Protecting Privacy of Users in Brain-Computer Interface Applications
Pith reviewed 2026-05-25 10:47 UTC · model grok-4.3
The pith
Secure multiparty computation enables linear regression on EEG signals without revealing individual user data.
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The authors develop cryptographic protocols based on secure multiparty computation that perform linear regression over EEG signals from many users such that no individual's EEG signals are revealed to anyone else, and apply this to estimate driver drowsiness with performance comparable to the non-private case at reasonable computational cost. This is the first use of commodity-based SMC on EEG data and the largest secret-sharing SMC experiment with 15 players.
What carries the argument
Secure multiparty computation protocols for privacy-preserving linear regression on distributed EEG datasets
If this is right
- Linear regression models for EEG-based tasks can be trained without exposing raw signals.
- Drowsiness estimation from EEG can be done privately with similar accuracy to the unencrypted case.
- The framework supports computations involving up to 15 users with acceptable overhead.
- Privacy protection is achieved without loss of model utility for the target task.
Where Pith is reading between the lines
- The same approach could apply to other machine learning models beyond linear regression on EEG data.
- It opens possibilities for cross-institutional collaboration on BCI applications without sharing raw data.
- Reductions in SMC overhead might enable real-time private BCI inference in the future.
Load-bearing premise
The secure multiparty computation primitives can be efficiently realized for the volume and structure of real EEG datasets while preserving both privacy and the utility of linear regression for the target task.
What would settle it
Running the SMC protocol on real EEG data and finding that the resulting drowsiness prediction model has substantially lower accuracy than a standard linear regression trained on the pooled unencrypted data.
Figures
read the original abstract
Machine learning (ML) is revolutionizing research and industry. Many ML applications rely on the use of large amounts of personal data for training and inference. Among the most intimate exploited data sources is electroencephalogram (EEG) data, a kind of data that is so rich with information that application developers can easily gain knowledge beyond the professed scope from unprotected EEG signals, including passwords, ATM PINs, and other intimate data. The challenge we address is how to engage in meaningful ML with EEG data while protecting the privacy of users. Hence, we propose cryptographic protocols based on Secure Multiparty Computation (SMC) to perform linear regression over EEG signals from many users in a fully privacy-preserving (PP) fashion, i.e.~such that each individual's EEG signals are not revealed to anyone else. To illustrate the potential of our secure framework, we show how it allows estimating the drowsiness of drivers from their EEG signals as would be possible in the unencrypted case, and at a very reasonable computational cost. Our solution is the first application of commodity-based SMC to EEG data, as well as the largest documented experiment of secret sharing based SMC in general, namely with 15 players involved in all the computations.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes cryptographic protocols based on Secure Multiparty Computation (SMC) to perform linear regression over EEG signals from multiple users in a fully privacy-preserving manner, ensuring individual signals are not revealed. It illustrates the framework by estimating driver drowsiness from EEG data with performance equivalent to the unencrypted case at reasonable computational cost, claiming this as the first commodity-based SMC application to EEG data and the largest secret-sharing SMC experiment with 15 players.
Significance. If the protocols achieve exact utility preservation and scale with reasonable overhead on real EEG volumes, the work would enable collaborative privacy-preserving analysis of sensitive neural data in BCI applications, addressing key privacy risks in ML. The reported scale of the 15-player experiment would be a notable strength if backed by concrete timings and data dimensions.
major comments (3)
- [Abstract] Abstract: the claim that SMC-based regression 'allows estimating the drowsiness of drivers from their EEG signals as would be possible in the unencrypted case' lacks any error metrics, accuracy comparisons, or experimental results, which is load-bearing for validating that utility is preserved without approximation.
- [Abstract] Abstract: no matrix dimensions (channels, time samples), iteration counts, timing breakdowns, or communication costs are supplied for the 15-player experiment, preventing assessment of whether 'very reasonable computational cost' holds for typical EEG feature matrices (hundreds of channels, thousands of samples across 15+ parties).
- [Abstract] Abstract: the manuscript asserts SMC protocols for privacy-preserving linear regression but provides no security proofs, formal privacy analysis, or implementation details, which is essential to substantiate the 'fully privacy-preserving' guarantee.
Simulated Author's Rebuttal
We thank the referee for the detailed review and constructive feedback on our manuscript. We address each major comment point-by-point below, focusing on the abstract as noted. Where appropriate, we indicate willingness to revise for clarity while maintaining the paper's core contributions on SMC for EEG-based linear regression.
read point-by-point responses
-
Referee: [Abstract] Abstract: the claim that SMC-based regression 'allows estimating the drowsiness of drivers from their EEG signals as would be possible in the unencrypted case' lacks any error metrics, accuracy comparisons, or experimental results, which is load-bearing for validating that utility is preserved without approximation.
Authors: The abstract is a concise summary; the full manuscript (Section on experimental evaluation) reports that the privacy-preserving regression achieves equivalent performance to the plaintext case on the driver drowsiness EEG dataset, with matching accuracy metrics (e.g., comparable mean squared error or classification rates across the 15 parties). This is not an approximation but exact utility preservation due to the properties of the SMC protocol. We agree the abstract could better support the claim and will revise it to include a brief quantitative reference to the equivalence (e.g., 'with performance metrics matching the unencrypted baseline'). revision: yes
-
Referee: [Abstract] Abstract: no matrix dimensions (channels, time samples), iteration counts, timing breakdowns, or communication costs are supplied for the 15-player experiment, preventing assessment of whether 'very reasonable computational cost' holds for typical EEG feature matrices (hundreds of channels, thousands of samples across 15+ parties).
Authors: The manuscript body provides the experimental details for the 15-player setting, including EEG matrix dimensions, iteration counts for the regression, runtime breakdowns, and communication volumes, demonstrating feasibility at reasonable cost for the evaluated scales. The abstract summarizes these findings at a high level. We can partially revise the abstract to include key figures (e.g., approximate matrix sizes and total runtime) to aid assessment without exceeding length limits. revision: partial
-
Referee: [Abstract] Abstract: the manuscript asserts SMC protocols for privacy-preserving linear regression but provides no security proofs, formal privacy analysis, or implementation details, which is essential to substantiate the 'fully privacy-preserving' guarantee.
Authors: The protocols rely on established secret-sharing SMC primitives (commodity-based), with privacy following directly from the standard security definitions of the underlying framework (e.g., against semi-honest adversaries). The manuscript emphasizes the novel application to EEG data and the large-scale experiment rather than reproving base SMC results; implementation and protocol details appear in the main text. We do not believe formal proofs are required in the abstract itself, but can add a reference to the security model in a revision if needed. revision: no
Circularity Check
No circularity: protocol application is independent of fitted results or self-referential definitions
full rationale
The paper proposes applying existing secure multiparty computation primitives to perform linear regression on EEG data for privacy-preserving drowsiness estimation. No derivation chain reduces a claimed result to its own inputs by construction, no parameters are fitted and then relabeled as predictions, and no load-bearing uniqueness theorems or ansatzes are imported via self-citation. The central contribution is an engineering demonstration whose correctness rests on standard SMC security definitions and empirical timing measurements rather than any self-referential mathematical step.
Axiom & Free-Parameter Ledger
axioms (1)
- domain assumption Standard security assumptions of secure multiparty computation (e.g., semi-honest or malicious adversary models) hold for the EEG sharing scenario.
Reference graph
Works this paper leans on
-
[1]
How susceptible is the brain to the side-channel private information extraction,
T. Bonaci, J. Herron, and H. Chizeck, “How susceptible is the brain to the side-channel private information extraction,” American Journal of Bioethics, Neuroscience, vol. 6, no. 4, pp. 82–83, 2015
work page 2015
-
[2]
Neural markers of religious conviction,
M. Inzlicht, I. McGregor, J. B. Hirsh, and K. Nash, “Neural markers of religious conviction,” Psychol. Sci., vol. 20, no. 3, pp. 385–392, 2009
work page 2009
-
[3]
M. Poel, C. M ¨uhl, B. Reuderink, and A. Nijholt, “Guessing what’s on your mind,” in Int. Conf. of Brain Informatics , 2010, pp. 180–191
work page 2010
-
[4]
Attentional bias pattern recognition in spiking neural networks from spatio-temporal EEG data,
Z. G. Doborjeh, M. G. Doborjeh, and N. Kasabov, “Attentional bias pattern recognition in spiking neural networks from spatio-temporal EEG data,” Cognitive Computation, vol. 10, no. 1, pp. 35–48, 2018
work page 2018
-
[5]
X. Qian, B. R. Y . Loo, F. X. Castellanos, S. Liu, H. L. Koh, X. W. W. Poh, R. Krishnan, D. Fung, M. W. Chee, C. Guan et al. , “Brain- computer-interface-based intervention re-normalizes brain functional network topology in children with attention deficit/hyperactivity disor- der,” Translational Psychiatry, vol. 8, no. 1, p. 149, 2018
work page 2018
-
[6]
D. Wu, V . J. Lawhern, S. Gordon, B. J. Lance, and C.-T. Lin, “Driver drowsiness estimation from EEG signals using online weighted adap- tation regularization for regression (OwARR),” IEEE Transactions on Fuzzy Systems, vol. 25, no. 6, pp. 1522–1535, 2017. IEEE TRANSACTIONS ON NEURAL SYSTEMS AND REHABILITATION ENGINEERING 10
work page 2017
-
[7]
On the feasibility of side-channel attacks with brain-computer interfaces,
I. Martinovic, D. Davies, M. Frank, D. Perito, T. Ros, and D. Song, “On the feasibility of side-channel attacks with brain-computer interfaces,” in Proc. of the 21st USENIX Security Symposium , 2012
work page 2012
-
[8]
App stores for the brain: Privacy & security in brain-computer interfaces,
T. Bonaci, R. Calo, and H. J. Chizeck, “App stores for the brain: Privacy & security in brain-computer interfaces,” IEEE Technology and Society Magazine, vol. 34, no. 2, pp. 32–39, 2015
work page 2015
-
[9]
USACM statement on the importance of preserving personal privacy,
ACM, “USACM statement on the importance of preserving personal privacy,” https://www.acm.org/articles/bulletins/2018/march/ usacm-statement-on-data-privacy, 2018, accessed Mar 30, 2018
work page 2018
-
[10]
Systems and methods for deidentifying entries in a data source,
L. Sweeney, “Systems and methods for deidentifying entries in a data source,” 2007, US Patent 7,269,578
work page 2007
- [11]
-
[12]
Lynx: A framework for privacy preserving machine learning,
A. Agarwal, K. Saminathan, and S. Bhagat, “Lynx: A framework for privacy preserving machine learning,” https://bitbucket.org/uwtppml
-
[13]
Deep learning with differential privacy,
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Tal- war, and L. Zhang, “Deep learning with differential privacy,” in 23rd ACM SIGSAC Conf. on Comp. and Comm. Security , 2016, pp. 308–318
work page 2016
-
[14]
Securing data analytics on SGX with randomization,
S. Chandra, V . Karande, Z. Lin, L. Khan, M. Kantarcioglu, and B. Thu- raisingham, “Securing data analytics on SGX with randomization,” in Eur. Symp. on Research in Comp. Sec. Springer, 2017, pp. 352–369
work page 2017
-
[15]
Practical secure aggregation for privacy-preserving machine learning,
K. Bonawitz, V . Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical secure aggregation for privacy-preserving machine learning,” in24th ACM SIGSAC Conf. on Comp. and Comm. Security , 2017, pp. 1175–1191
work page 2017
-
[16]
Privacy-preserving deep learning,
R. Shokri and V . Shmatikov, “Privacy-preserving deep learning,” in CCS 2015, 2015, pp. 1310–1321
work page 2015
-
[17]
J. Wang, V . L. Cherkassky, and M. A. Just, “Predicting the brain activation pattern associated with the propositional content of a sentence: Modeling neural representations of events and states,” Human Brain Mapping, vol. 38, no. 10, pp. 4865–4881, 2017
work page 2017
-
[18]
Sharing deep generative representation for perceived image reconstruction from human brain activity,
C. Du, C. Du, and H. He, “Sharing deep generative representation for perceived image reconstruction from human brain activity,” in Proc. of International Joint Conf. on Neural Networks , 2017, pp. 1049–1056
work page 2017
-
[19]
Moving magnetoencephalography towards real-world applications with a wearable system,
E. Boto, N. Holmes, J. Leggett, G. Roberts, V . Shah, S. S. Meyer, L. D. Mu ˜noz, K. J. Mullinger, T. M. Tierney, S. Bestmann et al. , “Moving magnetoencephalography towards real-world applications with a wearable system,” Nature, vol. 555, pp. 657–661, 2018
work page 2018
-
[20]
Highly efficient linear regression outsourcing to a cloud,
F. Chen, T. Xiang, X. Lei, and J. Chen, “Highly efficient linear regression outsourcing to a cloud,” IEEE Transactions on Cloud Computing, vol. 2, no. 4, pp. 499–508, 2014
work page 2014
-
[21]
Secure multiple linear regres- sion based on homomorphic encryption,
R. Hall, S. E. Fienberg, and Y . Nardi, “Secure multiple linear regres- sion based on homomorphic encryption,” Journal of Official Statistics , vol. 27, no. 4, pp. 669–691, 2011
work page 2011
-
[22]
Fast and secure linear regression and biometric authentication with security update
Y . Aono, T. Hayashi, L. T. Phong, and L. Wang, “Fast and secure linear regression and biometric authentication with security update.” IACR Cryptology ePrint Archive , vol. 2015, p. 692, 2015
work page 2015
-
[23]
Privacy-preserving ridge regression on hundreds of millions of records,
V . Nikolaenko, U. Weinsberg, S. Ioannidis, M. Joye, D. Boneh, and N. Taft, “Privacy-preserving ridge regression on hundreds of millions of records,” in IEEE Symp. on Security and Privacy , 2013, pp. 334–348
work page 2013
-
[24]
Privacy-preserving analysis of vertically partitioned data using secure matrix products,
A. F. Karr, X. Lin, A. P. Sanil, and J. P. Reiter, “Privacy-preserving analysis of vertically partitioned data using secure matrix products,” Journal of Official Statistics , vol. 25, no. 1, p. 125, 2009
work page 2009
-
[25]
Privacy preserving re- gression modelling via distributed computation,
A. P. Sanil, A. F. Karr, X. Lin, and J. P. Reiter, “Privacy preserving re- gression modelling via distributed computation,” in 10th ACM SIGKDD Int. Conf. on Knowledge Disc. and Data Mining , 2004, pp. 677–682
work page 2004
-
[26]
Secure regression on distributed databases,
A. F. Karr, X. Lin, A. P. Sanil, and J. P. Reiter, “Secure regression on distributed databases,” Journal of Computational and Graphical Statistics, vol. 14, no. 2, pp. 263–279, 2005
work page 2005
-
[27]
Privacy-preserving cooperative statistical analysis,
W. Du and M. J. Atallah, “Privacy-preserving cooperative statistical analysis,” in 17th Annual Comp. Sec. Appl. Conf. , 2001, pp. 102–110
work page 2001
-
[28]
Fast, privacy preserving linear regression over distributed datasets based on pre-distributed data,
M. De Cock, R. Dowsley, A. C. A. Nascimento, and S. C. Newman, “Fast, privacy preserving linear regression over distributed datasets based on pre-distributed data,” in 8th ACM Workshop on Artificial Intelligence and Security (AISec) , 2015, pp. 3–14
work page 2015
-
[29]
Privacy-preserving distributed linear regression on high- dimensional data,
A. Gasc ´on, P. Schoppmann, B. Balle, M. Raykova, J. Doerner, S. Zahur, and D. Evans, “Privacy-preserving distributed linear regression on high- dimensional data,” Proceedings on Privacy Enhancing Technologies, vol. 2017, no. 4, pp. 345 – 364, 2017
work page 2017
-
[30]
Privacy-preserving multivariate statistical analysis: Linear regression and classification,
W. Du, Y . S. Han, and S. Chen, “Privacy-preserving multivariate statistical analysis: Linear regression and classification,” in 4th SIAM International Conference on Data Mining , 2004, pp. 222–233
work page 2004
-
[31]
Tools for privacy preserving distributed data mining,
C. Clifton, M. Kantarcioglu, J. Vaidya, X. Lin, and M. Y . Zhu, “Tools for privacy preserving distributed data mining,” SIGKDD Explor. Newsl., vol. 4, no. 2, pp. 28–34, 2002
work page 2002
-
[32]
A general survey of privacy- preserving data mining models and algorithms,
C. C. Aggarwal and S. Y . Philip, “A general survey of privacy- preserving data mining models and algorithms,” in Privacy-Preserving Data Mining. Springer, 2008, pp. 11–52
work page 2008
-
[33]
Practical secure decision tree learning in a teletreatment application,
S. de Hoogh, B. Schoenmakers, P. Chen, and H. op den Akker, “Practical secure decision tree learning in a teletreatment application,” in International Conference on Financial Cryptography and Data Security. Springer, 2014, pp. 179–194
work page 2014
-
[34]
Privacy-preserving scoring of tree ensembles: A novel framework for AI in healthcare,
K. Fritchman, K. Saminathan, R. Dowsley, T. Hughes, M. De Cock, A. Nascimento, and A. Teredesai, “Privacy-preserving scoring of tree ensembles: A novel framework for AI in healthcare,” in Proceedings of 2018 IEEE International Conference on Big Data, 2018, pp. 2412–2421
work page 2018
-
[35]
Sharemind: A framework for fast privacy-preserving computations,
D. Bogdanov, S. Laur, and J. Willemson, “Sharemind: A framework for fast privacy-preserving computations,” in 13th Eur. Symp. on Research in Comp. Sec. , 2008, pp. 192–206
work page 2008
-
[36]
FairplayMP: A system for secure multi-party computation,
A. Ben-David, N. Nisan, and B. Pinkas, “FairplayMP: A system for secure multi-party computation,” in Proc. of 15th ACM Conference on Computer and Communications Security , 2008, pp. 257–266
work page 2008
-
[37]
Chameleon: A Hybrid Secure Computation Framework for Machine Learning Applications,
M. Sadegh Riazi, C. Weinert, O. Tkachenko, E. M. Songhori, T. Schnei- der, and F. Koushanfar, “Chameleon: A Hybrid Secure Computation Framework for Machine Learning Applications,” ArXiv e-prints, 2018
work page 2018
-
[38]
Artificial intelligence helps to keep tired drivers awake,
T. Sandle, “Artificial intelligence helps to keep tired drivers awake,” http://www.digitaljournal.com/tech-and-science/technology/ artificial-intelligence-helps-to-keep-tired-drivers-awake/article/499369
-
[39]
Privacy-preserving linear regression for brain-computer interface applications,
A. Agarwal, R. Dowsley, N. D. McKinney, D. Wu, C.-T. Lin, M. De Cock, and A. Nascimento, “Privacy-preserving linear regression for brain-computer interface applications,” in Proceedings of 2018 IEEE International Conference on Big Data , 2018, pp. 5260–5261
work page 2018
-
[40]
One-time tables for two-party computation,
D. Beaver, “One-time tables for two-party computation,” in Computing and Combinatorics. Springer, 1998, pp. 361–370
work page 1998
-
[41]
B. David, R. Dowsley, R. Katti, and A. C. Nascimento, “Efficient unconditionally secure comparison and privacy preserving machine learning classification protocols,” in International Conference on Prov- able Security. Springer, 2015, pp. 354–367
work page 2015
-
[42]
M. De Cock, R. Dowsley, C. Horst, R. Katti, A. Nascimento, W.- S. Poon, and S. Truex, “Efficient and private scoring of decision trees, support vector machines and logistic regression models based on pre-computation,” IEEE Transactions on Dependable and Secure Computing, vol. 16, no. 2, pp. 217–230, March 2019
work page 2019
-
[43]
R. L. Rivest, “Unconditionally secure commitment and oblivious transfer schemes using private channels and a trusted initializer,” 1999, preprint available at http://people.csail.mit.edu/rivest/Rivest- commitment.pdf
work page 1999
-
[44]
Precomputing oblivious transfer,
D. Beaver, “Precomputing oblivious transfer,” in Annual Int. Cryptology Conference. Springer, 1995, pp. 97–109
work page 1995
-
[45]
A two-party protocol with trusted initializer for computing the inner prod- uct,
R. Dowsley, J. Van De Graaf, D. Marques, and A. C. Nascimento, “A two-party protocol with trusted initializer for computing the inner prod- uct,” in International Workshop on Information Security Applications . Springer, 2010, pp. 337–350
work page 2010
-
[46]
R. Dowsley, J. M ¨uller-Quade, A. Otsuka, G. Hanaoka, H. Imai, and A. C. A. Nascimento, “Universally composable and statistically secure verifiable secret sharing scheme based on pre-distributed data,” IEICE Transactions, vol. 94-A, no. 2, pp. 725–734, 2011
work page 2011
-
[47]
On the power of correlated randomness in secure com- putation,
Y . Ishai, E. Kushilevitz, S. Meldgaard, C. Orlandi, and A. Paskin- Cherniavsky, “On the power of correlated randomness in secure com- putation,” in Theory of Cryptography . Springer, 2013, pp. 600–620
work page 2013
-
[48]
Information-theoretically se- cure oblivious polynomial evaluation in the commodity-based model,
R. Tonicelli, A. C. A. Nascimento, R. Dowsley, J. M ¨uller-Quade, H. Imai, G. Hanaoka, and A. Otsuka, “Information-theoretically se- cure oblivious polynomial evaluation in the commodity-based model,” Int. Journal of Information Security , vol. 14, no. 1, pp. 73–84, 2015
work page 2015
-
[49]
Unconditionally secure, universally composable privacy preserving linear algebra,
B. David, R. Dowsley, J. van de Graaf, D. Marques, A. C. A. Nascimento, and A. C. B. Pinto, “Unconditionally secure, universally composable privacy preserving linear algebra,” IEEE Transactions on Information Forensics and Security , vol. 11, no. 1, pp. 59–73, 2016
work page 2016
-
[50]
Efficient multiparty protocols using circuit randomization,
D. Beaver, “Efficient multiparty protocols using circuit randomization,” in Annual Int. Cryptology Conf. Springer, 1991, pp. 420–432
work page 1991
-
[51]
Cryptography based on correlated data: Foundations and practice,
R. Dowsley, “Cryptography based on correlated data: Foundations and practice,” Ph.D. dissertation, Karlsruhe Institute of Technology, Germany, 2016
work page 2016
-
[52]
Secure computation with fixed-point num- bers,
O. Catrina and A. Saxena, “Secure computation with fixed-point num- bers,” in Int. Conf. on Financial Cryptography and Data Security . Springer, 2010, pp. 35–50
work page 2010
-
[53]
Selective transfer learning for EEG-based drowsiness detection,
C.-S. Wei, Y .-P. Lin, Y .-T. Wang, T.-P. Jung, N. Bigdely-Shamlo, and C.- T. Lin, “Selective transfer learning for EEG-based drowsiness detection,” in IEEE SMC 2015 , 2015, pp. 3229–3232
work page 2015
-
[54]
Lapse in alertness: coherence of fluctuations in performance and EEG spectrum,
S. Makeig and M. Inlow, “Lapse in alertness: coherence of fluctuations in performance and EEG spectrum,” Electroencephalography and Clinical Neurophysiology, vol. 86, no. 1, pp. 23–35, 1993
work page 1993
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.