对抗滤波攻击的研究,揭示了新的安全威胁,呼吁加强对脑机接口安全的关注。
原文摘要 · Abstract (English)
A brain-computer interface (BCI) enables direct communication between the brain and an external device. Electroencephalogram (EEG) is a common input signal for BCIs, due to its convenience and low cost. Most research on EEG-based BCIs focuses on the accurate decoding of EEG signals, while ignoring their security. Recent studies have shown that machine learning models in BCIs are vulnerable to adversarial attacks. This paper proposes adversarial filtering based evasion and backdoor attacks to EEG-based BCIs, which are very easy to implement. Experiments on three datasets from different BCI paradigms demonstrated the effectiveness of our proposed attack approaches. To our knowledge, this is the first study on adversarial filtering for EEG-based BCIs, raising a new security concern and calling for more attention on the security of BCIs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。