Pith. sign in

REVIEW 3 major objections 5 minor 172 references

Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology

T0 review · 3 major / 5 minor · reviewed 2026-07-14 · grok-4.5

Pith's one-line read Neurosecurity lags far behind BCI capability; a full attack-surface map plus existing cyber, hardware, and ML defenses can close many gaps now.

desk verdict Useful, well-sourced taxonomy of BCI attack surfaces that extends prior reviews and points to transferable defenses; the “apply these methods now” claim is an informed extrapolation, not a validated transfer result. read the letter →

arxiv 2607.10451 v1 pith:JS6DILI5 submitted 2026-07-11 cs.CR cs.ETcs.HCq-bio.NC

classification cs.CRcs.ETcs.HCq-bio.NC
keywords neurosecuritybrain-computerinterfacesattacksurfacesdifferentialprivacypost-quantumcryptographyhardwareTrojansadversarialmachinelearningneuralbiometrics
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Brain-computer interfaces are advancing rapidly into clinical and consumer use, but security research for them—neurosecurity—has not kept pace. This paper maps the full range of attack surfaces across the BCI cycle, from supply chains and chip fabrication through the brain’s physical substrate and cognition, wireless links, cloud pipelines, and machine-learning models. It argues that many of those threats are already firmly established or highly probable, and that methods already proven in cybersecurity, hardware security, and private or robust machine learning can be applied immediately to reduce risk. The practical aim is to give engineers, clinicians, and policymakers a usable taxonomy and a set of concrete, off-the-shelf countermeasures rather than waiting for new neuro-specific standards. If the map and recommendations hold, developers can stop treating security as an afterthought and start building systems that treat neural data and closed-loop stimulation as safety-critical from day one.

What carries the argument

An unrolled BCI-cycle taxonomy of attack surfaces (Figure 1) that treats every arrow and node—from brain substrate and neural identity through acquisition, transmission, cloud, and ML models—as a concrete vulnerability locus, used to organize both threats and transferable defenses.

What would settle it

Deploy a representative closed-loop BCI stack that implements the recommended post-quantum encryption, differential privacy, zero-trust, PUF attestation, and adversarial defenses, then measure whether reconstruction, RF injection, backdoor, and biometric re-identification attacks still succeed at rates that violate the claimed privacy or integrity bounds.

Watch

Extended reading notes

Core claim

The central claim is that neurosecurity research lags the expanding capabilities of BCIs, that the attack surface is far broader than prior surveys have catalogued—spanning supply chain, ASIC, air-gap and side-channel physics, neural signals as biometrics, cognition, wireless, cloud, and ML lifecycle attacks—and that existing methods from cybersecurity, hardware security, and differential privacy / robust ML can be applied right now to close many of those gaps.

Load-bearing premise

The paper assumes that defenses proven on ordinary computers, chips, and machine-learning systems will still work on neural data and closed-loop brain devices once the modifications it sketches are applied, without new large-scale tests that check whether the statistics of brain signals or cognitive side channels break those guarantees.

Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This survey argues that neurosecurity research lags BCI capability growth and that a broad taxonomy of attack surfaces—from supply-chain and hardware Trojans through neural signals, cognition, wireless links, cloud/containers, and ML pipelines—plus immediate reuse of existing methods from cybersecurity, hardware security, and private/robust ML can close many gaps now. It unrolls the BCI cycle into a linear attack-surface map, catalogs firmly demonstrated threats (RF injection into EEG, EEG backdoors, PIN side-channels, air-gap channels, Spectre/Meltdown/Rowhammer, cloud CVEs) and highly probable ones, and recommends concrete countermeasures (NIST PQC, differential privacy and DP-FL, formal verification, PUFs/attestation, zero-trust, Bluetooth 6.x hardening, adversarial training).

Significance. If the taxonomy is accurate and the recommended methods transfer with only the modifications sketched, the paper supplies a timely, actionable reference for BCI engineers and policy audiences at a moment when clinical and consumer devices are entering the market. Strengths include the unusually wide interdisciplinary span (neurophysiology through cloud containers), explicit treatment of multi-surface attack chains, and concrete pointers to deployable standards (NIST FIPS 203–205, Signal SPQR, formal tools such as ProVerif). As a pure survey it offers no new experiments, formal reductions, or machine-checked proofs; its value therefore rests on completeness of coverage and the defensibility of the transfer claims.

major comments (3)
  1. [Abstract, §1, Conclusion; cf. §2.2.1, §3.1.3, §2.4.1.1] Abstract, §1 and Conclusion assert that existing methods from cybersecurity, hardware security and private/robust ML “can immediately be applied” to close many neurosecurity gaps. That claim is load-bearing yet rests on an untested transfer premise. §2.2.1 and §3.1.3 themselves note unknown neurophysiology zero-days, non-stationarity that can mask adversarial concept drift, and that DP guarantees depend on statistical assumptions that may fail for neural signals; no experiment, simulation or formal reduction is supplied showing that any recommended protocol (DP-FL, PQE session keys, PUF attestation, UAP defenses, etc.) retains its stated privacy/security budget once these properties and cognitive side-channels (§2.2.1.5) are present. Either add concrete transfer analysis or substantially qualify the “immediately applicable” language.
  2. [§2 (esp. 2.1.3, 2.3.5, 2.4)] Throughout §2 the paper repeatedly elevates attacks demonstrated only on general computing or non-BCI biometrics to “highly probable” against BCIs once deployment scales (e.g., many air-gap channels, container escapes, model-extraction vectors). The axiom is stated without a clear threat-model criterion or likelihood argument. For a survey whose central contribution is a comprehensive taxonomy, the boundary between “firmly established” and “highly probable” needs an explicit, reproducible rule (e.g., existence of a working PoC on any mixed-signal sensor, or a formal reduction) so readers can assess residual risk.
  3. [§2.2.1.4–2.2.1.5 vs §3.1.3–3.1.5] §2.2.1.4–2.2.1.5 treat neural identity and cognitive processes as first-class attack surfaces and correctly note that conventional de-identification fails. The subsequent defense recommendations (§3.1.3–3.1.5) do not, however, supply even a sketch of how DP budgets, information-fiduciary rules or blockchain audit would be calibrated against the permanent, cross-task biometric nature of neural fingerprints or against cognitive correlates that can break privacy guarantees that ignore them. Without that linkage the taxonomy of threats outruns the taxonomy of mitigations on the paper’s most distinctive surfaces.
minor comments (5)
  1. [Figure 1, §2] Figure 1 is described as an “unrolled” BCI cycle but the caption and surrounding text do not enumerate which concrete attacks map to each arrow/shape; a short legend or table would make the figure self-contained.
  2. [§1, §2.2.1.5, §3.1.3] Self-citations to the authors’ prior/ongoing work on “cogits” and cognition-oriented protocols ([16,22–24]) are used as pointers rather than results; a single clarifying sentence that these are works-in-progress would avoid any appearance of over-claiming.
  3. [§2.2.1.1 and throughout] Typographical inconsistencies appear (e.g., “breaks” for “brakes” in the vehicle-hacking analogy; mixed en-dashes/hyphens; occasional missing spaces after citations). A careful copy-edit pass is needed.
  4. [§3.2.3] §3.2.3 recommends Bluetooth 6.x features (RPA cycling, channel sounding) that are still rolling out; a short note on current device support and fallback for legacy BLE would improve practicality.
  5. [§2.1.5.2] The ransomware business-considerations subsection (§2.1.5.2) is useful but sits awkwardly between technical threat analysis and defense methods; consider moving it to an appendix or a short “operational considerations” box.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: survey taxonomy and defense recommendations rest on external literature; mild author self-pointers to ongoing cognitive-security work are non-load-bearing.

full rationale

This is a review/taxonomy paper, not a derivation of quantitative predictions from first principles or fitted parameters. The central claim (Abstract, §1, Conclusion)—that neurosecurity lags BCI capability and that a broad attack-surface taxonomy plus immediate transfer of existing cyber/hardware/ML methods can close many gaps—is supported by extensive external citations (e.g., Bernal et al. [20], air-gap literature, Spectre/Meltdown, DP foundations [143–150], NIST PQC, BLE attacks, BCI adversarial papers [9,13,14,127], etc.). There are no equations, no fitted inputs re-labeled as predictions, no uniqueness theorems imported from the authors, and no ansatz smuggled via self-citation. The only self-references ([16,22–24] on cognitive math/“cogits” and protocols under development) appear as forward-looking pointers (“Bagley and colleagues are working on…”, “there is already at least one formal protocol…”) rather than as the sole or load-bearing justification for the taxonomy or the transfer recommendations. Per the analyzer rules, ordinary self-citation that is not load-bearing and does not reduce a claimed result to its own inputs does not constitute circularity. Score 1 reflects only the presence of those non-essential self-pointers; the derivation chain (survey of threats + catalog of existing defenses) is self-contained against external benchmarks.

Assumptions & free parameters 0 free parameters · 5 assumptions · 2 invented entities

As a survey, the paper introduces almost no free parameters or new physical entities. Load-bearing background is standard security and neuroscience domain assumptions plus a few author-coined framing terms carried from prior work. Invented or semi-invented framing is limited to ‘cogits’ and the cognitive-security protocol program referenced as ongoing.

assumptions (5)
  • domain assumption The BCI cycle (acquisition → processing → application → feedback/stimulation) is an adequate organizing structure for enumerating attack surfaces.
    Used from §1–2 and Figure 1; inherited from prior BCI security literature (e.g., Bernal et al.) without independent validation that no major surface falls outside the cycle.
  • domain assumption Neural and neuromuscular signals function as stable biometric identifiers across sessions and tasks, so conventional de-identification is insufficient.
    §2.2.1.4 cites fMRI fingerprinting, EEG biometrics, and sEMG identification literature; treated as established fact for privacy recommendations.
  • domain assumption Post-quantum cryptography and differential privacy, under their standard threat models, remain meaningful when applied to neural data retention and model training.
    §2.1.2, §3.1.2–3.1.3; paper notes DP privacy budgets and assumption sensitivity but still recommends them as primary mitigations.
  • ad hoc to paper Many attacks that are only demonstrated on general computing or non-BCI biometrics are ‘highly probable’ against BCI systems once deployment scales.
    Abstract and §1 frame the survey as covering firmly established and highly probable threats; probability judgments are expert extrapolation, not measured rates.
  • standard math Standard mathematical and cryptographic results (Shor’s algorithm risk for HNDL, formal verification soundness for protocols like Signal/ProVerif, PUF uniqueness assumptions) hold as in the cited literature.
    Invoked in §2.1.2, §3.1.1–3.1.2, §2.1.1 without re-proof.
invented entities (2)
  • cogits (as a named unit of cognitive/functional neural content)
    purpose: Linguistic convenience for discussing reconstruction risk when signals cannot be cleanly segmented into intents or physiologic operations (§3.1.3, citing Bagley & Petritsch).
    Framing term from authors’ prior work; not a new physical object and not independently measured in this paper.
  • cognition-oriented neurosecurity protocols (work in progress)
    purpose: Claimed future formal protocols for cognitive attack surfaces (§1, [24]).
    Referenced as ongoing; not specified or evaluated here, so they do not support the survey’s present recommendations.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology." pith.science (2026). https://pith.science/paper/JS6DILI5

@misc{pith2026260710451,
  author       = {Pith},
  title        = {Pith review of: Threat Vectors and the State of the Art in Defense Methods for Security in Neurotechnology},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/JS6DILI5}},
  note         = {Machine review of arXiv:2607.10451}
}
read the original abstract

Brain-computer interfaces (BCIs) are a class of diverse hardware modalities, associated software, and connected devices which are widely used in a variety of fields, including neurosurgery, biomedical data analysis, and neuroimaging. Recent years have seen rapid advancements in BCI technology, and neurotechnology more broadly, with the first devices now passing clinical trials, early examples of consumer hardware entering the market, and many variants of consumer and medical hardware with increasingly extensive capabilities being developed rapidly. However, research and development in security for BCIs--known as neurosecurity--lags significantly behind the capabilities of BCIs themselves. In an effort to address as many vulnerabilities as feasible immediately, in this paper we review the current state of the art in neurosecurity, thoroughly survey the breadth and complexity of both firmly established and highly probable security threats to BCI systems, and provide recommendations of existing methods from cybersecurity, hardware security, and machine learning which can immediately be applied to address some of these gaps in neurosecurity.

Figures

Figures reproduced from arXiv: 2607.10451 by the authors.

Figure 1
Figure 1. A simplified visualization categorizing the attack surfaces in the BCI cycle. While dif [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Taxonomy of machine learning attack vectors relevant to BCI systems, organized by phase [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

172 extracted references · 51 canonical work pages

  1. [1]

    High performance communication by people with paralysis using an intracortical brain-computer interface

    Chethan Pandarinath et al. “High performance communication by people with paralysis using an intracortical brain-computer interface”. In:eLife6 (Feb. 2017).issn: 2050-084X.doi: 10.7554/elife.18554.url:http://dx.doi.org/10.7554/eLife.18554

  2. [2]

    Mind Reading and Writing: The Future of Neurotechnology

    Pieter R. Roelfsema, Damiaan Denys, and P. Christiaan Klink. “Mind Reading and Writing: The Future of Neurotechnology”. In:Trends in Cognitive Sciences22.7 (July 2018), pp. 598– 610.issn: 1364-6613.doi:10.1016/j.tics.2018.04.001.url:http://dx.doi.org/10. 1016/j.tics.2018.04.001. 16

  3. [3]

    High-performance brain-to-text communication via handwriting

    Francis R. Willett et al. “High-performance brain-to-text communication via handwriting”. In:Nature593.7858 (May 2021), pp. 249–254.issn: 1476-4687.doi:10.1038/s41586-021- 03506-2.url:http://dx.doi.org/10.1038/s41586-021-03506-2

  4. [5]

    The rise of brain-reading technology: what you need to know

    Liam Drew. “The rise of brain-reading technology: what you need to know”. In:Nature 623.7986 (Nov. 2023), pp. 241–243.issn: 1476-4687.doi:10.1038/d41586- 023- 03423- 6. url:http://dx.doi.org/10.1038/d41586-023-03423-6

  5. [6]

    Scotti et al.MindEye2: Shared-Subject Models Enable fMRI-To-Image With 1 Hour of Data

    Paul S. Scotti et al.MindEye2: Shared-Subject Models Enable fMRI-To-Image With 1 Hour of Data. 2024. arXiv:2403.11207 [cs.CV].url:https://arxiv.org/abs/2403.11207

  6. [7]

    Neurosecurity: security and pri- vacy for neural devices

    Tamara Denning, Yoky Matsuoka, and Tadayoshi Kohno. “Neurosecurity: security and pri- vacy for neural devices”. In:Neurosurgical Focus27.1 (July 2009), E7.issn: 1092-0684.doi: 10.3171/2009.4.focus0985.url:http://dx.doi.org/10.3171/2009.4.FOCUS0985

  7. [8]

    Mind Your Mind: EEG-Based Brain-Computer Interfaces and Their Security in Cyber Space

    Ofir Landau, Rami Puzis, and Nir Nissim. “Mind Your Mind: EEG-Based Brain-Computer Interfaces and Their Security in Cyber Space”. In:ACM Comput. Surv.53.1 (Feb. 2020). issn: 0360-0300.doi:10.1145/3372043.url:https://doi.org/10.1145/3372043

  8. [9]

    EEG-Based Brain-Computer Interfaces Are Vulnerable to Backdoor At- tacks

    Lubin Meng et al. “EEG-Based Brain-Computer Interfaces Are Vulnerable to Backdoor At- tacks”. In:IEEE Transactions on Neural Systems and Rehabilitation Engineering31 (2023), pp. 2224–2234.doi:10.1109/TNSRE.2023.3273214

Show all 172 references
  1. [10]

    Cybersecurity Framework for P300-based Brain Com- puter Interface

    Abdelkader Nasreddine Belkacem. “Cybersecurity Framework for P300-based Brain Com- puter Interface”. In:2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC). 2020, pp. 1–6.doi:10.1109/SMC42975.2020.9283100

  2. [11]

    Side-channel attacks against the human brain: the PIN code case study (extended version)

    Joseph Lange et al. “Side-channel attacks against the human brain: the PIN code case study (extended version)”. In:Brain Informatics5.2 (Oct. 2018).issn: 2198-4026.doi:10.1186/ s40708-018-0090-1.url:http://dx.doi.org/10.1186/s40708-018-0090-1

  3. [12]

    Cyberattacks on Miniature Brain Implants to Disrupt Spon- taneous Neural Signaling

    Sergio L´ opez Bernal et al. “Cyberattacks on Miniature Brain Implants to Disrupt Spon- taneous Neural Signaling”. In:IEEE Access8 (2020), pp. 152204–152222.doi:10 . 1109 / ACCESS.2020.3017394

  4. [13]

    Brain-Hack: Remotely In- jecting False Brain-Waves with RF to Take Control of a Brain-Computer Interface

    Alexandre Armengol-Urpi, Reid Kovacs, and Sanjay E. Sarma. “Brain-Hack: Remotely In- jecting False Brain-Waves with RF to Take Control of a Brain-Computer Interface”. In: Proceedings of the 5th Workshop on CPS&IoT Security and Privacy (CPSIoTSec). 2023. doi:10.1145/3605758.3623497

  5. [14]

    arXiv preprint arXiv:2409.20158

    Xuan-Hao Liu et al.Professor X: Manipulating EEG BCI with Invisible and Robust Backdoor Attack. arXiv preprint arXiv:2409.20158. 2024.url:https://arxiv.org/abs/2409.20158

  6. [15]

    Securing the exocortex: A twenty-first century cybernetics challenge

    Tamara Bonaci et al. “Securing the exocortex: A twenty-first century cybernetics challenge”. In:2014 IEEE Conference on Norbert Wiener in the 21st Century (21CW). 2014, pp. 1–8. doi:10.1109/NORBERT.2014.6893912

  7. [16]

    A Mathematical Framework for the Problem of Security for Cognition in Neurotechnology and AI

    Bryce Allen Bagley and Claudia Katherina Petritsch. “A Mathematical Framework for the Problem of Security for Cognition in Neurotechnology and AI”. In:arXiv(2024)

  8. [17]

    Brain Computer Interface (BCI) Appli- cations: Privacy Threats and Countermeasures

    Hassan Takabi, Anuj Bhalotiya, and Manar Alohaly. “Brain Computer Interface (BCI) Appli- cations: Privacy Threats and Countermeasures”. In:2016 IEEE 2nd International Conference on Collaboration and Internet Computing (CIC). 2016.doi:10.1109/CIC.2016.026

  9. [18]

    Brainjacking: Implant Security Issues in Invasive Neuromodulation

    Laurie Pycroft et al. “Brainjacking: Implant Security Issues in Invasive Neuromodulation”. In:World Neurosurgery92 (2016), pp. 454–462.issn: 1878-8750.doi:https://doi.org/10. 1016/j.wneu.2016.05.010.url:https://www.sciencedirect.com/science/article/ pii/S1878875016302728

  10. [19]

    Neurosecurity: Human Brain Electro-optical Signals as MASINT

    Matthew Canham and Ben D. Sawyer. “Neurosecurity: Human Brain Electro-optical Signals as MASINT”. In:American Intelligence Journal36.2 (2019), pp. 40–47

  11. [20]

    Security in Brain-Computer Interfaces: State-of-the-Art, Oppor- tunities, and Future Challenges

    Sergio L´ opez Bernal et al. “Security in Brain-Computer Interfaces: State-of-the-Art, Oppor- tunities, and Future Challenges”. In:ACM Comput. Surv.54.1 (Jan. 2021).issn: 0360-0300. doi:10.1145/3427376.url:https://doi.org/10.1145/3427376

  12. [21]

    Privacy-Preserving Brain–Computer Interfaces: A Systematic Review

    Kun Xia et al. “Privacy-Preserving Brain–Computer Interfaces: A Systematic Review”. In: IEEE Transactions on Computational Social Systems(2023).doi:10 . 1109 / TCSS . 2022 . 3184818

  13. [22]

    Bryce-Allen Bagley and Navin Khoshnan.Approximating the Mathematical Structure of Psy- chodynamics. 2025. arXiv:2511.05580 [q-bio.NC].url:https://arxiv.org/abs/2511. 05580

  14. [23]

    Brain leaks and consumer neu- rotechnology

    Marcello Ienca, Pim Haselager, and Ezekiel J Emanuel. “Brain leaks and consumer neu- rotechnology”. In:Nature Biotechnology36.9 (Oct. 2018), pp. 805–810.issn: 1546-1696.doi: 10.1038/nbt.4240.url:http://dx.doi.org/10.1038/nbt.4240. 17

  15. [24]

    Mathematical Formalization of Cognition for AI Safety

    Bryce-Allen Bagley. “Mathematical Formalization of Cognition for AI Safety”. In:Trust Ev- erything, Everywhere Workshop, Advanced Research and Invention Agency, UK Department of Science, Innovation, and Technology. 2025

  16. [25]

    Hardware Trojan Attacks: Threat Analysis and Countermeasures

    Swarup Bhunia et al. “Hardware Trojan Attacks: Threat Analysis and Countermeasures”. In: Proceedings of the IEEE102.8 (2014), pp. 1229–1247.doi:10.1109/JPROC.2014.2334493

  17. [26]

    Der Spiegel

    Jacob Appelbaum, Christian St¨ ocker, and Judith Horchert.Shopping for Spy Gear: Catalog Advertises NSA Toolbox. Der Spiegel. Reports NSA interdiction of network hardware in transit for implant installation. 2013.url:https : / / www . spiegel . de / international / world / cat...

  18. [27]

    Ars Technica

    Sean Gallagher.Photos of an NSA “upgrade” factory show Cisco router getting implant. Ars Technica. 2014.url:https://arstechnica.com/tech-policy/2014/05/photos-of-an- nsa-upgrade-factory-show-cisco-router-getting-implant/

  19. [28]

    Tech Supplier

    Bloomberg Businessweek.The Long Hack: How China Exploited a U.S. Tech Supplier. Bloomberg Businessweek. Allegations of hardware implants in server motherboards; denied by the com- panies named. Cite as reported claim. 2021.url:https://www.bloomberg.com/features/ 2021-supermicro/

  20. [29]

    IACR Cryptology ePrint Archive, Report 2024/1275

    Philippe Teuwen.MIFARE Classic: Exposing the Static Encrypted Nonce Variant. IACR Cryptology ePrint Archive, Report 2024/1275. 2024.url:https : / / eprint . iacr . org / 2024/1275

  21. [30]

    Ledger Security — Threat Model,https : / / donjon

    Ledger SAS.Device Genuineness. Ledger Security — Threat Model,https : / / donjon . ledger.com/threat- model/device- genuineness/. Accessed March 2026. Describes the HSM-provisioned attestation certificate and challenge-response protocol by which Ledger ver- ifies device authen...

  22. [31]

    Physical Unclonable Functions for Device Authen- tication and Secret Key Generation

    G. Edward Suh and Srinivas Devadas. “Physical Unclonable Functions for Device Authen- tication and Secret Key Generation”. In:44th ACM/IEEE Design Automation Conference (DAC). 2007, pp. 9–14.doi:10.1145/1278480.1278484

  23. [32]

    May 2018.doi:10

    Andrew Regenscheid.Platform firmware resiliency guidelines. May 2018.doi:10 . 6028 / nist.sp.800-193.url:http://dx.doi.org/10.6028/NIST.SP.800-193

  24. [33]

    Comprehensive decoding mental processes from Web repositories of functional brain images

    Romuald Menuet et al. “Comprehensive decoding mental processes from Web repositories of functional brain images”. In:Scientific Reports(2022).doi:10.1038/s41598-022-10710-1

  25. [34]

    Deep learning-based patient re-identification is able to exploit the biometric nature of medical chest X-ray data

    Kai Packh¨ auser et al. “Deep learning-based patient re-identification is able to exploit the biometric nature of medical chest X-ray data”. In:Scientific Reports(2022).doi:10.1038/ s41598-022-19045-3

  26. [35]

    ECG Unveiled: Analysis of Client Re-identification Risks in Real-World ECG Datasets

    Ziyu Wang et al. “ECG Unveiled: Analysis of Client Re-identification Risks in Real-World ECG Datasets”. In:2024 IEEE 20th International Conference on Body Sensor Networks (BSN). 2024.doi:10.1109/BSN63547.2024.10780752

  27. [36]

    A Survey on Air-Gap Attacks: Fundamentals, Transport Means, At- tack Scenarios and Challenges

    Jangyong Park et al. “A Survey on Air-Gap Attacks: Fundamentals, Transport Means, At- tack Scenarios and Challenges”. In:Sensors23.6 (2023).issn: 1424-8220.doi:10 . 3390 / s23063215

  28. [37]

    MAGNETO: Covert Channel be- tween Air-Gapped Systems and Nearby Smartphones via CPU-Generated Magnetic Fields

    Mordechai Guri, Andrey Daidakulov, and Yuval Elovici. “MAGNETO: Covert Channel be- tween Air-Gapped Systems and Nearby Smartphones via CPU-Generated Magnetic Fields”. In: (2018). arXiv:1802.02317 [cs.CR].url:https://arxiv.org/abs/1802.02317

  29. [38]

    ODINI : Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields

    Mordechai Guri et al. “ODINI : Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields”. In:CoRRabs/1802.02700 (2018). arXiv:1802.02700.url: http://arxiv.org/abs/1802.02700

  30. [39]

    Fansmitter: Acoustic Data Exfiltration from (Speakerless) Air-Gapped Computers

    Mordechai Guri et al. “Fansmitter: Acoustic Data Exfiltration from (Speakerless) Air-Gapped Computers”. In:CoRRabs/1606.05915 (2016). arXiv:1606.05915.url:http://arxiv.org/ abs/1606.05915

  31. [40]

    AiR-ViBeR: Exfiltrating Data from Air-Gapped Computers via Covert Surface ViBrAtIoNs

    Mordechai Guri. “AiR-ViBeR: Exfiltrating Data from Air-Gapped Computers via Covert Surface ViBrAtIoNs”. In:CoRRabs/2004.06195 (2020). arXiv:2004.06195.url:https: //arxiv.org/abs/2004.06195

  32. [41]

    USBee: Air-gap covert-channel via elec- tromagnetic emission from USB

    Mordechai Guri, Matan Monitz, and Yuval Elovici. “USBee: Air-gap covert-channel via elec- tromagnetic emission from USB”. In:2016 14th Annual Conference on Privacy, Security and Trust (PST). 2016.doi:10.1109/PST.2016.7906972

  33. [42]

    PowerHammer: Exfiltrating Data From Air-Gapped Computers Through Power Lines

    Mordechai Guri et al. “PowerHammer: Exfiltrating Data From Air-Gapped Computers Through Power Lines”. In:IEEE Transactions on Information Forensics and Security15 (2020).doi: 10.1109/TIFS.2019.2952257

  34. [43]

    MOSQUITO: Covert Ultrasonic Transmissions between Two Air- Gapped Computers using Speaker-to-Speaker Communication

    Mordechai Guri et al. “MOSQUITO: Covert Ultrasonic Transmissions between Two Air- Gapped Computers using Speaker-to-Speaker Communication”. In:CoRRabs/1803.03422 (2018). arXiv:1803.03422.url:http://arxiv.org/abs/1803.03422

  35. [44]

    BitWhisper: Covert Signaling Channel via Thermal Manipulations

    Mordechai Guri et al. “BitWhisper: Covert Signaling Channel via Thermal Manipulations”. In:IEEE Security & Privacy. 2015. 18

  36. [45]

    Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers

    Giovanni Camurati et al. “Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers”. In:Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS). 2018, pp. 163–177.doi:10.1145/3243734.3243802

  37. [46]

    Fault Injection Attacks on Cryptographic Devices: Theory, Prac- tice, and Countermeasures

    Alessandro Barenghi et al. “Fault Injection Attacks on Cryptographic Devices: Theory, Prac- tice, and Countermeasures”. In:Proceedings of the IEEE100.11 (2012), pp. 3056–3076.doi: 10.1109/JPROC.2012.2188769

  38. [47]

    CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management

    Adrian Tang, Simha Sethumadhavan, and Salvatore J. Stolfo. “CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management”. In:26th USENIX Security Symposium. 2017, pp. 1057–1074

  39. [48]

    Plundervolt: Software-Based Fault Injection Attacks against Intel SGX

    Kit Murdock et al. “Plundervolt: Software-Based Fault Injection Attacks against Intel SGX”. In:IEEE Symposium on Security and Privacy (S&P). 2020, pp. 1466–1482.doi:10.1109/ SP40000.2020.00057

  40. [49]

    Introduction to the Special Issue on High-Power Electromagnetics (HPEM) and Intentional Electromagnetic Interference (IEMI)

    W.A. Radasky, C.E. Baum, and M.W. Wik. “Introduction to the Special Issue on High-Power Electromagnetics (HPEM) and Intentional Electromagnetic Interference (IEMI)”. In:IEEE Transactions on Electromagnetic Compatibility(2004)

  41. [50]

    Spectre Attacks: Exploiting Speculative Exe- cution

    Paul Kocher, Jann Horn, Anders Fogh, et al. “Spectre Attacks: Exploiting Speculative Exe- cution”. In:IEEE Symposium on Security and Privacy (S&P). 2019, pp. 1–19.doi:10.1109/ SP.2019.00002

  42. [51]

    Meltdown: Reading Kernel Memory from User Space

    Moritz Lipp, Michael Schwarz, Daniel Gruss, et al. “Meltdown: Reading Kernel Memory from User Space”. In:27th USENIX Security Symposium. 2018, pp. 973–990.url:https: //www.usenix.org/conference/usenixsecurity18/presentation/lipp

  43. [52]

    Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors

    Yoongu Kim, Ross Daly, Jeremie Kim, et al. “Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors”. In:ACM/IEEE International Symposium on Computer Architecture (ISCA). 2014, pp. 361–372.doi:10.1145/2678373. 2665726

  44. [53]

    Guru Baran.Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption. 2025

  45. [54]

    Guru Baran.Record-breaking Ransom Payment: Dark Angels Ransomware Received$75 Mil- lion. 2024

  46. [55]

    Mohammad Khalil.Ransomware Payout Statistics 2025: Trends, Costs & Industry Insights. 2024

  47. [56]

    Place cells, grid cells, and mem- ory

    May-Britt Moser, David C Rowland, and Edvard I Moser. “Place cells, grid cells, and mem- ory”. en. In:Cold Spring Harb. Perspect. Biol.7.2 (Feb. 2015), a021808

  48. [57]

    A theory of the brain - the brain uses both distributed and localist (symbolic) rep- resentation

    Asim Roy. “A theory of the brain - the brain uses both distributed and localist (symbolic) rep- resentation”. In:The 2011 International Joint Conference on Neural Networks. 2011, pp. 215– 221.doi:10.1109/IJCNN.2011.6033224

  49. [58]

    Dan Goodin.Tampering with a car’s brakes and speed by hacking its computers: A new how- to.https://arstechnica.com/information-technology/2013/07/disabling-a-cars- brakes-and-speed-by-hacking-its-computers-a-new-how-to/. 2013. [59]Bupropion drug safety information

  50. [59]

    Functional connectome fingerprinting: identifying individuals using patterns of brain connectivity

    Emily S. Finn et al. “Functional connectome fingerprinting: identifying individuals using patterns of brain connectivity”. In:Nature Neuroscience18 (2015), pp. 1664–1671.doi:10. 1038/nn.4135

  51. [60]

    Contrastive learning for neural fingerprinting from limited neuroimag- ing data

    Nikolas Kampel et al. “Contrastive learning for neural fingerprinting from limited neuroimag- ing data”. In:Frontiers in Nuclear Medicine(2024).doi:10.3389/fnume.2024.1332747

  52. [61]

    Brain–Computer Interface for EEG-Based Authentication: Advance- ments and Practical Implications

    Lamia Alahaideb et al. “Brain–Computer Interface for EEG-Based Authentication: Advance- ments and Practical Implications”. In:Sensors(2025).doi:10.3390/s25164946

  53. [62]

    EEG-based identification system using deep neural networks with frequency features

    Yasaman Akbarnia and Mohammad Reza Daliri. “EEG-based identification system using deep neural networks with frequency features”. In:Heliyon(2024).doi:10.1016/j.heliyon. 2024.e25999

  54. [63]

    Brainprint: Assessing the uniqueness, collectability, and perma- nence of a novel method for ERP biometrics

    Blair C. Armstrong et al. “Brainprint: Assessing the uniqueness, collectability, and perma- nence of a novel method for ERP biometrics”. In:Neurocomputing166 (2015), pp. 59–67. doi:10.1016/j.neucom.2015.04.025

  55. [64]

    ResNet1D-based personal identification with multi-session sur- face electromyography for electronic health record integration

    Raghavendra Ganiga et al. “ResNet1D-based personal identification with multi-session sur- face electromyography for electronic health record integration”. In:Sensors24.10 (2024), p. 3140.doi:10.3390/s24103140

  56. [65]

    Multi-day dataset of forearm and wrist electromyogram for hand gesture recognition and biometrics

    Ashirbad Pradhan, Jiayuan He, and Ning Jiang. “Multi-day dataset of forearm and wrist electromyogram for hand gesture recognition and biometrics”. In:Scientific Data(2022). doi:10.1038/s41597-022-01836-y

  57. [66]

    Person-identifying brainprints are stably embedded in EEG mind- prints

    Yao-Yuan Yang et al. “Person-identifying brainprints are stably embedded in EEG mind- prints”. In:Scientific Reports(2022).doi:10.1038/s41598-022-21384-0. 19

  58. [67]

    Brain structure-function coupling provides signatures for task de- coding and individual fingerprinting

    Alessandra Griffa et al. “Brain structure-function coupling provides signatures for task de- coding and individual fingerprinting”. In:NeuroImage(2022).doi:10.1016/j.neuroimage. 2022.118970

  59. [68]

    Beyond neural data: Cognitive biometrics and mental privacy

    Patrick Magee, Marcello Ienca, and Nita Farahany. “Beyond neural data: Cognitive biometrics and mental privacy”. In:Neuron112.18 (2024), pp. 3017–3028.doi:10.1016/j.neuron. 2024.09.004

  60. [69]

    Quantitative EEG fingerprints: Spatiotemporal stabil- ity in interhemispheric and interannual coherence

    Sultan Tarlacı and A¸ celya Hıdımo˘ glu. “Quantitative EEG fingerprints: Spatiotemporal stabil- ity in interhemispheric and interannual coherence”. In:International Journal of Psychophys- iology207 (2025), p. 112478.doi:10.1016/j.ijpsycho.2024.112478

  61. [70]

    Joint disentangled representation and domain adversarial training for EEG-based cross-session biometric recognition in single-task protocols

    Honggang Liu et al. “Joint disentangled representation and domain adversarial training for EEG-based cross-session biometric recognition in single-task protocols”. In:Cognitive Neu- rodynamics(2025).doi:10.1007/s11571-024-10214-w

  62. [71]

    Adversarial deep learning in EEG biometrics

    Ozan ¨Ozdenizci et al. “Adversarial deep learning in EEG biometrics”. In:IEEE Signal Pro- cessing Letters26 (2019), pp. 710–714.doi:10.1109/LSP.2019.2906826

  63. [72]

    A deep descriptor for cross-tasking EEG-based recognition

    Mariana R. F. Mota et al. “A deep descriptor for cross-tasking EEG-based recognition”. In: PeerJ Computer Science7 (2021), e549.doi:10.7717/peerj-cs.549

  64. [73]

    Decision making and reward in frontal cor- tex: Complementary evidence from neurophysiological and neuropsychological studies

    Steven W. Kennerley and Mark E. Walton. “Decision making and reward in frontal cor- tex: Complementary evidence from neurophysiological and neuropsychological studies.” In: Behavioral Neuroscience125.3 (2011), pp. 297–317.doi:10.1037/a0023575

  65. [74]

    Adaptive neural coding: from biological to behavioral decision-making

    Kenway Louie, Paul W Glimcher, and Ryan Webb. “Adaptive neural coding: from biological to behavioral decision-making”. In:Current Opinion in Behavioral Sciences5 (Oct. 2015), pp. 91–99.doi:10.1016/j.cobeha.2015.08.008

  66. [75]

    Deficits in decision-making induced by parietal cortex inactivation are compensated at two timescales

    Danique Jeurissen et al. “Deficits in decision-making induced by parietal cortex inactivation are compensated at two timescales”. In:Neuron110.12 (2022), 1924–1931.e5.doi:10.1016/ j.neuron.2022.03.022

  67. [76]

    A brain-wide map of neural activity during complex behaviour

    International Brain Laboratory et al. “A brain-wide map of neural activity during complex behaviour”. In:Nature645.8079 (2025), pp. 177–191.doi:10.1038/s41586-025-09235-0

  68. [77]

    Rate and noise in human amygdala drive increased exploration in aversive learning

    Tamar Reitich-Stolero et al. “Rate and noise in human amygdala drive increased exploration in aversive learning”. In:Nature646.8086 (Aug. 2025), pp. 883–892.doi:10.1038/s41586- 025-09466-1

  69. [78]

    Acoustic Cryptanalysis

    Daniel Genkin, Adi Shamir, and Eran Tromer. “Acoustic Cryptanalysis”. In:Journal of Cryptology30.2 (2017), pp. 392–443.doi:10.1007/s00145-015-9224-2

  70. [79]

    Get Your Hands Off My Laptop: Physical Side-Channel Key-Extraction Attacks on PCs

    Daniel Genkin, Itamar Pipman, and Eran Tromer. “Get Your Hands Off My Laptop: Physical Side-Channel Key-Extraction Attacks on PCs”. In:Cryptographic Hardware and Embedded Systems (CHES 2014). 2014.doi:10.1007/978-3-662-44709-3_14

  71. [80]

    Bluetooth: With Low Energy Comes Low Security

    Mike Ryan. “Bluetooth: With Low Energy Comes Low Security”. In:7th USENIX Workshop on Offensive Technologies (WOOT 13). 2013.url:https://www.usenix.org/conference/ woot13/workshop-program/presentation/ryan

  72. [81]

    Tracking Anonymized Bluetooth De- vices

    Johannes K. Becker, David Li, and David Starobinski. “Tracking Anonymized Bluetooth De- vices”. In:Proceedings on Privacy Enhancing Technologies (PoPETs)2019.3 (2019), pp. 50– 65.url:https://petsymposium.org/popets/2019/popets-2019-0036.php

  73. [82]

    The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation of Bluetooth BR/EDR

    Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen. “The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation of Bluetooth BR/EDR”. In:28th USENIX Security Symposium (USENIX Security 19). 2019, pp. 1047–1061.url:https : //www.usenix.org/conferenc...

  74. [83]

    BIAS: Bluetooth Imper- sonation AttackS

    Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen. “BIAS: Bluetooth Imper- sonation AttackS”. In:2020 IEEE Symposium on Security and Privacy (SP). 2020.doi: 10.1109/SP40000.2020.00093

  75. [84]

    BLURtooth: Exploiting Cross-Transport Key Derivation in Blue- tooth Classic and Bluetooth Low Energy

    Daniele Antonioli et al. “BLURtooth: Exploiting Cross-Transport Key Derivation in Blue- tooth Classic and Bluetooth Low Energy”. In:Proceedings of the 2022 ACM on Asia Con- ference on Computer and Communications Security ASIACCS. 2022, pp. 196–207.doi:10. 1145/3488932.3523258

  76. [85]

    On the Feasibility of Side-Channel Attacks with Brain-Computer In- terfaces

    Ivan Martinovic et al. “On the Feasibility of Side-Channel Attacks with Brain-Computer In- terfaces”. In:21st USENIX Security Symposium (USENIX Security 12). 2012.url:https:// www.usenix.org/conference/usenixsecurity12/technical- sessions/presentation/ martinovic

  77. [86]

    Security in brain-computer interfaces: State-of-the-art, oppor- tunities, and future challenges

    Sergio L´ opez Bernal et al. “Security in brain-computer interfaces: State-of-the-art, oppor- tunities, and future challenges”. In:ACM Computing Surveys54.1 (2021), pp. 1–35.doi: 10.1145/3427376

  78. [87]

    Electroencephalography EEG and Event-Related Potentials (ERPs) with Human Participants

    Gregory A. Light et al. “Electroencephalography EEG and Event-Related Potentials (ERPs) with Human Participants”. In:Current Protocols in Neuroscience52.1 (2010).doi:10.1002/ 0471142301.ns0625s52. 20

  79. [88]

    Brain Waves for Automatic Biometric-Based User Recognition

    Patrizio Campisi and Daria La Rocca. “Brain Waves for Automatic Biometric-Based User Recognition”. In:IEEE Transactions on Information Forensics and Security9.5 (2014), pp. 782–800.doi:10.1109/TIFS.2014.2308640

  80. [89]

    Brain Oscillations and the Importance of Waveform Shape

    Scott R. Cole and Bradley Voytek. “Brain Oscillations and the Importance of Waveform Shape”. In:Trends in Cognitive Sciences21 (2017), pp. 137–149.doi:10.1016/j.tics. 2016.12.008

  81. [90]

    Schomer and Fernando H

    Donald L. Schomer and Fernando H. Lopes da Silva, eds.Niedermeyer’s Electroencephalog- raphy: Basic Principles, Clinical Applications, and Related Fields. 6th. Lippincott Williams & Wilkins, 2011.isbn: 978-0-78-178942-4.url:https : / / www . wolterskluwer . com / en / solution...

  82. [91]

    Human Brain Distinctiveness Based on EEG Spectral Coherence Connectivity

    Daria La Rocca et al. “Human Brain Distinctiveness Based on EEG Spectral Coherence Connectivity”. In:IEEE Transactions on Biomedical Engineering61.9 (2014), pp. 2406– 2412.doi:10.1109/TBME.2014.2317881

  83. [92]

    Broken Hearted: How to Attack ECG Biometrics

    Simon Eberz et al. “Broken Hearted: How to Attack ECG Biometrics”. In:Network and Distributed System Security Symposium (NDSS 2017). 2017.url:https : / / www . ndss - symposium.org/ndss2017/ndss- 2017- programme/broken- hearted- how- attack- ecg- biometrics/

  84. [93]

    2025.url:https://owasp.org/Top10/2025/

    OWASP Foundation.OWASP Top 10: 2025. 2025.url:https://owasp.org/Top10/2025/

  85. [94]

    Man- diant Threat Intelligence Report, Google Cloud,https://cloud.google.com/blog/topics/ threat-intelligence/unc5537-snowflake-data-theft-extortion

    Mandiant.UNC5537 targets Snowflake customer instances for data theft and extortion. Man- diant Threat Intelligence Report, Google Cloud,https://cloud.google.com/blog/topics/ threat-intelligence/unc5537-snowflake-data-theft-extortion. 2024

  86. [95]

    CSA Industry Insights Blog,https://cloudsecurityalliance.org/blog/2025/05/07/unpacking- the- 2024- snowflake-data-breach

    Cloud Security Alliance.Unpacking the 2024 Snowflake data breach. CSA Industry Insights Blog,https://cloudsecurityalliance.org/blog/2025/05/07/unpacking- the- 2024- snowflake-data-breach. 2025

  87. [96]

    Cyber Safety Review Board.Review of the Summer 2023 Microsoft Exchange Online Intru- sion. Tech. rep. U.S. Department of Homeland Security, 2024.url:https://www.cisa.gov/ resources-tools/resources/CSRB-Review-Summer-2023-MEO-Intrusion

  88. [97]

    A systematic analysis of the Capital One data breach: Critical lessons learned

    Shaharyar Khan et al. “A systematic analysis of the Capital One data breach: Critical lessons learned”. In:ACM Transactions on Privacy and Security(2022).doi:10.1145/3546068

  89. [98]

    National Security Agency and Cybersecurity and Infrastructure Security Agency.Kubernetes Hardening Guide, Version 1.2. Tech. rep. U/OO/168286-21. U.S. National Security Agency, 2022.url:https : / / media . defense . gov / 2022 / Aug / 29 / 2003066362/ - 1/ - 1 / 0 / CTR _ KUBE...

  90. [99]

    National Institute of Standards and Technology.Platform Firmware Resiliency Guidelines. Tech. rep. SP 800-193. NIST, 2018.url:https://csrc.nist.gov/publications/detail/ sp/800-193/final

  91. [100]

    org / www - project - kubernetes-top-ten/

    OWASP Foundation.OWASP Kubernetes Top 10.https : / / owasp . org / www - project - kubernetes-top-ten/. 2023

  92. [101]

    2024.url:https://nvd.nist.gov/vuln/detail/CVE-2024-21626

    MITRE.CVE-2024-21626: runC process.cwd container breakout vulnerability (Leaky Vessels). 2024.url:https://nvd.nist.gov/vuln/detail/CVE-2024-21626

  93. [102]

    Wiz Threat Intelligence Blog,https://www.wiz.io/blog/nvidia-ai-vulnerability- cve-2025-23266-nvidiascape

    Wiz Research.NVIDIAScape (CVE-2025-23266): Container escape in NVIDIA Container Toolkit. Wiz Threat Intelligence Blog,https://www.wiz.io/blog/nvidia-ai-vulnerability- cve-2025-23266-nvidiascape. 2025

  94. [103]

    CISA Advisory,https://www.cisa.gov/news- events/alerts/ 2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem

    Cybersecurity and Infrastructure Security Agency.Widespread supply chain compromise im- pacting npm ecosystem. CISA Advisory,https://www.cisa.gov/news- events/alerts/ 2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem. 2025

  95. [104]

    Datadog Security Labs Research,https://securitylabs.datadoghq.com/articles/shai- hulud-2.0-npm-worm/

    Datadog Security Labs.The Shai-Hulud 2.0 npm worm: Analysis and what you need to know. Datadog Security Labs Research,https://securitylabs.datadoghq.com/articles/shai- hulud-2.0-npm-worm/. 2025

  96. [105]

    CISA Advisory,https://www

    Cybersecurity and Infrastructure Security Agency.Reported supply chain compromise af- fecting XZ Utils data compression library, CVE-2024-3094. CISA Advisory,https://www. cisa . gov / news - events / alerts / 2024 / 03 / 29 / reported - supply - chain - compromise - affecting-...

  97. [106]

    Zscaler Threat- Labz Research,https : / / www

    Zscaler ThreatLabz.Anthropic Claude Code leak: A supply chain risk analysis. Zscaler Threat- Labz Research,https : / / www . zscaler . com / blogs / security - research / anthropic - claude-code-leak. 2026

  98. [107]

    Cloud Security Alliance,https://cloudsecurityalliance.org/artifacts/top-threats- to-cloud-computing-2024

    Cloud Security Alliance Top Threats Working Group.Top Threats to Cloud Computing 2024. Cloud Security Alliance,https://cloudsecurityalliance.org/artifacts/top-threats- to-cloud-computing-2024. 2024

  99. [108]

    A survey on security challenges in cloud computing: Issues, threats, and solutions

    Hamed Tabrizchi and Marjan Kuchaki Rafsanjani. “A survey on security challenges in cloud computing: Issues, threats, and solutions”. In:The Journal of Supercomputing76 (2020), pp. 9493–9532.doi:10.1007/s11227-020-03213-1. 21

  100. [109]

    EEG-Based Brain-Computer Interfaces (BCIs): A Survey of Recent Studies on Signal Sensing Technologies and Computational Intelligence Approaches and Their Applications

    Xiaotong Gu et al. “EEG-Based Brain-Computer Interfaces (BCIs): A Survey of Recent Studies on Signal Sensing Technologies and Computational Intelligence Approaches and Their Applications”. In:IEEE/ACM Transactions on Computational Biology and Bioinformatics 18.5 (2021), pp. 16...

  101. [110]

    A Review of Classification Algorithms for EEG-Based Brain-Computer Interfaces: A 10-Year Update

    Fabien Lotte et al. “A Review of Classification Algorithms for EEG-Based Brain-Computer Interfaces: A 10-Year Update”. In:Journal of Neural Engineering15.3 (2018).doi:10.1088/ 1741-2552/aab2f2

  102. [111]

    Brain-Computer Interfaces in Medicine

    Jerry J. Shih, Dean J. Krusienski, and Jonathan R. Wolpaw. “Brain-Computer Interfaces in Medicine”. In:Mayo Clinic Proceedings87.3 (2012), pp. 268–279.doi:10.1016/j.mayocp. 2011.12.008

  103. [112]

    Transfer Learning in Brain-Computer Interfaces

    Vinay Jayaram et al. “Transfer Learning in Brain-Computer Interfaces”. In:IEEE Compu- tational Intelligence Magazine11.1 (2016), pp. 20–31.doi:10.1109/MCI.2015.2501545

  104. [113]

    Active Poisoning: Efficient Backdoor Attacks on Transfer Learning-Based Brain-Computer Interfaces

    Xue Jiang et al. “Active Poisoning: Efficient Backdoor Attacks on Transfer Learning-Based Brain-Computer Interfaces”. In:Science China Information Sciences66 (2023), p. 182402. doi:10.1007/s11432-022-3548-2

  105. [114]

    Poisoning Attacks against Support Vec- tor Machines

    Battista Biggio, Blaine Nelson, and Pavel Laskov. “Poisoning Attacks against Support Vec- tor Machines”. In:Proceedings of the 29th International Conference on Machine Learning (ICML). 2012.url:https://arxiv.org/abs/1206.6389

  106. [115]

    Alexandra Souly et al.Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples. 2025. arXiv:2510.07192.url:https://arxiv.org/abs/2510.07192

  107. [116]

    Adversarial concept drift detection under poisoning attacks for robust data stream mining

    Lukasz Korycki and Bartosz Krawczyk. “Adversarial concept drift detection under poisoning attacks for robust data stream mining”. In:Machine Learning(2022).doi:10.1007/s10994- 022-06177-w

  108. [117]

    Towards adaptive classification for BCI

    Pradeep Shenoy et al. “Towards adaptive classification for BCI”. In:Journal of Neural En- gineering3.1 (2006).doi:10.1088/1741-2560/3/1/R02

  109. [118]

    How To Backdoor Federated Learning

    Eugene Bagdasaryan et al. “How To Backdoor Federated Learning”. In:Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics (AISTATS). Vol. 108. 2020, pp. 2938–2948.url:https://proceedings.mlr.press/v108/bagdasaryan20a.html

  110. [119]

    Poisoning Web-Scale Training Datasets is Practical

    Nicholas Carlini et al. “Poisoning Web-Scale Training Datasets is Practical”. In:2024 IEEE Symposium on Security and Privacy (SP). 2024.doi:10.1109/SP54263.2024.00179

  111. [120]

    An Introduction to Adversarially Robust Deep Learning

    Jonathan Peck, Bart Goossens, and Yvan Saeys. “An Introduction to Adversarially Robust Deep Learning”. In:IEEE Transactions on Pattern Analysis and Machine Intelligence46.4 (2024), pp. 2071–2090.doi:10.1109/TPAMI.2023.3331087

  112. [121]

    New Perspectives on Adversarially Robust Machine Learning Systems

    Chawin Sitawarin. “New Perspectives on Adversarially Robust Machine Learning Systems”. PhD thesis. EECS Department, University of California, Berkeley, Mar. 2024.url:http: //www2.eecs.berkeley.edu/Pubs/TechRpts/2024/EECS-2024-10.html

  113. [122]

    Wenjie Ruan, Xinping Yi, and Xiaowei Huang.Adversarial Robustness of Deep Learning: Theory, Algorithms, and Applications. 2021. arXiv:2108.10451 [cs.LG].url:https:// arxiv.org/abs/2108.10451

  114. [123]

    Adversarial Filtering Based Evasion and Backdoor Attacks to EEG-Based Brain-Computer Interfaces

    Lubin Meng et al. “Adversarial Filtering Based Evasion and Backdoor Attacks to EEG-Based Brain-Computer Interfaces”. In:Information Fusion107 (2024), p. 102316.doi:10.1016/j. inffus.2024.102316

  115. [124]

    Large Brain Model for Learning Generic Representations with Tremendous EEG Data in BCI

    Wei-Bang Jiang, Li-Ming Zhao, and Bao-Liang Lu. “Large Brain Model for Learning Generic Representations with Tremendous EEG Data in BCI”. In:International Conference on Learn- ing Representations (ICLR). 2024.url:https://openreview.net/forum?id=QzTpTRVtrP

  116. [125]

    Explaining and Harnessing Adversarial Examples

    Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. “Explaining and Harnessing Adversarial Examples”. In:International Conference on Learning Representations (ICLR). 2015.url:https://arxiv.org/abs/1412.6572

  117. [126]

    Tiny Noise, Big Mistakes: Adversarial Perturbations Induce Errors in Brain-Computer Interface Spellers

    Xiao Zhang et al. “Tiny Noise, Big Mistakes: Adversarial Perturbations Induce Errors in Brain-Computer Interface Spellers”. In:National Science Review8.4 (2021).doi:10.1093/ nsr/nwaa233

  118. [127]

    Universal Adversarial Perturbations

    Seyed-Mohsen Moosavi-Dezfooli et al. “Universal Adversarial Perturbations”. In:Proceed- ings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 2017, pp. 1765–1773.doi:10.1109/CVPR.2017.17

  119. [128]

    Universal Adversarial Perturbations for CNN Classifiers in EEG-Based BCIs

    Zihan Liu et al. “Universal Adversarial Perturbations for CNN Classifiers in EEG-Based BCIs”. In:Journal of Neural Engineering18.4 (2021).doi:10.1088/1741-2552/ac0f4c

  120. [129]

    Model Inversion Attacks that Ex- ploit Confidence Information and Basic Countermeasures

    Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. “Model Inversion Attacks that Ex- ploit Confidence Information and Basic Countermeasures”. In:Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS). 2015, pp. 1322– 1333.doi:10.1145/28101...

  121. [130]

    Membership Inference Attacks Against Machine Learning Models

    Reza Shokri et al. “Membership Inference Attacks Against Machine Learning Models”. In: 2017 IEEE Symposium on Security and Privacy (SP). 2017, pp. 3–18.doi:10.1109/SP. 2017.41. 22

  122. [131]

    Stealing Machine Learning Models via Prediction APIs

    Florian Tram` er et al. “Stealing Machine Learning Models via Prediction APIs”. In:25th USENIX Security Symposium (USENIX Security 16). 2016, pp. 601–618.url:https : / / www.usenix.org/conference/usenixsecurity16/technical- sessions/presentation/ tramer

  123. [132]

    Formal Verification of a Post-quantum Signal Protocol with Tamarin

    Hugo Beguinet et al. “Formal Verification of a Post-quantum Signal Protocol with Tamarin”. In:Verification and Evaluation of Computer and Communication Systems. Springer Nature Switzerland, Dec. 2023, pp. 105–121.isbn: 9783031497377.doi:10 . 1007 / 978 - 3 - 031 - 49737-7_8.ur...

  124. [133]

    Analyzing security protocols with secrecy types and logic programs

    Mart´ ın Abadi and Bruno Blanchet. “Analyzing security protocols with secrecy types and logic programs”. In:Journal of the ACM52.1 (2005).doi:10.1145/1044731.1044735

  125. [134]

    Security protocols: from linear to classical logic by abstract interpretation

    Bruno Blanchet. “Security protocols: from linear to classical logic by abstract interpretation”. In:Information Processing Letters95.5 (2005).doi:10.1016/j.ipl.2005.05.011

  126. [135]

    Verification of cryptographic protocols: tagging en- forces termination

    Bruno Blanchet and Andreas Podelski. “Verification of cryptographic protocols: tagging en- forces termination”. In:Theoretical Computer Science333.1-2 (2005).doi:10.1016/j.tcs. 2004.10.018

  127. [136]

    Computer-assisted verification of a protocol for certified email

    Mart´ ın Abadi and Bruno Blanchet. “Computer-assisted verification of a protocol for certified email”. In:Science of Computer Programming58.1-2 (2005).doi:10.1016/j.scico.2005. 02.002

  128. [137]

    The Applied Pi Calculus: Mobile Values, New Names, and Secure Communication

    Mart´ ın Abadi, Bruno Blanchet, and C´ edric Fournet. “The Applied Pi Calculus: Mobile Values, New Names, and Secure Communication”. In:Journal of the ACM65.1 (2017).doi:10.1145/ 3127586

  129. [138]

    Just fast keying in the pi calculus

    Mart´ ın Abadi, Bruno Blanchet, and C´ edric Fournet. “Just fast keying in the pi calculus”. In: ACM Transactions on Information and System Security10.3 (2007).doi:10.1145/1266977. 1266978

  130. [139]

    Automatic Verification of Security Protocols in the Symbolic Model: The Verifier ProVerif

    Bruno Blanchet. “Automatic Verification of Security Protocols in the Symbolic Model: The Verifier ProVerif”. In:Foundations of Security Analysis and Design VII. Springer Interna- tional Publishing, 2014, pp. 54–87.isbn: 9783319100821.doi:10.1007/978-3-319-10082- 1_3

  131. [140]

    ACCESS: Assurance Case Centric Engineering of Safety–critical Systems

    Ran Wei et al. “ACCESS: Assurance Case Centric Engineering of Safety–critical Systems”. In:Journal of Systems and Software213 (2024), p. 112034.issn: 0164-1212.doi:https : / / doi . org / 10 . 1016 / j . jss . 2024 . 112034.url:https : / / www . sciencedirect . com / science/a...

  132. [141]

    Foun- dations and Trends (R) in Theoretical Computer Science

    Cynthia Dwork and Aaron Roth.The algorithmic foundations of differential privacy. Foun- dations and Trends (R) in Theoretical Computer Science. Hanover, MD: now, Aug. 2014

  133. [142]

    Exposed! A Survey of Attacks on Private Data

    Cynthia Dwork et al. “Exposed! A Survey of Attacks on Private Data”. In:Annual Review of Statistics and Its Application4.1 (Mar. 2017), pp. 61–84.issn: 2326-831X.doi:10.1146/ annurev - statistics - 060116 - 054123.url:http : / / dx . doi . org / 10 . 1146 / annurev - statistic...

  134. [143]

    Van- derbilt Journal of Entertainment and Technology Law, 2020

    Alexandra Wood et al.Differential Privacy: A Primer for a Non-Technical Audience. Van- derbilt Journal of Entertainment and Technology Law, 2020

  135. [144]

    Deep Learning with Differential Privacy

    Martin Abadi et al. “Deep Learning with Differential Privacy”. In:Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. CCS ’16. Vienna, Austria: Association for Computing Machinery, 2016, pp. 308–318.isbn: 9781450341394. doi:10.1145/2976749.29...

  136. [145]

    Differentially Private Model Publishing for Deep Learning

    Lei Yu et al. “Differentially Private Model Publishing for Deep Learning”. In:2019 IEEE Symposium on Security and Privacy (SP). 2019, pp. 332–349.doi:10.1109/SP.2019.00019

  137. [146]

    Differentially-Private Deep Learning from an optimization Perspective

    Liyao Xiang, Jingbo Yang, and Baochun Li. “Differentially-Private Deep Learning from an optimization Perspective”. In:IEEE INFOCOM 2019 - IEEE Conference on Computer Com- munications. 2019, pp. 559–567.doi:10.1109/INFOCOM.2019.8737494

  138. [147]

    An Adaptive and Fast Convergent Approach to Differentially Private Deep Learning

    Zhiying Xu et al. “An Adaptive and Fast Convergent Approach to Differentially Private Deep Learning”. In:IEEE INFOCOM 2020 - IEEE Conference on Computer Communications. 2020, pp. 1867–1876.doi:10.1109/INFOCOM41043.2020.9155359

  139. [148]

    Accurate Differentially Private Deep Learning on the Edge

    Rui Han et al. “Accurate Differentially Private Deep Learning on the Edge”. In:IEEE Trans- actions on Parallel and Distributed Systems32.9 (2021), pp. 2231–2247.doi:10.1109/TPDS. 2021.3064345

  140. [149]

    Geyer, Tassilo Klein, and Moin Nabi.Differentially Private Federated Learning: A Client Level Perspective

    Robin C. Geyer, Tassilo Klein, and Moin Nabi.Differentially Private Federated Learning: A Client Level Perspective. 2017.doi:10.48550/ARXIV.1712.07557.url:https://arxiv. org/abs/1712.07557. 23

  141. [150]

    The Skellam Mechanism for Differentially Private Federated Learning

    Naman Agarwal, Peter Kairouz, and Ziyu Liu. “The Skellam Mechanism for Differentially Private Federated Learning”. In:Advances in Neural Information Processing Systems. Vol. 34. Curran Associates, Inc., 2021, pp. 5052–5064.url:https://proceedings.neurips.cc/ paper_files/paper/...

  142. [151]

    Differentially Private Federated Learning on Heterogeneous Data

    Maxence Noble, Aur´ elien Bellet, and Aymeric Dieuleveut. “Differentially Private Federated Learning on Heterogeneous Data”. In:Proceedings of The 25th International Conference on Artificial Intelligence and Statistics. Vol. 151. Proceedings of Machine Learning Research. PMLR,...

  143. [152]

    Differentially private knowledge transfer for federated learning

    Tao Qi et al. “Differentially private knowledge transfer for federated learning”. In:Nature Communications14.1 (June 2023).issn: 2041-1723.doi:10.1038/s41467- 023- 38794- x. url:http://dx.doi.org/10.1038/s41467-023-38794-x

  144. [153]

    Jie Fu et al.Differentially Private Federated Learning: A Systematic Review. 2025. arXiv: 2405.08299 [cs.CR].url:https://arxiv.org/abs/2405.08299

  145. [154]

    arXiv preprint arXiv:2507.14339

    Abhishek Bhattacharjee, Jack Pilkington, and Nita Farahany.Fiduciary AI for the Future of Brain-Technology Interactions. arXiv preprint arXiv:2507.14339. 2025.url:https://arxiv. org/abs/2507.14339

  146. [155]

    Federal Trade Commission.Data Brokers: A Call for Transparency and Accountability. Tech. rep. Federal Trade Commission, 2014.url:https://www.ftc.gov/reports/data-brokers- call-transparency-accountability-report-federal-trade-commission-may-2014

  147. [156]

    Information Fiduciaries and the First Amendment

    Jack M. Balkin. “Information Fiduciaries and the First Amendment”. In:UC Davis Law Review49.4 (2016), pp. 1183–1234.url:https://lawreview.law.ucdavis.edu/archives/ 49/4/information-fiduciaries-and-first-amendment

  148. [157]

    ACTION-EHR: Patient-Centric Blockchain-Based Electronic Health Record Data Management for Cancer Care

    Alevtina Dubovitskaya et al. “ACTION-EHR: Patient-Centric Blockchain-Based Electronic Health Record Data Management for Cancer Care”. In:Journal of Medical Internet Research 22.8 (2020), e13598.doi:10.2196/13598

  149. [158]

    A survey on blockchain deployment for biometric systems

    Surbhi Sharma and Rudresh Dwivedi. “A survey on blockchain deployment for biometric systems”. In:IET Blockchain4 (2024), pp. 124–151.doi:10.1049/blc2.12063

  150. [159]

    Formal verification of the PQXDH Post-Quantum key agree- ment protocol for end-to-end secure messaging

    Karthikeyan Bhargavan et al. “Formal verification of the PQXDH Post-Quantum key agree- ment protocol for end-to-end secure messaging”. In:33rd USENIX Security Symposium. Philadelphia, PA: USENIX Association, Aug. 2024, pp. 469–486.isbn: 978-1-939133-44- 1.url:https : / / www ....

  151. [160]

    Cryptology ePrint Archive, Paper 2025/078

    Yevgeniy Dodis et al.Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal Protocol. Cryptology ePrint Archive, Paper 2025/078. 2025.url:https://eprint.iacr.org/2025/ 078

  152. [161]

    How to Compare Bandwidth Constrained Two-Party Secure Mes- saging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol

    Benedikt Auerbach and. “How to Compare Bandwidth Constrained Two-Party Secure Mes- saging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol”. In: 34th USENIX Security Symposium. 2025.url:https : / / www . usenix . org / conference / usenixsecurity25/pres...

  153. [162]

    2025.url: https://signal.org/blog/spqr/

    Graeme Connell and Rolfe Schmidt.Signal Protocol and Post-Quantum Ratchets. 2025.url: https://signal.org/blog/spqr/

  154. [163]

    Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its Implementations

    Jianliang Wu et al. “Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its Implementations”. In:33rd USENIX Security Symposium (USENIX Security 24). 2024, pp. 4499–4516.url:https : / / www . usenix . org / conference / usenixsecurity24 / presentation/w...

  155. [164]

    A survey on Bluetooth Low Energy security and privacy

    Matthias C¨ asar et al. “A survey on Bluetooth Low Energy security and privacy”. In:Computer Networks205 (2022).doi:10.1016/j.comnet.2021.108712

  156. [165]

    Indescribably Blue: Bluetooth Low Energy Threat Landscape

    Christopher Skallak and Silvie Schmidt. “Indescribably Blue: Bluetooth Low Energy Threat Landscape”. In:Proceedings of the 9th International Conference on Internet of Things, Big Data and Security (IoTBDS 2024). 2024.url:https : / / www . scitepress . org / Papers / 2024/12737...

  157. [166]

    Detection of electromagnetic interference attacks on sensor systems

    Youqian Zhang and Kasper B. Rasmussen. “Detection of electromagnetic interference attacks on sensor systems”. In:2020 IEEE Symposium on Security and Privacy (SP). 2020, pp. 203– 216.doi:10.1109/SP40000.2020.00001

  158. [167]

    Taxonomy and Challenges of Out-of-Band Signal Injection Attacks and Defenses

    Ilias Giechaskiel and Kasper B. Rasmussen. “Taxonomy and Challenges of Out-of-Band Signal Injection Attacks and Defenses”. In:IEEE Communications Surveys & Tutorials22.1 (2020), pp. 645–670.doi:10.1109/COMST.2019.2952858

  159. [168]

    Securing the exocortex: A twenty-first century cybernetics challenge

    Tamara Bonaci et al. “Securing the exocortex: A twenty-first century cybernetics challenge”. In:2014 IEEE Conference on Norbert Wiener in the 21st Century (21CW). 2014.doi:10. 1109/NORBERT.2014.6893912

  160. [169]

    App stores for the brain: Privacy and security in brain-computer interfaces

    Tamara Bonaci, Ryan Calo, and Howard Jay Chizeck. “App stores for the brain: Privacy and security in brain-computer interfaces”. In:IEEE Technology and Society Magazine34.2 (2015), pp. 32–39.doi:10.1109/MTS.2015.2425551. 24

  161. [170]

    arXiv preprint arXiv:2201.07711

    Zahra Tarkhani et al.Enhancing the security & privacy of wearable brain-computer interfaces. arXiv preprint arXiv:2201.07711. 2022.doi:10.48550/arXiv.2201.07711

  162. [171]

    Alignment-based adversarial training (ABAT) for improving the robustness and accuracy of EEG-based BCIs

    Xiaoqing Chen, Ziwei Wang, and Dongrui Wu. “Alignment-based adversarial training (ABAT) for improving the robustness and accuracy of EEG-based BCIs”. In:IEEE Transactions on Neural Systems and Rehabilitation Engineering32 (2024), pp. 1703–1714.doi:10 . 1109 / TNSRE.2024.3391936

  163. [172]

    Adversarial attacks and defenses in physiological computing: A systematic review

    Dongrui Wu et al. “Adversarial attacks and defenses in physiological computing: A systematic review”. In:National Science Open(2023).doi:10.1360/nso/20220023

  164. [173]

    Wiley, Oct

    Niels Ferguson, Bruce Schneier, and Tadayoshi Kohno.Cryptography Engineering: Design Principles and Practical Applications. Wiley, Oct. 2015.isbn: 9781118722367.doi:10.1002/ 9781118722367.url:http://dx.doi.org/10.1002/9781118722367. 25

Pith tools

Reviewed July 14, 2026 · model on record in the stance chip above.