神经接口模型证书通过但实际表现下降,需用新框架评估真实安全风险。
When Certificates Fail: A Unified Safety Framework for Embedded Neural Interface Models
- 提出统一审计框架,检测证书与实际性能的偏差
- 在扰动0.25下,脑电分类准确率降25.7%但证书仍有效
- 适合关注脑机接口安全性的研究人员和开发者
嵌入式神经接口模型的形式化鲁棒性证书可能通过,但任务准确率却急剧下降:在扰动预算 e=0.25 时,EEGNet 分类准确率在投影梯度攻击下下降 25.7%,而基于 Lipschitz 的证书对所有 9 名受试者均保持有效。我们指出,数学证书与实际安全之间的差距是神经接口中更广泛对齐失效的表现,训练目标与用户福祉发生偏离。为此,我们提出一个统一的实证审计框架,涵盖三类失效:验证不足(证书通过但任务行为恶化)、代理保真度偏差(任务优化表示破坏神经信号结构,时间域辅助目标使重建 MSE 降低 0.1132,但频谱 log-MSE 反而恶化)以及潜在信息泄露(公开任务嵌入可恢复主体身份,准确率达 48.1%,远高于随机水平 6.7%)。该框架在 BCI Competition IV 2a 与 SEED-IV 数据集上,使用多种深度与经典脑电解码器、官方会话级验证、零控制及配对统计检验进行验证。验证差距在 EEGNet、CSP+LDA 与 FBCSP+LDA 中均持续存在,表明其与架构无关。结果表明,负责任的神经接口部署必须依赖操作安全性审计,而非仅依赖证书验证。
原文摘要 · Abstract (English)
Formal robustness certificates for embedded neural-interface models can pass while task accuracy collapses: at perturbation budget e=0.25, EEGNet classification accuracy drops by 25.7% under projected-gradient attack while the Lipschitz-style certificate remains valid for all 9 tested subjects. We argue that this gap between mathematical certification and operational safety is one instance of a broader alignment failure in neural interfaces, where training objectives diverge from user welfare. We propose a unified empirical audit framework organized around three such failures: verification insufficiency, in which certificates pass while task behavior degrades; proxy-fidelity divergence, in which task-optimized representations damage neural signal structure (a time-domain auxiliary objective reduces reconstruction MSE by 0.1132 while worsening spectral log-MSE); and latent information exfiltration, in which public-task embeddings retain private attributes (subject identity recoverable at 48.1% versus 6.7% chance). We instantiate the framework on BCI Competition IV 2a and SEED-IV using multiple deep and classical EEG decoders, official session-level validation, null controls, and paired statistical tests. The verification gap persists across EEGNet, CSP+LDA, and FBCSP+LDA, and is therefore architecture-independent. Our results establish that operational safety auditing, not certificate verification alone, is necessary for responsible neural-interface deployment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。