Pith. sign in

REVIEW 4 major objections 4 minor 109 references

Privacy-Preserving Brain-Computer Interfaces: A Systematic Review

T0 review · 4 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read This review paper claims that brain-computer interface privacy is an underserved field and that existing EEG privacy attacks and defenses can be organized into a single framework.

desk verdict A useful but stale narrative survey of BCI privacy that overclaims 'contemporary and comprehensive' without a search methodology or post-2021 literature. read the letter →

arxiv 2412.11394 v1 pith:NP7HMW3H submitted 2024-12-16 cs.HC

classification cs.HC
keywords brain-computerinterfaceEEGprivacyprivacy-preservingmachinelearningside-channelattacksdifferentialhomomorphicencryptionsecuremulti-partycomputationsyntheticdata
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This review paper attempts to establish that privacy has been neglected in brain-computer interface research and that attacks on EEG-derived data are already demonstrated. It assembles existing evidence that EEG carries private information about identity, preferences, physical condition, and commercial models, and it sorts attacks into data-level and model-level categories. It argues that generic privacy-preserving machine learning techniques, namely cryptography, perturbation, and ML-aided systems, can be adapted to BCIs, and it lists open challenges. If correct, the paper gives researchers a structured map of BCI privacy threats and defenses plus a research agenda. The novel contribution is the synthesis, not new attacks or defenses.

What carries the argument

The organizing device is a two-axis taxonomy: private information types (personal account, personal preferences, physical state, commercial models) crossed with privacy threats (data-level identification and inference attacks, model-level extraction and inversion attacks) and protection strategies (cryptography, perturbation, ML-aided systems). This taxonomy carries the review; each surveyed paper is placed within it to show which gaps are filled and which remain open.

What would settle it

A reader could search publication databases for peer-reviewed BCI privacy papers from 2022 through 2024; if several established attacks or defenses are absent from the review's tables, the contemporary and comprehensive claim would need qualification. Finding a previously published systematic review that the paper overlooks would directly test the gap claim.

Watch

Extended reading notes

Core claim

The paper's central claim is that BCI privacy is a real and underserved problem, and that the scattered literature on attacks and defenses can be organized into a coherent framework. It reports that EEG signals let attackers infer PINs, passwords, identity, personality traits, political preferences, health conditions, and smoking status; that model-level attacks are plausible but not yet demonstrated in BCIs; and that existing defenses fall into cryptography, perturbation, and ML-aided systems, with only a handful of BCI-specific implementations. The paper also identifies cross-subject variation, utility-privacy trade-offs, computation cost, and the lack of benchmarking as open challenges.

Load-bearing premise

The review's load-bearing premise is that the hand-assembled set of references is representative and complete enough to support the claim of being contemporary and comprehensive, yet no search strategy or inclusion criteria are documented and the bibliography largely stops before 2022.

Editorial extensions

If this is right

  • BCI system designers should treat EEG as sensitive biometric data subject to legal protections, not merely as a control signal.
  • Source-free transfer learning and federated learning become the leading candidates for privacy-preserving BCI calibration because they avoid sharing raw EEG.
  • GAN-based synthetic EEG, such as seizure-signal generation, could allow data sharing without patient re-identification risk.
  • Encryption-based methods remain too costly for real-time BCI use, so reducing their computation and communication overhead becomes a priority.
  • A quantitative index of privacy-protection strength is needed before different BCI defenses can be benchmarked against each other.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper's map suggests model extraction and model inversion attacks will soon be demonstrated against BCI models; a natural extension is to run established model-stealing attacks on a published EEG classifier and measure information leakage.
  • The taxonomy implies that dimensionality-reduction anonymization of EEG may be fragile, and a testable extension would be to check whether differentially private variants preserve task utility while blocking re-identification.
  • Because many demonstrated attacks rely on event-related potentials, a plausible untested defense is to use adversarial perturbation to mask ERP responses without degrading the BCI's primary task.
  • The review's sparse coverage after 2021 leaves the field open to a rapid update that could test whether the proposed taxonomy still accommodates newer attacks and defenses.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The manuscript is a review of privacy threats and defenses in brain-computer interface (BCI) systems. It proposes a taxonomy of private information in BCIs (personal accounts, personal preferences, physical state, commercial models), distinguishes data-level from model-level privacy threats, surveys protection approaches organized into cryptography, perturbation, and machine-learning-aided systems, and lists four research challenges and future directions. The paper claims to be the first contemporary and comprehensive systematic review of privacy-preserving BCIs, while explicitly stating that it does not introduce new attacks, defenses, or experimental data.

Significance. If the claims were substantiated, the paper would provide a useful structured entry point into BCI privacy: the threat taxonomy and the data-level/model-level distinction are clear, the summaries of individual works are generally faithful to the cited abstracts, and the discussion of source-free transfer learning, federated learning, utility-privacy tradeoffs, and evaluation gaps is valuable. Its contribution is synthetic rather than technical. The main significance hinges on the asserted 'contemporary and comprehensive' and 'systematic review' status, which is exactly what the manuscript does not currently establish; if that status is removed or properly supported, the review would still be a useful survey but with a weaker scope claim.

major comments (4)
  1. [Title, Abstract, Section VI] The central claim that this is the first 'contemporary and comprehensive' review, and the 'Systematic Review' designation, is not supported by the manuscript's method. There is no methodology section, no search strategy, no database list, no date range, no inclusion/exclusion criteria, and no PRISMA-style study selection flow. Sections III-D and IV-D summarize a chosen set of BCI papers without explaining how those papers were identified or why they represent the literature. Because the contribution is explicitly framed as filling a gap through comprehensiveness, the absence of a reproducible selection protocol is a load-bearing limitation, not a stylistic one.
  2. [Tables I-II and Reference List] The 'contemporary' part of the claim is contradicted by the evidence base. Table I's most recent BCI privacy attack is from 2020, and Table II's most recent BCI protection works are from 2020 and 2021; several references are listed as 'in press' or 'submitted' (e.g., refs [26], [47], [50], [53], [85]), and there are no references from 2022-2024 even though the manuscript is dated December 2024. The paper either needs a genuinely updated search covering the intervening years or a qualified scope statement that it reviews work through approximately 2021.
  3. [Sections III-C and IV-D] The paper makes strong negative statements, e.g., 'To our knowledge, no privacy attacks targeting the BCI models have been reported yet' and 'ML aided systems have not been studied in privacy-preserving BCIs yet.' In a systematic review, such absence claims require exhaustive coverage of the literature; without a documented search, they are not established. Please either support these claims with a searchable protocol or soften them to reflect that they are based on the authors' manually assembled reference set.
  4. [Section IV] A large fraction of Section IV (e.g., homomorphic encryption, secure multi-party computation, secure processors, differential privacy, data reconstruction, and ML aided systems) describes generic privacy-preserving machine learning methods and cites general works with little or no BCI-specific evidence. This breadth is useful background for an unsystematic survey, but it weakens the 'comprehensiveness' claim for privacy-preserving BCIs because the reader cannot tell which described solutions have actually been evaluated on BCI data. The authors should either connect each category to concrete BCI applications or explicitly identify these parts as transferable background.
minor comments (4)
  1. [Reference list] Several references are listed with incomplete publication status (e.g., refs [26], [47], [50], [53], [85], [109]); please update them to final versions or clearly mark them as preprints.
  2. [Throughout] There are typographical and copy-editing errors, including 'Icena' for 'Ienca' (Section I), 'CrytoNets' for 'CryptoNets' (Section IV-A), 'Cao and Jian' for 'Cao and Jain' (Section III-B2), and 'a directly communication pathway' in the first sentence of Section I.
  3. [Author block] The author block contains spacing artifacts such as 'Y u Sun' and 'Fei-Y ue Wang'; these should be normalized.
  4. [Figures] The text references Figures 1-4, but the supplied manuscript does not show them; please ensure all figures are present in the compiled version and that their labels match the text.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the review's taxonomy and survey content are assembled from cited prior work; the self-citations are evidentiary, not definitional, and no derivation reduces to its own inputs.

full rationale

This is a systematic review with no mathematical derivations, fitted parameters, or predictive claims generated from the paper's own model. The central claim is that no contemporary comprehensive review on privacy-preserving BCIs exists and that this paper fills the gap by describing threats and protections. That claim rests on literature coverage, not on a derivation, and the paper's own equations or models play no role in producing its conclusions. The paper does cite several works by its own authors, including [31], [47], [53]-[57], [74]-[75], and [104], as evidence for adversarial vulnerability, transfer learning practice, and SMC-based linear regression in BCIs; these are prior published or submitted results used as literature evidence, not outputs of the present review, so they are normal self-citations rather than load-bearing circularity. The absence of a documented search strategy, inclusion criteria, and 2022-2024 coverage is a genuine verifiability and evidence-quality concern that weakens the 'contemporary and comprehensive' claim, but it is not a circularity pattern: no statement in the paper is equivalent by construction to its input, and no fitted parameter or derived quantity is renamed as a prediction. Therefore the appropriate circularity score is 0.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

No equations, fitting, or new entities are introduced. The review's contribution rests on accepting that cited empirical findings transfer to the BCI domain, so the ledger records those domain assumptions rather than free parameters.

assumptions (4)
  • domain assumption EEG and BCI signals contain private information that is inferable by attackers.
    The entire threat model in Sections II and III-D rests on cited experiments (e.g., Martinovic et al., Neupane et al.), not on new measurements.
  • domain assumption A typical BCI system involves separate parties exchanging data and models, creating transmission risks.
    Section III-A's flowchart assumes this architecture; no survey of real deployments in the paper verifies how common it is.
  • domain assumption Generic privacy-preserving ML techniques (HE, SMC, DP, GANs) transfer to EEG and BCI workloads.
    Section IV applies these methods to BCIs by analogy and cites isolated EEG examples, but does not establish general transferability.
  • domain assumption The selected corpus of references is representative of the whole privacy-preserving BCI literature.
    The 'comprehensive' claim in the abstract depends on this; no systematic search is reported to justify it.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Privacy-Preserving Brain-Computer Interfaces: A Systematic Review." pith.science (2026). https://pith.science/paper/NP7HMW3H

@misc{pith2026241211394,
  author       = {Pith},
  title        = {Pith review of: Privacy-Preserving Brain-Computer Interfaces: A Systematic Review},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/NP7HMW3H}},
  note         = {Machine review of arXiv:2412.11394}
}
read the original abstract

A brain-computer interface (BCI) establishes a direct communication pathway between the human brain and a computer. It has been widely used in medical diagnosis, rehabilitation, education, entertainment, etc. Most research so far focuses on making BCIs more accurate and reliable, but much less attention has been paid to their privacy. Developing a commercial BCI system usually requires close collaborations among multiple organizations, e.g., hospitals, universities, and/or companies. Input data in BCIs, e.g., electroencephalogram (EEG), contain rich privacy information, and the developed machine learning model is usually proprietary. Data and model transmission among different parties may incur significant privacy threats, and hence privacy protection in BCIs must be considered. Unfortunately, there does not exist any contemporary and comprehensive review on privacy-preserving BCIs. This paper fills this gap, by describing potential privacy threats and protection strategies in BCIs. It also points out several challenges and future research directions in developing privacy-preserving BCIs.

Figures

Figures reproduced from arXiv: 2412.11394 by the authors.

Figure 1
Figure 1. Private information in BCIs. A. Personal Account Personal account information may include the user’s iden￾tity, personal identification number (PIN), bank account, and so on. Therefore, EEG signals can be used for biometric identification [15], [16]. Martinovic et al. [17] showed that EEG signals collected by cheap consumer-grade BCI devices can be used to infer private information of users, such as credit cards, PI… view at source ↗
Figure 3
Figure 3. Privacy threat types. B. Data-Level Privacy Threats Data-level privacy threats aim at the information contained in published data, such as raw data, identity, statistical prop￾erties, etc. The input part is usually separated from the computation part in practical BCIs. When raw or processed data have been transmitted to the computation part, the input part may no longer be able to control their usage and storage, wh… view at source ↗
Figure 2
Figure 2. Flowchart of a typical BCI system, with correspondin [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: Privacy protection approaches. approaches may not be able to deal with encrypted data. To overcome this limitation, Bost et al. [65] designed efficient protocols for many core operations on encrypted data in many classification algorithms, such as comparison, argmax an…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

109 extracted references · 73 canonical work pages

  1. [26]

    Brain-computer interface for generating personally attractive images,

    M. Spap´ e, K. Davis, L. Kangassalo, N. Ravaja, Z. Sovij¨ arvi-Spap´ e, and T. Ruotsalo, “Brain-computer interface for generating personally attractive images,” IEEE Trans. on Affective Computing , 2021, in press

  2. [47]

    Transfer learning for EEG-ba sed brain- computer interfaces: A review of progress made since 2016,

    D. Wu, Y . Xu, and B.-L. Lu, “Transfer learning for EEG-ba sed brain- computer interfaces: A review of progress made since 2016,” IEEE Trans. on Cognitive and Developmental Systems , 2020, in press

  3. [50]

    Demysti fying membership inference attacks in machine learning as a servi ce,

    S. Truex, L. Liu, M. E. Gursoy, L. Y u, and W. Wei, “Demysti fying membership inference attacks in machine learning as a servi ce,” IEEE Trans. on Services Computing , 2019, in press

  4. [53]

    Adversarial attacks and defenses in physiological c omputing: A systematic review,

    D. Wu, W. Fang, Y . Zhang, L. Y ang, H. Luo, L. Ding, X. Xu, an d X. Y u, “Adversarial attacks and defenses in physiological c omputing: A systematic review,” IEEE Computational Intelligence Magazine , 2021, submitted

  5. [85]

    EpilepsyGAN: Synthetic epileptic brain a ctivities with privacy preservation,

    D. Pascual, A. Amirshahi, A. Aminifar, D. Atienza, P . Ry vlin, and R. Wattenhofer, “EpilepsyGAN: Synthetic epileptic brain a ctivities with privacy preservation,” IEEE Trans. on Biomedical Engineering , 2020, in press

  6. [1]

    EEG-based brain-computer interfaces (BCIs): A surve y of recent studies on signal sensing technologies and computational i ntelligence approaches and their applications,

    X. Gu, Z. Cao, A. Jolfaei, P . Xu, D. Wu, T.-P . Jung, and C.-T . Lin, “EEG-based brain-computer interfaces (BCIs): A surve y of recent studies on signal sensing technologies and computational i ntelligence approaches and their applications,” IEEE/ACM Trans. on Computa- tional Biology and Bioinformatics , vol. 18, no. 5, pp. 1645–1666, 2021. 10

  7. [2]

    Epileptic seizure detection in EEG signals using a unified temporal-sp ectral squeeze-and-excitation network,

    Y . Li, Y . Liu, W.-G. Cui, Y .-Z. Guo, H. Huang, and Z.-Y . Hu,“Epileptic seizure detection in EEG signals using a unified temporal-sp ectral squeeze-and-excitation network,” IEEE Trans. on Neural Systems and Rehabilitation Engineering , vol. 28, no. 4, pp. 782–794, 2020

  8. [3]

    Co chlear implants: System design, integration, and evaluation,

    F. Zeng, S. Rebscher, W. Harrison, X. Sun, and H. Feng, “Co chlear implants: System design, integration, and evaluation,” IEEE Reviews in Biomedical Engineering , vol. 1, pp. 115–142, 2008

Show all 109 references
  1. [4]

    Natural brain-information inter faces: Rec- ommending information by relevance inferred from human bra in sig- nals,

    M. J. Eugster, T. Ruotsalo, M. M. Spap´ e, O. Barral, N. Rav aja, G. Jacucci, and S. Kaski, “Natural brain-information inter faces: Rec- ommending information by relevance inferred from human bra in sig- nals,” Scientific Reports , vol. 6, p. 38580, 2016

  2. [5]

    Intelligent assistive technolog y for Alzheimers disease and other dementias: a systematic revie w,

    M. Ienca, J. Fabrice, B. Elger, M. Caon, A. S. Pappagallo, R. W. Kressing, and T. Wangmo, “Intelligent assistive technolog y for Alzheimers disease and other dementias: a systematic revie w,” Journal of Alzheimer’s Disease , vol. 56, no. 4, pp. 1301–1340, 2017

  3. [6]

    Brain hemor- rhage: When brainwaves leak sensitive medical conditions a nd personal information,

    A. Neupane, K. Satvat, M. Hosseini, and N. Saxena, “Brain hemor- rhage: When brainwaves leak sensitive medical conditions a nd personal information,” in Proc. 17th Int’l Conf. on Privacy, Security and Trust , Fredericton, Canada, Aug. 2019, pp. 1–10

  4. [7]

    Generative adversarial networks conditioned by brain sig nals,

    S. Palazzo, C. Spampinato, I. Kavasidis, D. Giordano, an d M. Shah, “Generative adversarial networks conditioned by brain sig nals,” in Proc. IEEE Int’l’ Conf. on Computer Vision , V enice, Italy, Oct. 2017, pp. 3430–3438

  5. [8]

    Using EEG-based BCI d evices to subliminally probe for private information,

    M. Frank, T. Hwu, S. Jain, R. T. Knight, I. Martinovic, P . M ittal, D. Perito, I. Sluganovic, and D. Song, “Using EEG-based BCI d evices to subliminally probe for private information,” in Proc. W orkshop on Privacy in the Electronic Society , Dallas, TX, Oct. 2017, pp. 133–136

  6. [9]

    On the po tential of data extraction by detecting unaware facial recognition with brain- computer interfaces,

    C. Bellman, M. V argas Martin, and S. MacDonald, “On the po tential of data extraction by detecting unaware facial recognition with brain- computer interfaces,” in Proc. IEEE Int’l Conf. on Cognitive Comput- ing, San Francisco, CA, Jul. 2018, pp. 99–105

  7. [10]

    Mind your privacy: Privacy leakage through BCI applications using machine lea rning methods,

    O. Landau, A. Cohen, S. Gordon, and N. Nissim, “Mind your privacy: Privacy leakage through BCI applications using machine lea rning methods,” Knowledge-Based Systems , vol. 198, p. 105932, 2020

  8. [11]

    Brain-computer interface applications: Security and privacy challenges,

    Q. Li, D. Ding, and M. Conti, “Brain-computer interface applications: Security and privacy challenges,” in Proc. IEEE Conf. on Communica- tions and Network Security , Florence, Italy, Sep. 2015, pp. 663–666

  9. [12]

    Brain compute r interface (BCI) applications: Privacy threats and countermeasures,

    H. Takabi, A. Bhalotiya, and M. Alohaly, “Brain compute r interface (BCI) applications: Privacy threats and countermeasures, ” in Proc. IEEE 2nd Int’l Conf. on Collaboration and Internet Computin g, Pittsburgh, PA, Nov. 2016, pp. 102–111

  10. [13]

    Four ethical piorities for neurotechnologies and AI,

    R. Y uste, S. Goering, G. Bi, J. M. Carmena, A. Carter, J. J . Fins, P . Friesen, J. Gallant, J. E. Huggins, J. Illes et al., “Four ethical piorities for neurotechnologies and AI,” Nature, vol. 551, no. 7679, pp. 159– 163, 2017

  11. [14]

    Brain leaks a nd consumer neurotechnology,

    M. Ienca, P . Haselager, and E. J. Emanuel, “Brain leaks a nd consumer neurotechnology,” Nature Biotechnology, vol. 36, no. 9, pp. 805–810, 2018

  12. [15]

    EEG biometric identification: A thorough explorat ion of the time-frequency domain,

    M. DelPozo-Banos, C. M. Travieso, C. T. Weidemann, and J . B. Alonso, “EEG biometric identification: A thorough explorat ion of the time-frequency domain,” Journal of Neural Engineering , vol. 12, no. 5, p. 056019, 2015

  13. [16]

    Brainprint: Identifying unique features of neu ral activity with machine learning,

    M. Ruiz-Blondet, N. Khlaifian, B. Armstrong, Z. Jin, K. K urtz, and S. Laszlo, “Brainprint: Identifying unique features of neu ral activity with machine learning,” in Proc. Annual Meeting of the Cognitive Science Society , Quebec City, Canada, Jul. 2014

  14. [17]

    On the feasibility of side-channel attacks with brain-comput er interfaces,

    I. Martinovic, D. Davies, M. Frank, D. Perito, T. Ros, an d D. Song, “On the feasibility of side-channel attacks with brain-comput er interfaces,” in Proc. 21st USENIX Security Symposium , Bellevue, W A, Aug. 2012, pp. 143–158

  15. [18]

    PEEP: Passivel y eaves- dropping private input via brainwave signals,

    A. Neupane, M. L. Rahman, and N. Saxena, “PEEP: Passivel y eaves- dropping private input via brainwave signals,” in Proc. Financial Cryptography and Data Security , Sliema, Malta, Apr. 2017, pp. 227– 246

  16. [19]

    Individual identificati on based on resting-state EEG,

    G. Choi, S. Choi, and H. Hwang, “Individual identificati on based on resting-state EEG,” in Proc. 6th Int’l Conf. on Brain-Computer Interface, Gangwon, Korea, Jan. 2018, pp. 1–4

  17. [20]

    Neura l correlates of automatic beliefs about gender and race,

    K. M. Knutson, L. Mah, C. F. Manly, and J. Grafman, “Neura l correlates of automatic beliefs about gender and race,” Human Brain Mapping, vol. 28, no. 10, pp. 915–930, 2007

  18. [21]

    Neu- ropolitics: EEG spectral maps related to a political vote ba sed on the first impression of the candidate’s face,

    G. V ecchiato, J. Toppi, F. Cincotti, L. Astolfi, F. De Vic o Fallani, F. Aloise, D. Mattia, S. Bocale, F. V ernucci, and F. Babiloni , “Neu- ropolitics: EEG spectral maps related to a political vote ba sed on the first impression of the candidate’s face,” in Proc. Annual Int’l ...

  19. [22]

    Pol itical neuroscience: The beginning of a beautiful friendship,

    J. T. Jost, H. H. Nam, D. M. Amodio, and J. J. V . Bavel, “Pol itical neuroscience: The beginning of a beautiful friendship,” Political Psy- chology, vol. 35, no. S1, pp. 3–42, 2014

  20. [23]

    Neuropolitics: Twenty years later,

    D. Schreiber, “Neuropolitics: Twenty years later,” Politics and the Life Sciences, vol. 36, no. 2, pp. 114–131, 2017

  21. [24]

    Early EEG responses to pre-elec toral survey items reflect political attitudes and predict voting behavior,

    G. Galli, D. Angelucci, S. Bode, C. D. Giorgi, L. D. Sio, A . Paparo, G. D. Lorenzo, and V . Betti, “Early EEG responses to pre-elec toral survey items reflect political attitudes and predict voting behavior,” Scientific Reports , vol. 11, p. 18692, 2021

  22. [25]

    The brain functional networks associated t o human and animal suffering differ among omnivores, vegetarians a nd vegans,

    M. Filippi, G. Riccitelli, A. Falini, F. Di Salle, P . Vui lleumier, G. Comi, and M. A. Rocca, “The brain functional networks associated t o human and animal suffering differ among omnivores, vegetarians a nd vegans,” PLoS ONE , vol. 5, no. 5, pp. 1–9, 2010

  23. [27]

    Collab orative filtering with preferences inferred from brain signals,

    K. M. Davis III, M. M. A. Spap´ e, and T. Ruotsalo, “Collab orative filtering with preferences inferred from brain signals,” in Proc. of the W eb Conf., Virtual Event, Apr. 2021, pp. 602–611

  24. [28]

    Evidence fo r erp biomark- ers of eating disorder symptoms in women,

    K. Groves, S. Kennett, and H. Gillmeister, “Evidence fo r erp biomark- ers of eating disorder symptoms in women,” Biological Psychology , vol. 123, pp. 205–219, 2017

  25. [29]

    Event-related p otential (ERP) measures of error processing as biomarkers of externa lizing dis- orders: A narrative review,

    M. C. Lutz, R. Kok, and I. H. A. Franken, “Event-related p otential (ERP) measures of error processing as biomarkers of externa lizing dis- orders: A narrative review,” International Journal of Psychophysiology, vol. 166, pp. 151–159, 2021

  26. [30]

    Smokers and ex-somkers have shared differences in the neural substr ates for potential monetary gains and losses,

    L. J. Nestor, E. McCabe, J. Jones, L. Clancy, and H. Garav an, “Smokers and ex-somkers have shared differences in the neural substr ates for potential monetary gains and losses,” Addiction Biology, vol. 23, no. 1, pp. 369–378, 2018

  27. [31]

    On the vulnerability of CNN classifie rs in EEG-based BCIs,

    X. Zhang and D. Wu, “On the vulnerability of CNN classifie rs in EEG-based BCIs,” IEEE Trans. on Neural Systems and Rehabilitation Engineering, vol. 27, no. 5, pp. 814–825, 2019

  28. [32]

    Stealing machine learning models via prediction APIs,

    F. Tram` er, F. Zhang, A. Juels, M. K. Reiter, and T. Riste npart, “Stealing machine learning models via prediction APIs,” in Proc. 25th USENIX Security Symposium , Austin, TX, Aug. 2016, pp. 601–618

  29. [33]

    Copycat CNN: Stealing knowledge by pe rsuading confession with random non-labeled data,

    J. R. Correia-Silva, R. F. Berriel, C. Badue, A. F. de Sou za, and T. Oliveira-Santos, “Copycat CNN: Stealing knowledge by pe rsuading confession with random non-labeled data,” in Proc. Int’l Joint Conf. on Neural Networks , Rio, Brazil, Jul. 2018, pp. 1–8

  30. [34]

    Practical black-box attacks against machine lea rning,

    N. Papernot, P . McDaniel, I. Goodfellow, S. Jha, Z. B. Ce lik, and A. Swami, “Practical black-box attacks against machine lea rning,” in Proc. ACM on Asia Conf. on Computer and Communications Secur ity, Abu Dhabi, United Arab Emirates, Apr. 2017, pp. 506–519

  31. [35]

    Privacy-preserving mach ine learning: Threats and solutions,

    M. Al-Rubaie and J. M. Chang, “Privacy-preserving mach ine learning: Threats and solutions,” IEEE Security & Privacy , vol. 17, no. 2, pp. 49–58, 2019

  32. [36]

    Can we stil l avoid automatic face detection?

    M. J. Wilber, V . Shmatikov, and S. Belongie, “Can we stil l avoid automatic face detection?” in Proc. IEEE Winter Conf. on Applications of Computer Vision , Lake Placid, NY , Mar. 2016, pp. 1–9

  33. [37]

    De-anony mization attack on geolocated data,

    S. Gambs, M. Killijian, and M. N. d. P . Cortez, “De-anony mization attack on geolocated data,” in Proc. 12th IEEE Int’l Conf. on Trust, Security and Privacy in Computing and Communications , Melbourne, Australia, Jul. 2013, pp. 789–797

  34. [38]

    Structural data de- anonymization: Theory and practice,

    S. Ji, W. Li, M. Srivatsa, and R. Beyah, “Structural data de- anonymization: Theory and practice,” IEEE/ACM Trans. on Network- ing, vol. 24, no. 6, pp. 3523–3536, 2016

  35. [39]

    Faceles s person recognition: Privacy implications in social media,

    S. J. Oh, R. Benenson, M. Fritz, and B. Schiele, “Faceles s person recognition: Privacy implications in social media,” in Proc. European Conf. on Computer Vision , Amsterdam, The Netherlands, Oct. 2016, pp. 19–35

  36. [40]

    Defeating i mage obfus- cation with deep learning,

    R. McPherson, R. Shokri, and V . Shmatikov, “Defeating i mage obfus- cation with deep learning,” arXiv preprint arXiv:1609.00408 , 2016

  37. [41]

    P3: Toward privac y-preserving photo sharing,

    M.-R. Ra, R. Govindan, and A. Ortega, “P3: Toward privac y-preserving photo sharing,” in Proc. 10th USENIX Symposium on Networked Systems Design and Implementation , Lombard, IL, Apr. 2013, pp. 515– 528

  38. [42]

    Priva cy leakage via de-anonymization and aggregation in heterogen eous social networks,

    H. Li, Q. Chen, H. Zhu, D. Ma, H. Wen, and X. S. Shen, “Priva cy leakage via de-anonymization and aggregation in heterogen eous social networks,” IEEE Trans. on Dependable and Secure Computing , vol. 17, no. 2, pp. 350–362, 2020

  39. [43]

    Fingerprint reconstruction: Fr om minutiae to phase,

    J. Feng and A. K. Jain, “Fingerprint reconstruction: Fr om minutiae to phase,” IEEE Trans. on Pattern Analysis and Machine Intelligence , vol. 33, no. 2, pp. 209–223, 2011

  40. [44]

    Learning fingerprint reconstruct ion: From minutiae to image,

    K. Cao and A. K. Jain, “Learning fingerprint reconstruct ion: From minutiae to image,” IEEE Trans. on Information F orensics and Security, vol. 10, no. 1, pp. 104–117, 2015. 11

  41. [45]

    Reconstruction attacks a gainst mobile- based continuous authentication systems in the cloud,

    M. Al-Rubaie and J. M. Chang, “Reconstruction attacks a gainst mobile- based continuous authentication systems in the cloud,” IEEE Trans. on Information F orensics and Security , vol. 11, no. 12, pp. 2648–2663, 2016

  42. [46]

    A review of classification algorith ms for EEG-based brain-computer interfaces: A 10-year update,

    F. Lotte, L. Bougrain, A. Cichocki, M. Clerc, M. Congedo , A. Rako- tomamonjy, and F. Yger, “A review of classification algorith ms for EEG-based brain-computer interfaces: A 10-year update,” Journal of Neural Engineering , vol. 15, 2018

  43. [48]

    Do we really need to access t he source data? Source hypothesis transfer for unsupervised domain a daptation,

    J. Liang, D. Hu, and J. Feng, “Do we really need to access t he source data? Source hypothesis transfer for unsupervised domain a daptation,” in Proc. 37th Int’l Conf. on Machine Learning , Vienna, Austria, Jul. 2020

  44. [49]

    Machine lear ning models that remember too much,

    C. Song, T. Ristenpart, and V . Shmatikov, “Machine lear ning models that remember too much,” in Proc. ACM SIGSAC Conf. on Computer and Communications Security , Dallas, TX, Oct. 2017, pp. 587–601

  45. [51]

    Memb ership inference attacks against machine learning models,

    R. Shokri, M. Stronati, C. Song, and V . Shmatikov, “Memb ership inference attacks against machine learning models,” in Proc. IEEE Symposium on Security and Privacy , San Jose, CA, May 2017, pp. 3–18

  46. [52]

    Model invers ion attacks that exploit confidence information and basic countermeasures,

    M. Fredrikson, S. Jha, and T. Ristenpart, “Model invers ion attacks that exploit confidence information and basic countermeasures, ” in Proc. 22nd ACM SIGSAC Conf. on Computer and Communications Securi ty, Denver, CO, Oct. 2015, pp. 1322–1333

  47. [54]

    Active learning for black -box adver- sarial attacks in EEG-based brain-computer interfaces,

    X. Jiang, X. Zhang, and D. Wu, “Active learning for black -box adver- sarial attacks in EEG-based brain-computer interfaces,” i n Proc. IEEE Symposium Series on Computational Intelligence , Xiamen, China, Dec. 2019

  48. [55]

    Tiny noise, big mistakes: Adversarial per turbations induce errors in brain-computer interface spellers,

    X. Zhang, D. Wu, L. Ding, H. Luo, C.-T. Lin, T.-P . Jung, an d R. Chavarriaga, “Tiny noise, big mistakes: Adversarial per turbations induce errors in brain-computer interface spellers,” National Science Review, vol. 8, no. 4, 2021

  49. [56]

    White-box tar get attack for EEG-based BCI regression problems,

    L. Meng, C.-T. Lin, T.-P . Jung, and D. Wu, “White-box tar get attack for EEG-based BCI regression problems,” in Proc. Int’l Conf. on Neural Information Processing, Sydney, Australia, Dec. 2019

  50. [57]

    Universal adversarial perturbations for CNN classifiers in EEG-based BCIs,

    Z. Liu, L. Meng, X. Zhang, W. Fang, and D. Wu, “Universal adversarial perturbations for CNN classifiers in EEG-based BCIs,” Journal of Neural Engineering , vol. 18, no. 4, p. 0460a4, 2021. [Online]. Available: https://arxiv.org/abs/1912.01171

  51. [58]

    Task- independent EEG identification via low-rank matrix decompo sition,

    X. Kong, W. Kong, Q. Fan, Q. Zhao, and A. Cichocki, “Task- independent EEG identification via low-rank matrix decompo sition,” in IEEE Int’l Conf. on Bioinformatics and Biomedicine , Madrid, Spain, Dec. 2018, pp. 412–419

  52. [59]

    BCI competition 2008 – Graz data set A,

    C. Brunner, R. Leeb, G. M¨ uller-Putz, A. Schl¨ ogl, and G . Pfurtscheller, “BCI competition 2008 – Graz data set A,” Institute for Knowledge Discovery (Laboratory of Brain-Computer Interfaces), Gra z University of Technology, vol. 16, pp. 1–6, 2008

  53. [60]

    Attention and p3 00-based BCI performance in people with amyotrophic lateral sclerosis,

    A. Riccio, L. Simione, F. Schettini, A. Pizzimenti, M. I nghilleri, M. O. Belardinelli, D. Mattia, and F. Cincotti, “Attention and p3 00-based BCI performance in people with amyotrophic lateral sclerosis, ” Frontiers in Human Neuroscience, vol. 7, no. 1, p. 732, 2013

  54. [61]

    Investigating critical freq uency bands and channels for EEG-based emotion recognition with deep ne ural networks,

    W.-L. Zheng and B.-L. Lu, “Investigating critical freq uency bands and channels for EEG-based emotion recognition with deep ne ural networks,” IEEE Trans. on Autonomous Mental Development , vol. 7, no. 3, pp. 162–175, 2015

  55. [62]

    Do EEG-biometric templates thre aten user privacy?

    Y . H¨ oller and A. Uhl, “Do EEG-biometric templates thre aten user privacy?” in Proc. 6th ACM W orkshop on Information Hiding and Multimedia Security , Innsbruck, Austria, Jun. 2018, pp. 31–42

  56. [63]

    Efficient and privacy-preserving medical research suppor t platform against COVID-19: A blockchain-based approach,

    K. Y u, J. Huang, L. Tan, G. Srivastava, X. Shang, and P . Ch atterjee, “Efficient and privacy-preserving medical research suppor t platform against COVID-19: A blockchain-based approach,” IEEE Consumer Electronics Magazine, vol. 10, no. 2, pp. 111–120, 2020

  57. [64]

    N-Sanitization: A semantic privacy-preserving framework for unstructured medical datasets,

    C. Iwendi, S. A. Moqurrab, A. Anjum, S. Khan, S. Mohan, an d G. Sri- vastava, “N-Sanitization: A semantic privacy-preserving framework for unstructured medical datasets,” Computer Communications , vol. 161, no. 2020, pp. 160–171, 2020

  58. [65]

    Machine le arning classification over encrypted data,

    R. Bost, R. A. Popa, S. Tu, and S. Goldwasser, “Machine le arning classification over encrypted data,” in Proc. Network and Distributed System Security Symposium , San Diego, CA, Feb. 2015

  59. [66]

    CryptoNets: Applying neural networks to encr ypted data with high throughput and accuracy,

    N. Dowlin, R. Gilad-Bachrach, K. Laine, K. Lauter, M. Na ehrig, and J. Wernsing, “CryptoNets: Applying neural networks to encr ypted data with high throughput and accuracy,” in Proc. 33rd Int’l Conf. on Int’l Conf. on Machine Learning , New Y ork, NY , Jun. 2016, pp. 201–210

  60. [67]

    Privacy preserving extreme learnin g machine using additively homomorphic encryption,

    S. Kuri, T. Hayashi, T. Omori, S. Ozawa, Y . Aono, L. T. Pho ng, L. Wang, and S. Moriai, “Privacy preserving extreme learnin g machine using additively homomorphic encryption,” in Proc. IEEE Symposium Series on Computational Intelligence , Honolulu, HI, Nov. 2017, pp. 1–8

  61. [68]

    Private mac hine learning classification based on fully homomorphic encrypt ion,

    X. Sun, P . Zhang, J. K. Liu, J. Y u, and W. Xie, “Private mac hine learning classification based on fully homomorphic encrypt ion,” IEEE Trans. on Emerging Topics in Computing , vol. 8, no. 2, pp. 352–364, 2020

  62. [69]

    How to generate and exchange secrets,

    A. C. Y ao, “How to generate and exchange secrets,” in Proc. 27th Annual Symposium on F oundations of Computer Science , Toronto, Canada, Oct. 1986

  63. [70]

    Common randomness in infor mation theory and cryptography. I. secret sharing,

    R. Ahlswede and I. Csiszar, “Common randomness in infor mation theory and cryptography. I. secret sharing,” IEEE Trans. on Information Theory, vol. 39, no. 4, pp. 1121–1132, 1993

  64. [71]

    Privacy-preserving ridge regression on hundreds of millions of records,

    V . Nikolaenko, U. Weinsberg, S. Ioannidis, M. Joye, D. B oneh, and N. Taft, “Privacy-preserving ridge regression on hundreds of millions of records,” in Proc. IEEE Symposium on Security and Privacy , Berkeley, CA, May 2013, pp. 334–348

  65. [72]

    Oblivious multi-party machine le arning on trusted processors,

    O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowo zin, K. V aswani, and M. Costa, “Oblivious multi-party machine le arning on trusted processors,” in Proc. 25th USENIX Security Symposium , Austin, TX, Aug. 2016, pp. 619–636

  66. [73]

    SGX-Big Matrix: A practical encrypted data analytic framework with trusted p rocessors,

    F. Shaon, M. Kantarcioglu, Z. Lin, and L. Khan, “SGX-Big Matrix: A practical encrypted data analytic framework with trusted p rocessors,” in Proc. ACM SIGSAC Conf. on Computer and Communications Secur ity, Dallas, TX, Oct. 2017, pp. 1211–1228

  67. [74]

    Privacy-preserving linear r egression for brain-computer interface applications,

    A. Agarwal, R. Dowsley, N. D. McKinney, D. Wu, C.-T. Lin, M. De Cock, and A. C. A. Nascimento, “Privacy-preserving linear r egression for brain-computer interface applications,” in Proc. IEEE Int’l Conf. on Big Data , Seattle, W A, Dec. 2018, pp. 5277–5278

  68. [75]

    Protecting privacy of users i n brain- computer interface applications,

    A. Agarwal, R. Dowsley, N. D. McKinney, D. Wu, C.-T. Lin, M. De Cock, and A. C. A. Nascimento, “Protecting privacy of users i n brain- computer interface applications,” IEEE Trans. on Neural Systems and Rehabilitation Engineering , vol. 27, no. 8, pp. 1546–1555, 2019

  69. [76]

    Privacy-preserving mach ine learning through data obfuscation,

    T. Zhang, Z. He, and R. B. Lee, “Privacy-preserving mach ine learning through data obfuscation,” arXiv preprint arXiv:1807.01860 , 2018

  70. [77]

    Differentially priv ate data publishing and analysis: A survey,

    T. Zhu, G. Li, W. Zhou, and P . S. Y u, “Differentially priv ate data publishing and analysis: A survey,” IEEE Trans. on Knowledge and Data Engineering , vol. 29, no. 8, pp. 1619–1638, 2017

  71. [78]

    A firm foundation for private data analysis,

    C. Dwork, “A firm foundation for private data analysis,” Communica- tions of the ACM , vol. 54, no. 1, pp. 86–95, 2011

  72. [79]

    Mechanism design via differ ential pri- vacy,

    F. McSherry and K. Talwar, “Mechanism design via differ ential pri- vacy,” in Proc. 48th Annual IEEE Symposium on F oundations of Computer Science , Providence, RI, Oct. 2007, pp. 94–103

  73. [80]

    Learning in a large function space: Privacy-preserving mechanisms f or SVM learning,

    B. I. P . Rubinstein, P . L. Bartlett, L. Huang, and N. Taft , “Learning in a large function space: Privacy-preserving mechanisms f or SVM learning,” Journal of Privacy and Confidentiality , vol. 4, no. 1, pp. 65–100, 2012

  74. [81]

    Differ entially private empirical risk minimization,

    K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differ entially private empirical risk minimization,” Journal of Machine Learning Research, vol. 12, no. 41, pp. 1069–1109, 2011

  75. [82]

    A comprehensi ve survey on local differential privacy,

    X. Xiong, S. Liu, D. Li, Z. Cai, and X. Niu, “A comprehensi ve survey on local differential privacy,” Security and Communication Networks , vol. 2020, pp. 1–29, 2020

  76. [83]

    Privacy-preser ving aggre- gation of time-series data,

    E. Shi, T. H. H. Chan, and E. G. Rieffel, “Privacy-preser ving aggre- gation of time-series data,” in Proc. Network and Distributed System Security Symposium , San Diego, CA, Feb. 2011

  77. [84]

    Protecting privacy in share d photos via adversarial examples based stealth,

    Y . Liu, W. Zhang, and N. Y u, “Protecting privacy in share d photos via adversarial examples based stealth,” Security and Communication Networks, vol. 2017, pp. 1–16, 2017

  78. [86]

    Random projection-ba sed mul- tiplicative data perturbation for privacy preserving dist ributed data mining,

    K. Liu, H. Kargupta, and J. Ryan, “Random projection-ba sed mul- tiplicative data perturbation for privacy preserving dist ributed data mining,” IEEE Trans. on Knowledge and Data Engineering , vol. 18, no. 1, pp. 92–106, 2006. 12

  79. [87]

    Non- linear dimensionality reduction for privacy-preserving d ata classifica- tion,

    K. Alotaibi, V . J. Rayward-Smith, W. Wang, and B. de la Ig lesia, “Non- linear dimensionality reduction for privacy-preserving d ata classifica- tion,” in Proc. Int’l Conf. on Privacy, Security, Risk and Trust and In t’l Conf on Social Computing , Amsterdam, Netherlands, Sep. ...

  80. [88]

    Repre- sentation transfer for differentially private drug sensit ivity prediction,

    T. Niinim¨ aki, M. A. Heikkil¨ a, A. Honkela, and S. Kaski , “Repre- sentation transfer for differentially private drug sensit ivity prediction,” Bioinformatics, vol. 35, no. 14, pp. 218–224, 2019

  81. [89]

    Deep generative image models using a Laplacian pyramid of adversarial netwo rks,

    E. L. Denton, S. Chintala, A. Szlam, and R. Fergus, “Deep generative image models using a Laplacian pyramid of adversarial netwo rks,” in Proc. Advances in Neural Information Processing Systems , Montreal, Canada, Dec. 2015, pp. 1486–1494

  82. [90]

    Gen- erative models for simulating mobility trajectories,

    V . Kulkarni, N. Tagasovska, T. V atter, and B. Garbinato , “Gen- erative models for simulating mobility trajectories,” arXiv preprint arXiv:1811.12801, 2018

  83. [91]

    Learning sensitive images using generative models,

    S. Samson Cheung, H. Wildfeuer, M. Nikkhah, X. Zhu, and W . Tan, “Learning sensitive images using generative models,” in Proc. 25th IEEE Int’l Conf. on Image Processing , Athens, Greece, Oct. 2018, pp. 4128–4132

  84. [92]

    Differen- tially private mixture of generative neural networks,

    G. Acs, L. Melis, C. Castelluccia, and E. De Cristofaro, “Differen- tially private mixture of generative neural networks,” IEEE Trans. on Knowledge and Data Engineering , vol. 31, no. 6, pp. 1109–1121, 2019

  85. [93]

    A privacy-pres erving gen- erative adversarial network method for securing EEG brain s ignals,

    E. Debie, N. Moustafa, and M. T. Whitty, “A privacy-pres erving gen- erative adversarial network method for securing EEG brain s ignals,” in Proc. Int’l Joint Conf. on Neural Networks , Glasgow, United Kingdom, Jul. 2020, pp. 1–8

  86. [94]

    Privac y risk assessment for data subject-aware threat modeling,

    L. Sion, D. V an Landuyt, K. Wuyts, and W. Joosen, “Privac y risk assessment for data subject-aware threat modeling,” in Proc. IEEE Security and Privacy W orkshops , San Francisco, CA, May 2019, pp. 64–71

  87. [95]

    Connecting pixe ls to privacy and utility: Automatic redaction of private information in images,

    T. Orekondy, M. Fritz, and B. Schiele, “Connecting pixe ls to privacy and utility: Automatic redaction of private information in images,” in Proc. IEEE/CVF Conf. on Computer Vision and Pattern Recogni tion, Salt Lake City, UT, Jun. 2018, pp. 8466–8475

  88. [96]

    When machine learning meets privacy: A survey and outlook,

    B. Liu, M. Ding, S. Shaham, W. Rahayu, F. Farokhi, and Z. L in, “When machine learning meets privacy: A survey and outlook,” arXiv preprint arXiv:2011.11819, 2020

  89. [97]

    The feasibility of dynamically granted pe rmissions: Aligning mobile privacy with user preferences,

    P . Wijesekera, A. Baokar, L. Tsai, J. Reardon, S. Egelma n, D. Wagner, and K. Beznosov, “The feasibility of dynamically granted pe rmissions: Aligning mobile privacy with user preferences,” in Proc. IEEE Sym- posium on Security and Privacy , San Jose, CA, May 2017, pp. 1077– 1093

  90. [98]

    Keeping conte xt in mind: Automating mobile app access control with user interface in spection,

    H. Fu, Z. Zheng, S. Zhu, and P . Mohapatra, “Keeping conte xt in mind: Automating mobile app access control with user interface in spection,” in Proc. IEEE Conf. on Computer Communications , Paris, France, Apr. 2019, pp. 2089–2097

  91. [99]

    A novel approach for ens uring the privacy of EEG signals using application-specific feature e xtraction and AES algorithm,

    V . Robinson and E. B. V arghese, “A novel approach for ens uring the privacy of EEG signals using application-specific feature e xtraction and AES algorithm,” in Proc. Int’l Conf. on Inventive Computation Technologies, Coimbatore, India, Aug. 2016, pp. 1–6

  92. [100]

    Privacy preserving classification of EEG data using machine learning and homomorphic encryption,

    A. B. Popescu, L. A. Taca, C. I. Nita, A. Vizitiu, R. Deme ter, C. Suciu, and L. M. Itu, “Privacy preserving classification of EEG data using machine learning and homomorphic encryption,” Applied Sciences , vol. 11, no. 16, p. 7360, 2021

  93. [101]

    Towards pr ivacy- preserving explanations in medical image analysis,

    H. Montenegro, W. Silva, and J. S. Cardoso, “Towards pr ivacy- preserving explanations in medical image analysis,” arXiv preprint arXiv:2107.09652, 2021

  94. [102]

    D. L. Schomer and F. H. L. da Silva, Niedermeyer’s Electroencephalog- raphy Basic Principles, Clinical Applications, and Relate d Fields . Oxford, UK: Oxford University Press, 2017

  95. [103]

    A survey on transfer learning,

    S. J. Pan and Q. Y ang, “A survey on transfer learning,” IEEE Trans. on Knowledge and Data Engineering , vol. 22, no. 10, pp. 1345–1359, 2010

  96. [104]

    Transfer learning for brain-computer interfaces: A Euclidean space data alignment approach,

    H. He and D. Wu, “Transfer learning for brain-computer interfaces: A Euclidean space data alignment approach,” IEEE Trans. on Biomedical Engineering, vol. 67, no. 2, pp. 399–410, 2020

  97. [105]

    Unsupervised domain adap- tation of black-box source models,

    H. Zhang, Y . Zhang, K. Jia, and L. Zhang, “Unsupervised domain adap- tation of black-box source models,” arXiv preprint arXiv:2101.02839 , 2021

  98. [106]

    A survey on federated learning: The journey from centralized to distributed on-site learning and beyond,

    S. A. Rahman, H. Tout, H. Ould-Slimane, A. Mourad, C. Ta lhi, and M. Guizani, “A survey on federated learning: The journey from centralized to distributed on-site learning and beyond,” IEEE Internet of Things Journal , 2020, i

  99. [107]

    A secure f ederated transfer learning framework,

    Y . Liu, Y . Kang, C. Xing, T. Chen, and Q. Y ang, “A secure f ederated transfer learning framework,” IEEE Intelligent Systems , vol. 35, no. 4, pp. 70–82, 2020

  100. [108]

    Feder ated transfer learning for EEG signal classification,

    C. Ju, D. Gao, R. Mane, B. Tan, Y . Liu, and C. Guan, “Feder ated transfer learning for EEG signal classification,” in Proc. 42nd Annual Int’l Conf. of the IEEE Engineering in Medicine and Biology S ociety, Montreal, Canada, Jul. 2020, pp. 3040–3045

  101. [109]

    Neurocrypt: Machine learning over encrypted distri buted neu- roimaging data,

    N. Senanayake, R. Podschwadt, D. Takabi, V . D. Calhoun , and S. M. Plis, “Neurocrypt: Machine learning over encrypted distri buted neu- roimaging data,” Neuroinformatics, 2021

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.