Pith. sign in

REVIEW 3 major objections 5 minor 172 references

Neurosecurity lags far behind BCI capability; a full attack-surface map plus existing cyber, hardware, and ML defenses can close many gaps now.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

Neurosecurity lags BCI capability; a full-stack attack-surface taxonomy plus transferable defenses from cyber, hardware security, and private ML can close many gaps immediately.

T0 review reviewed 2026-07-14 challenge →

load-bearing objection Useful, well-sourced taxonomy of BCI attack surfaces that extends prior reviews and points to transferable defenses; the “apply these methods now” claim is an informed extrapolation, not a validated transfer result. the 3 major comments →

arxiv 2607.10451 v1 pith:JS6DILI5 submitted 2026-07-11 cs.CR cs.ETcs.HCq-bio.NC

Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology

classification cs.CR cs.ETcs.HCq-bio.NC
keywords neurosecuritybrain-computer interfacesattack surfacesdifferential privacypost-quantum cryptographyhardware Trojansadversarial machine learningneural biometrics
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Brain-computer interfaces are advancing rapidly into clinical and consumer use, but security research for them—neurosecurity—has not kept pace. This paper maps the full range of attack surfaces across the BCI cycle, from supply chains and chip fabrication through the brain’s physical substrate and cognition, wireless links, cloud pipelines, and machine-learning models. It argues that many of those threats are already firmly established or highly probable, and that methods already proven in cybersecurity, hardware security, and private or robust machine learning can be applied immediately to reduce risk. The practical aim is to give engineers, clinicians, and policymakers a usable taxonomy and a set of concrete, off-the-shelf countermeasures rather than waiting for new neuro-specific standards. If the map and recommendations hold, developers can stop treating security as an afterthought and start building systems that treat neural data and closed-loop stimulation as safety-critical from day one.

Core claim

The central claim is that neurosecurity research lags the expanding capabilities of BCIs, that the attack surface is far broader than prior surveys have catalogued—spanning supply chain, ASIC, air-gap and side-channel physics, neural signals as biometrics, cognition, wireless, cloud, and ML lifecycle attacks—and that existing methods from cybersecurity, hardware security, and differential privacy / robust ML can be applied right now to close many of those gaps.

What carries the argument

An unrolled BCI-cycle taxonomy of attack surfaces (Figure 1) that treats every arrow and node—from brain substrate and neural identity through acquisition, transmission, cloud, and ML models—as a concrete vulnerability locus, used to organize both threats and transferable defenses.

Load-bearing premise

The paper assumes that defenses proven on ordinary computers, chips, and machine-learning systems will still work on neural data and closed-loop brain devices once the modifications it sketches are applied, without new large-scale tests that check whether the statistics of brain signals or cognitive side channels break those guarantees.

What would settle it

Deploy a representative closed-loop BCI stack that implements the recommended post-quantum encryption, differential privacy, zero-trust, PUF attestation, and adversarial defenses, then measure whether reconstruction, RF injection, backdoor, and biometric re-identification attacks still succeed at rates that violate the claimed privacy or integrity bounds.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This survey argues that neurosecurity research lags BCI capability growth and that a broad taxonomy of attack surfaces—from supply-chain and hardware Trojans through neural signals, cognition, wireless links, cloud/containers, and ML pipelines—plus immediate reuse of existing methods from cybersecurity, hardware security, and private/robust ML can close many gaps now. It unrolls the BCI cycle into a linear attack-surface map, catalogs firmly demonstrated threats (RF injection into EEG, EEG backdoors, PIN side-channels, air-gap channels, Spectre/Meltdown/Rowhammer, cloud CVEs) and highly probable ones, and recommends concrete countermeasures (NIST PQC, differential privacy and DP-FL, formal verification, PUFs/attestation, zero-trust, Bluetooth 6.x hardening, adversarial training).

Significance. If the taxonomy is accurate and the recommended methods transfer with only the modifications sketched, the paper supplies a timely, actionable reference for BCI engineers and policy audiences at a moment when clinical and consumer devices are entering the market. Strengths include the unusually wide interdisciplinary span (neurophysiology through cloud containers), explicit treatment of multi-surface attack chains, and concrete pointers to deployable standards (NIST FIPS 203–205, Signal SPQR, formal tools such as ProVerif). As a pure survey it offers no new experiments, formal reductions, or machine-checked proofs; its value therefore rests on completeness of coverage and the defensibility of the transfer claims.

major comments (3)
  1. [Abstract, §1, Conclusion; cf. §2.2.1, §3.1.3, §2.4.1.1] Abstract, §1 and Conclusion assert that existing methods from cybersecurity, hardware security and private/robust ML “can immediately be applied” to close many neurosecurity gaps. That claim is load-bearing yet rests on an untested transfer premise. §2.2.1 and §3.1.3 themselves note unknown neurophysiology zero-days, non-stationarity that can mask adversarial concept drift, and that DP guarantees depend on statistical assumptions that may fail for neural signals; no experiment, simulation or formal reduction is supplied showing that any recommended protocol (DP-FL, PQE session keys, PUF attestation, UAP defenses, etc.) retains its stated privacy/security budget once these properties and cognitive side-channels (§2.2.1.5) are present. Either add concrete transfer analysis or substantially qualify the “immediately applicable” language.
  2. [§2 (esp. 2.1.3, 2.3.5, 2.4)] Throughout §2 the paper repeatedly elevates attacks demonstrated only on general computing or non-BCI biometrics to “highly probable” against BCIs once deployment scales (e.g., many air-gap channels, container escapes, model-extraction vectors). The axiom is stated without a clear threat-model criterion or likelihood argument. For a survey whose central contribution is a comprehensive taxonomy, the boundary between “firmly established” and “highly probable” needs an explicit, reproducible rule (e.g., existence of a working PoC on any mixed-signal sensor, or a formal reduction) so readers can assess residual risk.
  3. [§2.2.1.4–2.2.1.5 vs §3.1.3–3.1.5] §2.2.1.4–2.2.1.5 treat neural identity and cognitive processes as first-class attack surfaces and correctly note that conventional de-identification fails. The subsequent defense recommendations (§3.1.3–3.1.5) do not, however, supply even a sketch of how DP budgets, information-fiduciary rules or blockchain audit would be calibrated against the permanent, cross-task biometric nature of neural fingerprints or against cognitive correlates that can break privacy guarantees that ignore them. Without that linkage the taxonomy of threats outruns the taxonomy of mitigations on the paper’s most distinctive surfaces.
minor comments (5)
  1. [Figure 1, §2] Figure 1 is described as an “unrolled” BCI cycle but the caption and surrounding text do not enumerate which concrete attacks map to each arrow/shape; a short legend or table would make the figure self-contained.
  2. [§1, §2.2.1.5, §3.1.3] Self-citations to the authors’ prior/ongoing work on “cogits” and cognition-oriented protocols ([16,22–24]) are used as pointers rather than results; a single clarifying sentence that these are works-in-progress would avoid any appearance of over-claiming.
  3. [§2.2.1.1 and throughout] Typographical inconsistencies appear (e.g., “breaks” for “brakes” in the vehicle-hacking analogy; mixed en-dashes/hyphens; occasional missing spaces after citations). A careful copy-edit pass is needed.
  4. [§3.2.3] §3.2.3 recommends Bluetooth 6.x features (RPA cycling, channel sounding) that are still rolling out; a short note on current device support and fallback for legacy BLE would improve practicality.
  5. [§2.1.5.2] The ransomware business-considerations subsection (§2.1.5.2) is useful but sits awkwardly between technical threat analysis and defense methods; consider moving it to an appendix or a short “operational considerations” box.

Circularity Check

0 steps flagged

No significant circularity: survey taxonomy and defense recommendations rest on external literature; mild author self-pointers to ongoing cognitive-security work are non-load-bearing.

full rationale

This is a review/taxonomy paper, not a derivation of quantitative predictions from first principles or fitted parameters. The central claim (Abstract, §1, Conclusion)—that neurosecurity lags BCI capability and that a broad attack-surface taxonomy plus immediate transfer of existing cyber/hardware/ML methods can close many gaps—is supported by extensive external citations (e.g., Bernal et al. [20], air-gap literature, Spectre/Meltdown, DP foundations [143–150], NIST PQC, BLE attacks, BCI adversarial papers [9,13,14,127], etc.). There are no equations, no fitted inputs re-labeled as predictions, no uniqueness theorems imported from the authors, and no ansatz smuggled via self-citation. The only self-references ([16,22–24] on cognitive math/“cogits” and protocols under development) appear as forward-looking pointers (“Bagley and colleagues are working on…”, “there is already at least one formal protocol…”) rather than as the sole or load-bearing justification for the taxonomy or the transfer recommendations. Per the analyzer rules, ordinary self-citation that is not load-bearing and does not reduce a claimed result to its own inputs does not constitute circularity. Score 1 reflects only the presence of those non-essential self-pointers; the derivation chain (survey of threats + catalog of existing defenses) is self-contained against external benchmarks.

Axiom & Free-Parameter Ledger

0 free parameters · 5 axioms · 2 invented entities

As a survey, the paper introduces almost no free parameters or new physical entities. Load-bearing background is standard security and neuroscience domain assumptions plus a few author-coined framing terms carried from prior work. Invented or semi-invented framing is limited to ‘cogits’ and the cognitive-security protocol program referenced as ongoing.

axioms (5)
  • domain assumption The BCI cycle (acquisition → processing → application → feedback/stimulation) is an adequate organizing structure for enumerating attack surfaces.
    Used from §1–2 and Figure 1; inherited from prior BCI security literature (e.g., Bernal et al.) without independent validation that no major surface falls outside the cycle.
  • domain assumption Neural and neuromuscular signals function as stable biometric identifiers across sessions and tasks, so conventional de-identification is insufficient.
    §2.2.1.4 cites fMRI fingerprinting, EEG biometrics, and sEMG identification literature; treated as established fact for privacy recommendations.
  • domain assumption Post-quantum cryptography and differential privacy, under their standard threat models, remain meaningful when applied to neural data retention and model training.
    §2.1.2, §3.1.2–3.1.3; paper notes DP privacy budgets and assumption sensitivity but still recommends them as primary mitigations.
  • ad hoc to paper Many attacks that are only demonstrated on general computing or non-BCI biometrics are ‘highly probable’ against BCI systems once deployment scales.
    Abstract and §1 frame the survey as covering firmly established and highly probable threats; probability judgments are expert extrapolation, not measured rates.
  • standard math Standard mathematical and cryptographic results (Shor’s algorithm risk for HNDL, formal verification soundness for protocols like Signal/ProVerif, PUF uniqueness assumptions) hold as in the cited literature.
    Invoked in §2.1.2, §3.1.1–3.1.2, §2.1.1 without re-proof.
invented entities (2)
  • cogits (as a named unit of cognitive/functional neural content) no independent evidence
    purpose: Linguistic convenience for discussing reconstruction risk when signals cannot be cleanly segmented into intents or physiologic operations (§3.1.3, citing Bagley & Petritsch).
    Framing term from authors’ prior work; not a new physical object and not independently measured in this paper.
  • cognition-oriented neurosecurity protocols (work in progress) no independent evidence
    purpose: Claimed future formal protocols for cognitive attack surfaces (§1, [24]).
    Referenced as ongoing; not specified or evaluated here, so they do not support the survey’s present recommendations.

reviewed 2026-07-14 · how reviews work

0 comments
Cite this review

Pith. "Pith review of Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology." pith.science (2026). https://pith.science/paper/JS6DILI5

@misc{pith2026260710451,
  author       = {Pith},
  title        = {Pith review of: Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/JS6DILI5}},
  note         = {Machine review of arXiv:2607.10451}
}
Share X Bluesky LinkedIn Reddit HN
read the original abstract

Brain-computer interfaces (BCIs) are a class of diverse hardware modalities, associated software, and connected devices which are widely used in a variety of fields, including neurosurgery, biomedical data analysis, and neuroimaging. Recent years have seen rapid advancements in BCI technology, and neurotechnology more broadly, with the first devices now passing clinical trials, early examples of consumer hardware entering the market, and many variants of consumer and medical hardware with increasingly extensive capabilities being developed rapidly. However, research and development in security for BCIs--known as neurosecurity--lags significantly behind the capabilities of BCIs themselves. In an effort to address as many vulnerabilities as feasible immediately, in this paper we review the current state of the art in neurosecurity, thoroughly survey the breadth and complexity of both firmly established and highly probable security threats to BCI systems, and provide recommendations of existing methods from cybersecurity, hardware security, and machine learning which can immediately be applied to address some of these gaps in neurosecurity.

Figures

Figures reproduced from arXiv: 2607.10451 by Bryce-Allen Bagley, Matthew Canham, Nathaniel Rose, Quintus Kilbourn.

Figure 1
Figure 1. Figure 1: A simplified visualization categorizing the attack surfaces in the BCI cycle. While dif [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: Taxonomy of machine learning attack vectors relevant to BCI systems, organized by phase [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

172 extracted references · 51 canonical work pages

  1. [1]

    High performance communication by people with paralysis using an intracortical brain-computer interface

    Chethan Pandarinath et al. “High performance communication by people with paralysis using an intracortical brain-computer interface”. In:eLife6 (Feb. 2017).issn: 2050-084X.doi: 10.7554/elife.18554.url:http://dx.doi.org/10.7554/eLife.18554

  2. [2]

    Mind Reading and Writing: The Future of Neurotechnology

    Pieter R. Roelfsema, Damiaan Denys, and P. Christiaan Klink. “Mind Reading and Writing: The Future of Neurotechnology”. In:Trends in Cognitive Sciences22.7 (July 2018), pp. 598– 610.issn: 1364-6613.doi:10.1016/j.tics.2018.04.001.url:http://dx.doi.org/10. 1016/j.tics.2018.04.001. 16

  3. [3]

    High-performance brain-to-text communication via handwriting

    Francis R. Willett et al. “High-performance brain-to-text communication via handwriting”. In:Nature593.7858 (May 2021), pp. 249–254.issn: 1476-4687.doi:10.1038/s41586-021- 03506-2.url:http://dx.doi.org/10.1038/s41586-021-03506-2

  4. [5]

    The rise of brain-reading technology: what you need to know

    Liam Drew. “The rise of brain-reading technology: what you need to know”. In:Nature 623.7986 (Nov. 2023), pp. 241–243.issn: 1476-4687.doi:10.1038/d41586- 023- 03423- 6. url:http://dx.doi.org/10.1038/d41586-023-03423-6

  5. [6]

    Scotti et al.MindEye2: Shared-Subject Models Enable fMRI-To-Image With 1 Hour of Data

    Paul S. Scotti et al.MindEye2: Shared-Subject Models Enable fMRI-To-Image With 1 Hour of Data. 2024. arXiv:2403.11207 [cs.CV].url:https://arxiv.org/abs/2403.11207

  6. [7]

    Neurosecurity: security and pri- vacy for neural devices

    Tamara Denning, Yoky Matsuoka, and Tadayoshi Kohno. “Neurosecurity: security and pri- vacy for neural devices”. In:Neurosurgical Focus27.1 (July 2009), E7.issn: 1092-0684.doi: 10.3171/2009.4.focus0985.url:http://dx.doi.org/10.3171/2009.4.FOCUS0985

  7. [8]

    Mind Your Mind: EEG-Based Brain-Computer Interfaces and Their Security in Cyber Space

    Ofir Landau, Rami Puzis, and Nir Nissim. “Mind Your Mind: EEG-Based Brain-Computer Interfaces and Their Security in Cyber Space”. In:ACM Comput. Surv.53.1 (Feb. 2020). issn: 0360-0300.doi:10.1145/3372043.url:https://doi.org/10.1145/3372043

  8. [9]

    EEG-Based Brain-Computer Interfaces Are Vulnerable to Backdoor At- tacks

    Lubin Meng et al. “EEG-Based Brain-Computer Interfaces Are Vulnerable to Backdoor At- tacks”. In:IEEE Transactions on Neural Systems and Rehabilitation Engineering31 (2023), pp. 2224–2234.doi:10.1109/TNSRE.2023.3273214

  9. [10]

    Cybersecurity Framework for P300-based Brain Com- puter Interface

    Abdelkader Nasreddine Belkacem. “Cybersecurity Framework for P300-based Brain Com- puter Interface”. In:2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC). 2020, pp. 1–6.doi:10.1109/SMC42975.2020.9283100

  10. [11]

    Side-channel attacks against the human brain: the PIN code case study (extended version)

    Joseph Lange et al. “Side-channel attacks against the human brain: the PIN code case study (extended version)”. In:Brain Informatics5.2 (Oct. 2018).issn: 2198-4026.doi:10.1186/ s40708-018-0090-1.url:http://dx.doi.org/10.1186/s40708-018-0090-1

  11. [12]

    Cyberattacks on Miniature Brain Implants to Disrupt Spon- taneous Neural Signaling

    Sergio L´ opez Bernal et al. “Cyberattacks on Miniature Brain Implants to Disrupt Spon- taneous Neural Signaling”. In:IEEE Access8 (2020), pp. 152204–152222.doi:10 . 1109 / ACCESS.2020.3017394

  12. [13]

    Brain-Hack: Remotely In- jecting False Brain-Waves with RF to Take Control of a Brain-Computer Interface

    Alexandre Armengol-Urpi, Reid Kovacs, and Sanjay E. Sarma. “Brain-Hack: Remotely In- jecting False Brain-Waves with RF to Take Control of a Brain-Computer Interface”. In: Proceedings of the 5th Workshop on CPS&IoT Security and Privacy (CPSIoTSec). 2023. doi:10.1145/3605758.3623497

  13. [14]

    arXiv preprint arXiv:2409.20158

    Xuan-Hao Liu et al.Professor X: Manipulating EEG BCI with Invisible and Robust Backdoor Attack. arXiv preprint arXiv:2409.20158. 2024.url:https://arxiv.org/abs/2409.20158

  14. [15]

    Securing the exocortex: A twenty-first century cybernetics challenge

    Tamara Bonaci et al. “Securing the exocortex: A twenty-first century cybernetics challenge”. In:2014 IEEE Conference on Norbert Wiener in the 21st Century (21CW). 2014, pp. 1–8. doi:10.1109/NORBERT.2014.6893912

  15. [16]

    A Mathematical Framework for the Problem of Security for Cognition in Neurotechnology and AI

    Bryce Allen Bagley and Claudia Katherina Petritsch. “A Mathematical Framework for the Problem of Security for Cognition in Neurotechnology and AI”. In:arXiv(2024)

  16. [17]

    Brain Computer Interface (BCI) Appli- cations: Privacy Threats and Countermeasures

    Hassan Takabi, Anuj Bhalotiya, and Manar Alohaly. “Brain Computer Interface (BCI) Appli- cations: Privacy Threats and Countermeasures”. In:2016 IEEE 2nd International Conference on Collaboration and Internet Computing (CIC). 2016.doi:10.1109/CIC.2016.026

  17. [18]

    Brainjacking: Implant Security Issues in Invasive Neuromodulation

    Laurie Pycroft et al. “Brainjacking: Implant Security Issues in Invasive Neuromodulation”. In:World Neurosurgery92 (2016), pp. 454–462.issn: 1878-8750.doi:https://doi.org/10. 1016/j.wneu.2016.05.010.url:https://www.sciencedirect.com/science/article/ pii/S1878875016302728

  18. [19]

    Neurosecurity: Human Brain Electro-optical Signals as MASINT

    Matthew Canham and Ben D. Sawyer. “Neurosecurity: Human Brain Electro-optical Signals as MASINT”. In:American Intelligence Journal36.2 (2019), pp. 40–47

  19. [20]

    Security in Brain-Computer Interfaces: State-of-the-Art, Oppor- tunities, and Future Challenges

    Sergio L´ opez Bernal et al. “Security in Brain-Computer Interfaces: State-of-the-Art, Oppor- tunities, and Future Challenges”. In:ACM Comput. Surv.54.1 (Jan. 2021).issn: 0360-0300. doi:10.1145/3427376.url:https://doi.org/10.1145/3427376

  20. [21]

    Privacy-Preserving Brain–Computer Interfaces: A Systematic Review

    Kun Xia et al. “Privacy-Preserving Brain–Computer Interfaces: A Systematic Review”. In: IEEE Transactions on Computational Social Systems(2023).doi:10 . 1109 / TCSS . 2022 . 3184818

  21. [22]

    Bryce-Allen Bagley and Navin Khoshnan.Approximating the Mathematical Structure of Psy- chodynamics. 2025. arXiv:2511.05580 [q-bio.NC].url:https://arxiv.org/abs/2511. 05580

  22. [23]

    Brain leaks and consumer neu- rotechnology

    Marcello Ienca, Pim Haselager, and Ezekiel J Emanuel. “Brain leaks and consumer neu- rotechnology”. In:Nature Biotechnology36.9 (Oct. 2018), pp. 805–810.issn: 1546-1696.doi: 10.1038/nbt.4240.url:http://dx.doi.org/10.1038/nbt.4240. 17

  23. [24]

    Mathematical Formalization of Cognition for AI Safety

    Bryce-Allen Bagley. “Mathematical Formalization of Cognition for AI Safety”. In:Trust Ev- erything, Everywhere Workshop, Advanced Research and Invention Agency, UK Department of Science, Innovation, and Technology. 2025

  24. [25]

    Hardware Trojan Attacks: Threat Analysis and Countermeasures

    Swarup Bhunia et al. “Hardware Trojan Attacks: Threat Analysis and Countermeasures”. In: Proceedings of the IEEE102.8 (2014), pp. 1229–1247.doi:10.1109/JPROC.2014.2334493

  25. [26]

    Der Spiegel

    Jacob Appelbaum, Christian St¨ ocker, and Judith Horchert.Shopping for Spy Gear: Catalog Advertises NSA Toolbox. Der Spiegel. Reports NSA interdiction of network hardware in transit for implant installation. 2013.url:https : / / www . spiegel . de / international / world / catalog-reveals-nsa-has-back-doors-for-numerous-devices-a-940994.html

  26. [27]

    Ars Technica

    Sean Gallagher.Photos of an NSA “upgrade” factory show Cisco router getting implant. Ars Technica. 2014.url:https://arstechnica.com/tech-policy/2014/05/photos-of-an- nsa-upgrade-factory-show-cisco-router-getting-implant/

  27. [28]

    Tech Supplier

    Bloomberg Businessweek.The Long Hack: How China Exploited a U.S. Tech Supplier. Bloomberg Businessweek. Allegations of hardware implants in server motherboards; denied by the com- panies named. Cite as reported claim. 2021.url:https://www.bloomberg.com/features/ 2021-supermicro/

  28. [29]

    IACR Cryptology ePrint Archive, Report 2024/1275

    Philippe Teuwen.MIFARE Classic: Exposing the Static Encrypted Nonce Variant. IACR Cryptology ePrint Archive, Report 2024/1275. 2024.url:https : / / eprint . iacr . org / 2024/1275

  29. [30]

    Ledger Security — Threat Model,https : / / donjon

    Ledger SAS.Device Genuineness. Ledger Security — Threat Model,https : / / donjon . ledger.com/threat- model/device- genuineness/. Accessed March 2026. Describes the HSM-provisioned attestation certificate and challenge-response protocol by which Ledger ver- ifies device authenticity. 2024

  30. [31]

    Physical Unclonable Functions for Device Authen- tication and Secret Key Generation

    G. Edward Suh and Srinivas Devadas. “Physical Unclonable Functions for Device Authen- tication and Secret Key Generation”. In:44th ACM/IEEE Design Automation Conference (DAC). 2007, pp. 9–14.doi:10.1145/1278480.1278484

  31. [32]

    May 2018.doi:10

    Andrew Regenscheid.Platform firmware resiliency guidelines. May 2018.doi:10 . 6028 / nist.sp.800-193.url:http://dx.doi.org/10.6028/NIST.SP.800-193

  32. [33]

    Comprehensive decoding mental processes from Web repositories of functional brain images

    Romuald Menuet et al. “Comprehensive decoding mental processes from Web repositories of functional brain images”. In:Scientific Reports(2022).doi:10.1038/s41598-022-10710-1

  33. [34]

    Deep learning-based patient re-identification is able to exploit the biometric nature of medical chest X-ray data

    Kai Packh¨ auser et al. “Deep learning-based patient re-identification is able to exploit the biometric nature of medical chest X-ray data”. In:Scientific Reports(2022).doi:10.1038/ s41598-022-19045-3

  34. [35]

    ECG Unveiled: Analysis of Client Re-identification Risks in Real-World ECG Datasets

    Ziyu Wang et al. “ECG Unveiled: Analysis of Client Re-identification Risks in Real-World ECG Datasets”. In:2024 IEEE 20th International Conference on Body Sensor Networks (BSN). 2024.doi:10.1109/BSN63547.2024.10780752

  35. [36]

    A Survey on Air-Gap Attacks: Fundamentals, Transport Means, At- tack Scenarios and Challenges

    Jangyong Park et al. “A Survey on Air-Gap Attacks: Fundamentals, Transport Means, At- tack Scenarios and Challenges”. In:Sensors23.6 (2023).issn: 1424-8220.doi:10 . 3390 / s23063215

  36. [37]

    MAGNETO: Covert Channel be- tween Air-Gapped Systems and Nearby Smartphones via CPU-Generated Magnetic Fields

    Mordechai Guri, Andrey Daidakulov, and Yuval Elovici. “MAGNETO: Covert Channel be- tween Air-Gapped Systems and Nearby Smartphones via CPU-Generated Magnetic Fields”. In: (2018). arXiv:1802.02317 [cs.CR].url:https://arxiv.org/abs/1802.02317

  37. [38]

    ODINI : Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields

    Mordechai Guri et al. “ODINI : Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields”. In:CoRRabs/1802.02700 (2018). arXiv:1802.02700.url: http://arxiv.org/abs/1802.02700

  38. [39]

    Fansmitter: Acoustic Data Exfiltration from (Speakerless) Air-Gapped Computers

    Mordechai Guri et al. “Fansmitter: Acoustic Data Exfiltration from (Speakerless) Air-Gapped Computers”. In:CoRRabs/1606.05915 (2016). arXiv:1606.05915.url:http://arxiv.org/ abs/1606.05915

  39. [40]

    AiR-ViBeR: Exfiltrating Data from Air-Gapped Computers via Covert Surface ViBrAtIoNs

    Mordechai Guri. “AiR-ViBeR: Exfiltrating Data from Air-Gapped Computers via Covert Surface ViBrAtIoNs”. In:CoRRabs/2004.06195 (2020). arXiv:2004.06195.url:https: //arxiv.org/abs/2004.06195

  40. [41]

    USBee: Air-gap covert-channel via elec- tromagnetic emission from USB

    Mordechai Guri, Matan Monitz, and Yuval Elovici. “USBee: Air-gap covert-channel via elec- tromagnetic emission from USB”. In:2016 14th Annual Conference on Privacy, Security and Trust (PST). 2016.doi:10.1109/PST.2016.7906972

  41. [42]

    PowerHammer: Exfiltrating Data From Air-Gapped Computers Through Power Lines

    Mordechai Guri et al. “PowerHammer: Exfiltrating Data From Air-Gapped Computers Through Power Lines”. In:IEEE Transactions on Information Forensics and Security15 (2020).doi: 10.1109/TIFS.2019.2952257

  42. [43]

    MOSQUITO: Covert Ultrasonic Transmissions between Two Air- Gapped Computers using Speaker-to-Speaker Communication

    Mordechai Guri et al. “MOSQUITO: Covert Ultrasonic Transmissions between Two Air- Gapped Computers using Speaker-to-Speaker Communication”. In:CoRRabs/1803.03422 (2018). arXiv:1803.03422.url:http://arxiv.org/abs/1803.03422

  43. [44]

    BitWhisper: Covert Signaling Channel via Thermal Manipulations

    Mordechai Guri et al. “BitWhisper: Covert Signaling Channel via Thermal Manipulations”. In:IEEE Security & Privacy. 2015. 18

  44. [45]

    Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers

    Giovanni Camurati et al. “Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers”. In:Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS). 2018, pp. 163–177.doi:10.1145/3243734.3243802

  45. [46]

    Fault Injection Attacks on Cryptographic Devices: Theory, Prac- tice, and Countermeasures

    Alessandro Barenghi et al. “Fault Injection Attacks on Cryptographic Devices: Theory, Prac- tice, and Countermeasures”. In:Proceedings of the IEEE100.11 (2012), pp. 3056–3076.doi: 10.1109/JPROC.2012.2188769

  46. [47]

    CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management

    Adrian Tang, Simha Sethumadhavan, and Salvatore J. Stolfo. “CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management”. In:26th USENIX Security Symposium. 2017, pp. 1057–1074

  47. [48]

    Plundervolt: Software-Based Fault Injection Attacks against Intel SGX

    Kit Murdock et al. “Plundervolt: Software-Based Fault Injection Attacks against Intel SGX”. In:IEEE Symposium on Security and Privacy (S&P). 2020, pp. 1466–1482.doi:10.1109/ SP40000.2020.00057

  48. [49]

    Introduction to the Special Issue on High-Power Electromagnetics (HPEM) and Intentional Electromagnetic Interference (IEMI)

    W.A. Radasky, C.E. Baum, and M.W. Wik. “Introduction to the Special Issue on High-Power Electromagnetics (HPEM) and Intentional Electromagnetic Interference (IEMI)”. In:IEEE Transactions on Electromagnetic Compatibility(2004)

  49. [50]

    Spectre Attacks: Exploiting Speculative Exe- cution

    Paul Kocher, Jann Horn, Anders Fogh, et al. “Spectre Attacks: Exploiting Speculative Exe- cution”. In:IEEE Symposium on Security and Privacy (S&P). 2019, pp. 1–19.doi:10.1109/ SP.2019.00002

  50. [51]

    Meltdown: Reading Kernel Memory from User Space

    Moritz Lipp, Michael Schwarz, Daniel Gruss, et al. “Meltdown: Reading Kernel Memory from User Space”. In:27th USENIX Security Symposium. 2018, pp. 973–990.url:https: //www.usenix.org/conference/usenixsecurity18/presentation/lipp

  51. [52]

    Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors

    Yoongu Kim, Ross Daly, Jeremie Kim, et al. “Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors”. In:ACM/IEEE International Symposium on Computer Architecture (ISCA). 2014, pp. 361–372.doi:10.1145/2678373. 2665726

  52. [53]

    Guru Baran.Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption. 2025

  53. [54]

    Guru Baran.Record-breaking Ransom Payment: Dark Angels Ransomware Received$75 Mil- lion. 2024

  54. [55]

    Mohammad Khalil.Ransomware Payout Statistics 2025: Trends, Costs & Industry Insights. 2024

  55. [56]

    Place cells, grid cells, and mem- ory

    May-Britt Moser, David C Rowland, and Edvard I Moser. “Place cells, grid cells, and mem- ory”. en. In:Cold Spring Harb. Perspect. Biol.7.2 (Feb. 2015), a021808

  56. [57]

    A theory of the brain - the brain uses both distributed and localist (symbolic) rep- resentation

    Asim Roy. “A theory of the brain - the brain uses both distributed and localist (symbolic) rep- resentation”. In:The 2011 International Joint Conference on Neural Networks. 2011, pp. 215– 221.doi:10.1109/IJCNN.2011.6033224

  57. [58]

    Dan Goodin.Tampering with a car’s brakes and speed by hacking its computers: A new how- to.https://arstechnica.com/information-technology/2013/07/disabling-a-cars- brakes-and-speed-by-hacking-its-computers-a-new-how-to/. 2013. [59]Bupropion drug safety information

  58. [59]

    Functional connectome fingerprinting: identifying individuals using patterns of brain connectivity

    Emily S. Finn et al. “Functional connectome fingerprinting: identifying individuals using patterns of brain connectivity”. In:Nature Neuroscience18 (2015), pp. 1664–1671.doi:10. 1038/nn.4135

  59. [60]

    Contrastive learning for neural fingerprinting from limited neuroimag- ing data

    Nikolas Kampel et al. “Contrastive learning for neural fingerprinting from limited neuroimag- ing data”. In:Frontiers in Nuclear Medicine(2024).doi:10.3389/fnume.2024.1332747

  60. [61]

    Brain–Computer Interface for EEG-Based Authentication: Advance- ments and Practical Implications

    Lamia Alahaideb et al. “Brain–Computer Interface for EEG-Based Authentication: Advance- ments and Practical Implications”. In:Sensors(2025).doi:10.3390/s25164946

  61. [62]

    EEG-based identification system using deep neural networks with frequency features

    Yasaman Akbarnia and Mohammad Reza Daliri. “EEG-based identification system using deep neural networks with frequency features”. In:Heliyon(2024).doi:10.1016/j.heliyon. 2024.e25999

  62. [63]

    Brainprint: Assessing the uniqueness, collectability, and perma- nence of a novel method for ERP biometrics

    Blair C. Armstrong et al. “Brainprint: Assessing the uniqueness, collectability, and perma- nence of a novel method for ERP biometrics”. In:Neurocomputing166 (2015), pp. 59–67. doi:10.1016/j.neucom.2015.04.025

  63. [64]

    ResNet1D-based personal identification with multi-session sur- face electromyography for electronic health record integration

    Raghavendra Ganiga et al. “ResNet1D-based personal identification with multi-session sur- face electromyography for electronic health record integration”. In:Sensors24.10 (2024), p. 3140.doi:10.3390/s24103140

  64. [65]

    Multi-day dataset of forearm and wrist electromyogram for hand gesture recognition and biometrics

    Ashirbad Pradhan, Jiayuan He, and Ning Jiang. “Multi-day dataset of forearm and wrist electromyogram for hand gesture recognition and biometrics”. In:Scientific Data(2022). doi:10.1038/s41597-022-01836-y

  65. [66]

    Person-identifying brainprints are stably embedded in EEG mind- prints

    Yao-Yuan Yang et al. “Person-identifying brainprints are stably embedded in EEG mind- prints”. In:Scientific Reports(2022).doi:10.1038/s41598-022-21384-0. 19

  66. [67]

    Brain structure-function coupling provides signatures for task de- coding and individual fingerprinting

    Alessandra Griffa et al. “Brain structure-function coupling provides signatures for task de- coding and individual fingerprinting”. In:NeuroImage(2022).doi:10.1016/j.neuroimage. 2022.118970

  67. [68]

    Beyond neural data: Cognitive biometrics and mental privacy

    Patrick Magee, Marcello Ienca, and Nita Farahany. “Beyond neural data: Cognitive biometrics and mental privacy”. In:Neuron112.18 (2024), pp. 3017–3028.doi:10.1016/j.neuron. 2024.09.004

  68. [69]

    Quantitative EEG fingerprints: Spatiotemporal stabil- ity in interhemispheric and interannual coherence

    Sultan Tarlacı and A¸ celya Hıdımo˘ glu. “Quantitative EEG fingerprints: Spatiotemporal stabil- ity in interhemispheric and interannual coherence”. In:International Journal of Psychophys- iology207 (2025), p. 112478.doi:10.1016/j.ijpsycho.2024.112478

  69. [70]

    Joint disentangled representation and domain adversarial training for EEG-based cross-session biometric recognition in single-task protocols

    Honggang Liu et al. “Joint disentangled representation and domain adversarial training for EEG-based cross-session biometric recognition in single-task protocols”. In:Cognitive Neu- rodynamics(2025).doi:10.1007/s11571-024-10214-w

  70. [71]

    Adversarial deep learning in EEG biometrics

    Ozan ¨Ozdenizci et al. “Adversarial deep learning in EEG biometrics”. In:IEEE Signal Pro- cessing Letters26 (2019), pp. 710–714.doi:10.1109/LSP.2019.2906826

  71. [72]

    A deep descriptor for cross-tasking EEG-based recognition

    Mariana R. F. Mota et al. “A deep descriptor for cross-tasking EEG-based recognition”. In: PeerJ Computer Science7 (2021), e549.doi:10.7717/peerj-cs.549

  72. [73]

    Decision making and reward in frontal cor- tex: Complementary evidence from neurophysiological and neuropsychological studies

    Steven W. Kennerley and Mark E. Walton. “Decision making and reward in frontal cor- tex: Complementary evidence from neurophysiological and neuropsychological studies.” In: Behavioral Neuroscience125.3 (2011), pp. 297–317.doi:10.1037/a0023575

  73. [74]

    Adaptive neural coding: from biological to behavioral decision-making

    Kenway Louie, Paul W Glimcher, and Ryan Webb. “Adaptive neural coding: from biological to behavioral decision-making”. In:Current Opinion in Behavioral Sciences5 (Oct. 2015), pp. 91–99.doi:10.1016/j.cobeha.2015.08.008

  74. [75]

    Deficits in decision-making induced by parietal cortex inactivation are compensated at two timescales

    Danique Jeurissen et al. “Deficits in decision-making induced by parietal cortex inactivation are compensated at two timescales”. In:Neuron110.12 (2022), 1924–1931.e5.doi:10.1016/ j.neuron.2022.03.022

  75. [76]

    A brain-wide map of neural activity during complex behaviour

    International Brain Laboratory et al. “A brain-wide map of neural activity during complex behaviour”. In:Nature645.8079 (2025), pp. 177–191.doi:10.1038/s41586-025-09235-0

  76. [77]

    Rate and noise in human amygdala drive increased exploration in aversive learning

    Tamar Reitich-Stolero et al. “Rate and noise in human amygdala drive increased exploration in aversive learning”. In:Nature646.8086 (Aug. 2025), pp. 883–892.doi:10.1038/s41586- 025-09466-1

  77. [78]

    Acoustic Cryptanalysis

    Daniel Genkin, Adi Shamir, and Eran Tromer. “Acoustic Cryptanalysis”. In:Journal of Cryptology30.2 (2017), pp. 392–443.doi:10.1007/s00145-015-9224-2

  78. [79]

    Get Your Hands Off My Laptop: Physical Side-Channel Key-Extraction Attacks on PCs

    Daniel Genkin, Itamar Pipman, and Eran Tromer. “Get Your Hands Off My Laptop: Physical Side-Channel Key-Extraction Attacks on PCs”. In:Cryptographic Hardware and Embedded Systems (CHES 2014). 2014.doi:10.1007/978-3-662-44709-3_14

  79. [80]

    Bluetooth: With Low Energy Comes Low Security

    Mike Ryan. “Bluetooth: With Low Energy Comes Low Security”. In:7th USENIX Workshop on Offensive Technologies (WOOT 13). 2013.url:https://www.usenix.org/conference/ woot13/workshop-program/presentation/ryan

  80. [81]

    Tracking Anonymized Bluetooth De- vices

    Johannes K. Becker, David Li, and David Starobinski. “Tracking Anonymized Bluetooth De- vices”. In:Proceedings on Privacy Enhancing Technologies (PoPETs)2019.3 (2019), pp. 50– 65.url:https://petsymposium.org/popets/2019/popets-2019-0036.php

Showing first 80 references.

This paper was first reviewed by grok-4.5 on July 14, 2026.