arXiv:2601.05789cs.HCcs.AI2026-01被引 2

SAFE让脑机接口在不泄露隐私的前提下,更准更稳地识别用户意图。

SAFE: Secure and Accurate Federated Learning for Privacy-Preserving Brain-Computer Interfaces

  • 通过本地批量归一化缓解不同人脑电特征差异,提升模型泛化能力。
  • 结合输入与参数空间扰动,使模型对恶意攻击更具鲁棒性,准确率更高。
  • 无需目标用户校准数据,适合真实场景下保护隐私的脑机接口应用。

基于脑电图(EEG)的脑机接口(BCI)因高效便携被广泛应用,但其解码算法仍面临泛化不足、对抗脆弱性和隐私泄露等挑战。本文提出安全且准确的联邦学习框架SAFE,通过将数据保留在本地实现隐私保护。SAFE采用本地批次特定归一化,缓解跨受试者特征分布偏移,提升模型泛化能力;并通过联邦对抗训练和对抗权重扰动,在输入空间与参数空间引入扰动,增强对抗鲁棒性。在5个来自运动想象(MI)与事件相关电位(ERP)范式的EEG数据集上,SAFE持续优于14种先进方法,在解码准确率与对抗鲁棒性方面均表现优异,甚至超越未考虑隐私保护的集中式训练方法。据我们所知,SAFE是首个无需目标受试者校准数据即可同时实现高精度、强抗干扰性与可靠隐私保护的算法,极具实际应用价值。

原文摘要 · Abstract (English)

Electroencephalogram (EEG)-based brain-computer interfaces (BCIs) are widely adopted due to their efficiency and portability; however, their decoding algorithms still face multiple challenges, including inadequate generalization, adversarial vulnerability, and privacy leakage. This paper proposes Secure and Accurate FEderated learning (SAFE), a federated learning-based approach that protects user privacy by keeping data local during model training. SAFE employs local batch-specific normalization to mitigate cross-subject feature distribution shifts and hence improves model generalization. It further enhances adversarial robustness by introducing perturbations in both the input space and the parameter space through federated adversarial training and adversarial weight perturbation. Experiments on five EEG datasets from motor imagery (MI) and event-related potential (ERP) BCI paradigms demonstrated that SAFE consistently outperformed 14 state-of-the-art approaches in both decoding accuracy and adversarial robustness, while ensuring privacy protection. Notably, it even outperformed centralized training approaches that do not consider privacy protection at all. To our knowledge, SAFE is the first algorithm to simultaneously achieve high decoding accuracy, strong adversarial robustness, and reliable privacy protection without using any calibration data from the target subject, making it highly desirable for real-world BCIs.

脑机接口联邦学习隐私保护对抗鲁棒

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。