REVIEW 4 major objections 4 minor 109 references
Privacy-Preserving Brain-Computer Interfaces: A Systematic Review
T0 review · 4 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read This review paper claims that brain-computer interface privacy is an underserved field and that existing EEG privacy attacks and defenses can be organized into a single framework.
desk verdict A useful but stale narrative survey of BCI privacy that overclaims 'contemporary and comprehensive' without a search methodology or post-2021 literature. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The organizing device is a two-axis taxonomy: private information types (personal account, personal preferences, physical state, commercial models) crossed with privacy threats (data-level identification and inference attacks, model-level extraction and inversion attacks) and protection strategies (cryptography, perturbation, ML-aided systems). This taxonomy carries the review; each surveyed paper is placed within it to show which gaps are filled and which remain open.
What would settle it
A reader could search publication databases for peer-reviewed BCI privacy papers from 2022 through 2024; if several established attacks or defenses are absent from the review's tables, the contemporary and comprehensive claim would need qualification. Finding a previously published systematic review that the paper overlooks would directly test the gap claim.
Extended reading notes
Core claim
The paper's central claim is that BCI privacy is a real and underserved problem, and that the scattered literature on attacks and defenses can be organized into a coherent framework. It reports that EEG signals let attackers infer PINs, passwords, identity, personality traits, political preferences, health conditions, and smoking status; that model-level attacks are plausible but not yet demonstrated in BCIs; and that existing defenses fall into cryptography, perturbation, and ML-aided systems, with only a handful of BCI-specific implementations. The paper also identifies cross-subject variation, utility-privacy trade-offs, computation cost, and the lack of benchmarking as open challenges.
Load-bearing premise
The review's load-bearing premise is that the hand-assembled set of references is representative and complete enough to support the claim of being contemporary and comprehensive, yet no search strategy or inclusion criteria are documented and the bibliography largely stops before 2022.
Editorial extensions
If this is right
- BCI system designers should treat EEG as sensitive biometric data subject to legal protections, not merely as a control signal.
- Source-free transfer learning and federated learning become the leading candidates for privacy-preserving BCI calibration because they avoid sharing raw EEG.
- GAN-based synthetic EEG, such as seizure-signal generation, could allow data sharing without patient re-identification risk.
- Encryption-based methods remain too costly for real-time BCI use, so reducing their computation and communication overhead becomes a priority.
- A quantitative index of privacy-protection strength is needed before different BCI defenses can be benchmarked against each other.
Reading between the lines
- The paper's map suggests model extraction and model inversion attacks will soon be demonstrated against BCI models; a natural extension is to run established model-stealing attacks on a published EEG classifier and measure information leakage.
- The taxonomy implies that dimensionality-reduction anonymization of EEG may be fragile, and a testable extension would be to check whether differentially private variants preserve task utility while blocking re-identification.
- Because many demonstrated attacks rely on event-related potentials, a plausible untested defense is to use adversarial perturbation to mask ERP responses without degrading the BCI's primary task.
- The review's sparse coverage after 2021 leaves the field open to a rapid update that could test whether the proposed taxonomy still accommodates newer attacks and defenses.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript is a review of privacy threats and defenses in brain-computer interface (BCI) systems. It proposes a taxonomy of private information in BCIs (personal accounts, personal preferences, physical state, commercial models), distinguishes data-level from model-level privacy threats, surveys protection approaches organized into cryptography, perturbation, and machine-learning-aided systems, and lists four research challenges and future directions. The paper claims to be the first contemporary and comprehensive systematic review of privacy-preserving BCIs, while explicitly stating that it does not introduce new attacks, defenses, or experimental data.
Significance. If the claims were substantiated, the paper would provide a useful structured entry point into BCI privacy: the threat taxonomy and the data-level/model-level distinction are clear, the summaries of individual works are generally faithful to the cited abstracts, and the discussion of source-free transfer learning, federated learning, utility-privacy tradeoffs, and evaluation gaps is valuable. Its contribution is synthetic rather than technical. The main significance hinges on the asserted 'contemporary and comprehensive' and 'systematic review' status, which is exactly what the manuscript does not currently establish; if that status is removed or properly supported, the review would still be a useful survey but with a weaker scope claim.
major comments (4)
- [Title, Abstract, Section VI] The central claim that this is the first 'contemporary and comprehensive' review, and the 'Systematic Review' designation, is not supported by the manuscript's method. There is no methodology section, no search strategy, no database list, no date range, no inclusion/exclusion criteria, and no PRISMA-style study selection flow. Sections III-D and IV-D summarize a chosen set of BCI papers without explaining how those papers were identified or why they represent the literature. Because the contribution is explicitly framed as filling a gap through comprehensiveness, the absence of a reproducible selection protocol is a load-bearing limitation, not a stylistic one.
- [Tables I-II and Reference List] The 'contemporary' part of the claim is contradicted by the evidence base. Table I's most recent BCI privacy attack is from 2020, and Table II's most recent BCI protection works are from 2020 and 2021; several references are listed as 'in press' or 'submitted' (e.g., refs [26], [47], [50], [53], [85]), and there are no references from 2022-2024 even though the manuscript is dated December 2024. The paper either needs a genuinely updated search covering the intervening years or a qualified scope statement that it reviews work through approximately 2021.
- [Sections III-C and IV-D] The paper makes strong negative statements, e.g., 'To our knowledge, no privacy attacks targeting the BCI models have been reported yet' and 'ML aided systems have not been studied in privacy-preserving BCIs yet.' In a systematic review, such absence claims require exhaustive coverage of the literature; without a documented search, they are not established. Please either support these claims with a searchable protocol or soften them to reflect that they are based on the authors' manually assembled reference set.
- [Section IV] A large fraction of Section IV (e.g., homomorphic encryption, secure multi-party computation, secure processors, differential privacy, data reconstruction, and ML aided systems) describes generic privacy-preserving machine learning methods and cites general works with little or no BCI-specific evidence. This breadth is useful background for an unsystematic survey, but it weakens the 'comprehensiveness' claim for privacy-preserving BCIs because the reader cannot tell which described solutions have actually been evaluated on BCI data. The authors should either connect each category to concrete BCI applications or explicitly identify these parts as transferable background.
minor comments (4)
- [Reference list] Several references are listed with incomplete publication status (e.g., refs [26], [47], [50], [53], [85], [109]); please update them to final versions or clearly mark them as preprints.
- [Throughout] There are typographical and copy-editing errors, including 'Icena' for 'Ienca' (Section I), 'CrytoNets' for 'CryptoNets' (Section IV-A), 'Cao and Jian' for 'Cao and Jain' (Section III-B2), and 'a directly communication pathway' in the first sentence of Section I.
- [Author block] The author block contains spacing artifacts such as 'Y u Sun' and 'Fei-Y ue Wang'; these should be normalized.
- [Figures] The text references Figures 1-4, but the supplied manuscript does not show them; please ensure all figures are present in the compiled version and that their labels match the text.
Circularity Check
No significant circularity: the review's taxonomy and survey content are assembled from cited prior work; the self-citations are evidentiary, not definitional, and no derivation reduces to its own inputs.
full rationale
This is a systematic review with no mathematical derivations, fitted parameters, or predictive claims generated from the paper's own model. The central claim is that no contemporary comprehensive review on privacy-preserving BCIs exists and that this paper fills the gap by describing threats and protections. That claim rests on literature coverage, not on a derivation, and the paper's own equations or models play no role in producing its conclusions. The paper does cite several works by its own authors, including [31], [47], [53]-[57], [74]-[75], and [104], as evidence for adversarial vulnerability, transfer learning practice, and SMC-based linear regression in BCIs; these are prior published or submitted results used as literature evidence, not outputs of the present review, so they are normal self-citations rather than load-bearing circularity. The absence of a documented search strategy, inclusion criteria, and 2022-2024 coverage is a genuine verifiability and evidence-quality concern that weakens the 'contemporary and comprehensive' claim, but it is not a circularity pattern: no statement in the paper is equivalent by construction to its input, and no fitted parameter or derived quantity is renamed as a prediction. Therefore the appropriate circularity score is 0.
Assumptions & free parameters
assumptions (4)
- domain assumption EEG and BCI signals contain private information that is inferable by attackers.
- domain assumption A typical BCI system involves separate parties exchanging data and models, creating transmission risks.
- domain assumption Generic privacy-preserving ML techniques (HE, SMC, DP, GANs) transfer to EEG and BCI workloads.
- domain assumption The selected corpus of references is representative of the whole privacy-preserving BCI literature.
Cite this review
Pith. "Pith review of Privacy-Preserving Brain-Computer Interfaces: A Systematic Review." pith.science (2026). https://pith.science/paper/NP7HMW3H
@misc{pith2026241211394,
author = {Pith},
title = {Pith review of: Privacy-Preserving Brain-Computer Interfaces: A Systematic Review},
year = {2026},
howpublished = {\url{https://pith.science/paper/NP7HMW3H}},
note = {Machine review of arXiv:2412.11394}
}
read the original abstract
A brain-computer interface (BCI) establishes a direct communication pathway between the human brain and a computer. It has been widely used in medical diagnosis, rehabilitation, education, entertainment, etc. Most research so far focuses on making BCIs more accurate and reliable, but much less attention has been paid to their privacy. Developing a commercial BCI system usually requires close collaborations among multiple organizations, e.g., hospitals, universities, and/or companies. Input data in BCIs, e.g., electroencephalogram (EEG), contain rich privacy information, and the developed machine learning model is usually proprietary. Data and model transmission among different parties may incur significant privacy threats, and hence privacy protection in BCIs must be considered. Unfortunately, there does not exist any contemporary and comprehensive review on privacy-preserving BCIs. This paper fills this gap, by describing potential privacy threats and protection strategies in BCIs. It also points out several challenges and future research directions in developing privacy-preserving BCIs.
Figures
Figures from the paper (1 more)
Reference graph
Works this paper leans on
-
[26]
Brain-computer interface for generating personally attractive images,
M. Spap´ e, K. Davis, L. Kangassalo, N. Ravaja, Z. Sovij¨ arvi-Spap´ e, and T. Ruotsalo, “Brain-computer interface for generating personally attractive images,” IEEE Trans. on Affective Computing , 2021, in press
2021
-
[47]
Transfer learning for EEG-ba sed brain- computer interfaces: A review of progress made since 2016,
D. Wu, Y . Xu, and B.-L. Lu, “Transfer learning for EEG-ba sed brain- computer interfaces: A review of progress made since 2016,” IEEE Trans. on Cognitive and Developmental Systems , 2020, in press
work page 2016
-
[50]
Demysti fying membership inference attacks in machine learning as a servi ce,
S. Truex, L. Liu, M. E. Gursoy, L. Y u, and W. Wei, “Demysti fying membership inference attacks in machine learning as a servi ce,” IEEE Trans. on Services Computing , 2019, in press
work page 2019
-
[53]
Adversarial attacks and defenses in physiological c omputing: A systematic review,
D. Wu, W. Fang, Y . Zhang, L. Y ang, H. Luo, L. Ding, X. Xu, an d X. Y u, “Adversarial attacks and defenses in physiological c omputing: A systematic review,” IEEE Computational Intelligence Magazine , 2021, submitted
work page 2021
-
[85]
EpilepsyGAN: Synthetic epileptic brain a ctivities with privacy preservation,
D. Pascual, A. Amirshahi, A. Aminifar, D. Atienza, P . Ry vlin, and R. Wattenhofer, “EpilepsyGAN: Synthetic epileptic brain a ctivities with privacy preservation,” IEEE Trans. on Biomedical Engineering , 2020, in press
work page 2020
-
[1]
EEG-based brain-computer interfaces (BCIs): A surve y of recent studies on signal sensing technologies and computational i ntelligence approaches and their applications,
X. Gu, Z. Cao, A. Jolfaei, P . Xu, D. Wu, T.-P . Jung, and C.-T . Lin, “EEG-based brain-computer interfaces (BCIs): A surve y of recent studies on signal sensing technologies and computational i ntelligence approaches and their applications,” IEEE/ACM Trans. on Computa- tional Biology and Bioinformatics , vol. 18, no. 5, pp. 1645–1666, 2021. 10
2021
-
[2]
Epileptic seizure detection in EEG signals using a unified temporal-sp ectral squeeze-and-excitation network,
Y . Li, Y . Liu, W.-G. Cui, Y .-Z. Guo, H. Huang, and Z.-Y . Hu,“Epileptic seizure detection in EEG signals using a unified temporal-sp ectral squeeze-and-excitation network,” IEEE Trans. on Neural Systems and Rehabilitation Engineering , vol. 28, no. 4, pp. 782–794, 2020
2020
-
[3]
Co chlear implants: System design, integration, and evaluation,
F. Zeng, S. Rebscher, W. Harrison, X. Sun, and H. Feng, “Co chlear implants: System design, integration, and evaluation,” IEEE Reviews in Biomedical Engineering , vol. 1, pp. 115–142, 2008
2008
Show all 109 references
-
[4]
Natural brain-information inter faces: Rec- ommending information by relevance inferred from human bra in sig- nals,
M. J. Eugster, T. Ruotsalo, M. M. Spap´ e, O. Barral, N. Rav aja, G. Jacucci, and S. Kaski, “Natural brain-information inter faces: Rec- ommending information by relevance inferred from human bra in sig- nals,” Scientific Reports , vol. 6, p. 38580, 2016
2016
-
[5]
Intelligent assistive technolog y for Alzheimers disease and other dementias: a systematic revie w,
M. Ienca, J. Fabrice, B. Elger, M. Caon, A. S. Pappagallo, R. W. Kressing, and T. Wangmo, “Intelligent assistive technolog y for Alzheimers disease and other dementias: a systematic revie w,” Journal of Alzheimer’s Disease , vol. 56, no. 4, pp. 1301–1340, 2017
2017
-
[6]
Brain hemor- rhage: When brainwaves leak sensitive medical conditions a nd personal information,
A. Neupane, K. Satvat, M. Hosseini, and N. Saxena, “Brain hemor- rhage: When brainwaves leak sensitive medical conditions a nd personal information,” in Proc. 17th Int’l Conf. on Privacy, Security and Trust , Fredericton, Canada, Aug. 2019, pp. 1–10
2019
-
[7]
Generative adversarial networks conditioned by brain sig nals,
S. Palazzo, C. Spampinato, I. Kavasidis, D. Giordano, an d M. Shah, “Generative adversarial networks conditioned by brain sig nals,” in Proc. IEEE Int’l’ Conf. on Computer Vision , V enice, Italy, Oct. 2017, pp. 3430–3438
2017
-
[8]
Using EEG-based BCI d evices to subliminally probe for private information,
M. Frank, T. Hwu, S. Jain, R. T. Knight, I. Martinovic, P . M ittal, D. Perito, I. Sluganovic, and D. Song, “Using EEG-based BCI d evices to subliminally probe for private information,” in Proc. W orkshop on Privacy in the Electronic Society , Dallas, TX, Oct. 2017, pp. 133–136
2017
-
[9]
On the po tential of data extraction by detecting unaware facial recognition with brain- computer interfaces,
C. Bellman, M. V argas Martin, and S. MacDonald, “On the po tential of data extraction by detecting unaware facial recognition with brain- computer interfaces,” in Proc. IEEE Int’l Conf. on Cognitive Comput- ing, San Francisco, CA, Jul. 2018, pp. 99–105
2018
-
[10]
Mind your privacy: Privacy leakage through BCI applications using machine lea rning methods,
O. Landau, A. Cohen, S. Gordon, and N. Nissim, “Mind your privacy: Privacy leakage through BCI applications using machine lea rning methods,” Knowledge-Based Systems , vol. 198, p. 105932, 2020
2020
-
[11]
Brain-computer interface applications: Security and privacy challenges,
Q. Li, D. Ding, and M. Conti, “Brain-computer interface applications: Security and privacy challenges,” in Proc. IEEE Conf. on Communica- tions and Network Security , Florence, Italy, Sep. 2015, pp. 663–666
2015
-
[12]
Brain compute r interface (BCI) applications: Privacy threats and countermeasures,
H. Takabi, A. Bhalotiya, and M. Alohaly, “Brain compute r interface (BCI) applications: Privacy threats and countermeasures, ” in Proc. IEEE 2nd Int’l Conf. on Collaboration and Internet Computin g, Pittsburgh, PA, Nov. 2016, pp. 102–111
2016
-
[13]
Four ethical piorities for neurotechnologies and AI,
R. Y uste, S. Goering, G. Bi, J. M. Carmena, A. Carter, J. J . Fins, P . Friesen, J. Gallant, J. E. Huggins, J. Illes et al., “Four ethical piorities for neurotechnologies and AI,” Nature, vol. 551, no. 7679, pp. 159– 163, 2017
2017
-
[14]
Brain leaks a nd consumer neurotechnology,
M. Ienca, P . Haselager, and E. J. Emanuel, “Brain leaks a nd consumer neurotechnology,” Nature Biotechnology, vol. 36, no. 9, pp. 805–810, 2018
2018
-
[15]
EEG biometric identification: A thorough explorat ion of the time-frequency domain,
M. DelPozo-Banos, C. M. Travieso, C. T. Weidemann, and J . B. Alonso, “EEG biometric identification: A thorough explorat ion of the time-frequency domain,” Journal of Neural Engineering , vol. 12, no. 5, p. 056019, 2015
2015
-
[16]
Brainprint: Identifying unique features of neu ral activity with machine learning,
M. Ruiz-Blondet, N. Khlaifian, B. Armstrong, Z. Jin, K. K urtz, and S. Laszlo, “Brainprint: Identifying unique features of neu ral activity with machine learning,” in Proc. Annual Meeting of the Cognitive Science Society , Quebec City, Canada, Jul. 2014
2014
-
[17]
On the feasibility of side-channel attacks with brain-comput er interfaces,
I. Martinovic, D. Davies, M. Frank, D. Perito, T. Ros, an d D. Song, “On the feasibility of side-channel attacks with brain-comput er interfaces,” in Proc. 21st USENIX Security Symposium , Bellevue, W A, Aug. 2012, pp. 143–158
2012
-
[18]
PEEP: Passivel y eaves- dropping private input via brainwave signals,
A. Neupane, M. L. Rahman, and N. Saxena, “PEEP: Passivel y eaves- dropping private input via brainwave signals,” in Proc. Financial Cryptography and Data Security , Sliema, Malta, Apr. 2017, pp. 227– 246
2017
-
[19]
Individual identificati on based on resting-state EEG,
G. Choi, S. Choi, and H. Hwang, “Individual identificati on based on resting-state EEG,” in Proc. 6th Int’l Conf. on Brain-Computer Interface, Gangwon, Korea, Jan. 2018, pp. 1–4
2018
-
[20]
Neura l correlates of automatic beliefs about gender and race,
K. M. Knutson, L. Mah, C. F. Manly, and J. Grafman, “Neura l correlates of automatic beliefs about gender and race,” Human Brain Mapping, vol. 28, no. 10, pp. 915–930, 2007
2007
-
[21]
Neu- ropolitics: EEG spectral maps related to a political vote ba sed on the first impression of the candidate’s face,
G. V ecchiato, J. Toppi, F. Cincotti, L. Astolfi, F. De Vic o Fallani, F. Aloise, D. Mattia, S. Bocale, F. V ernucci, and F. Babiloni , “Neu- ropolitics: EEG spectral maps related to a political vote ba sed on the first impression of the candidate’s face,” in Proc. Annual Int’l ...
2010
-
[22]
Pol itical neuroscience: The beginning of a beautiful friendship,
J. T. Jost, H. H. Nam, D. M. Amodio, and J. J. V . Bavel, “Pol itical neuroscience: The beginning of a beautiful friendship,” Political Psy- chology, vol. 35, no. S1, pp. 3–42, 2014
2014
-
[23]
Neuropolitics: Twenty years later,
D. Schreiber, “Neuropolitics: Twenty years later,” Politics and the Life Sciences, vol. 36, no. 2, pp. 114–131, 2017
2017
-
[24]
Early EEG responses to pre-elec toral survey items reflect political attitudes and predict voting behavior,
G. Galli, D. Angelucci, S. Bode, C. D. Giorgi, L. D. Sio, A . Paparo, G. D. Lorenzo, and V . Betti, “Early EEG responses to pre-elec toral survey items reflect political attitudes and predict voting behavior,” Scientific Reports , vol. 11, p. 18692, 2021
2021
-
[25]
The brain functional networks associated t o human and animal suffering differ among omnivores, vegetarians a nd vegans,
M. Filippi, G. Riccitelli, A. Falini, F. Di Salle, P . Vui lleumier, G. Comi, and M. A. Rocca, “The brain functional networks associated t o human and animal suffering differ among omnivores, vegetarians a nd vegans,” PLoS ONE , vol. 5, no. 5, pp. 1–9, 2010
2010
-
[27]
Collab orative filtering with preferences inferred from brain signals,
K. M. Davis III, M. M. A. Spap´ e, and T. Ruotsalo, “Collab orative filtering with preferences inferred from brain signals,” in Proc. of the W eb Conf., Virtual Event, Apr. 2021, pp. 602–611
2021
-
[28]
Evidence fo r erp biomark- ers of eating disorder symptoms in women,
K. Groves, S. Kennett, and H. Gillmeister, “Evidence fo r erp biomark- ers of eating disorder symptoms in women,” Biological Psychology , vol. 123, pp. 205–219, 2017
2017
-
[29]
Event-related p otential (ERP) measures of error processing as biomarkers of externa lizing dis- orders: A narrative review,
M. C. Lutz, R. Kok, and I. H. A. Franken, “Event-related p otential (ERP) measures of error processing as biomarkers of externa lizing dis- orders: A narrative review,” International Journal of Psychophysiology, vol. 166, pp. 151–159, 2021
2021
-
[30]
Smokers and ex-somkers have shared differences in the neural substr ates for potential monetary gains and losses,
L. J. Nestor, E. McCabe, J. Jones, L. Clancy, and H. Garav an, “Smokers and ex-somkers have shared differences in the neural substr ates for potential monetary gains and losses,” Addiction Biology, vol. 23, no. 1, pp. 369–378, 2018
2018
-
[31]
On the vulnerability of CNN classifie rs in EEG-based BCIs,
X. Zhang and D. Wu, “On the vulnerability of CNN classifie rs in EEG-based BCIs,” IEEE Trans. on Neural Systems and Rehabilitation Engineering, vol. 27, no. 5, pp. 814–825, 2019
2019
-
[32]
Stealing machine learning models via prediction APIs,
F. Tram` er, F. Zhang, A. Juels, M. K. Reiter, and T. Riste npart, “Stealing machine learning models via prediction APIs,” in Proc. 25th USENIX Security Symposium , Austin, TX, Aug. 2016, pp. 601–618
2016
-
[33]
Copycat CNN: Stealing knowledge by pe rsuading confession with random non-labeled data,
J. R. Correia-Silva, R. F. Berriel, C. Badue, A. F. de Sou za, and T. Oliveira-Santos, “Copycat CNN: Stealing knowledge by pe rsuading confession with random non-labeled data,” in Proc. Int’l Joint Conf. on Neural Networks , Rio, Brazil, Jul. 2018, pp. 1–8
2018
-
[34]
Practical black-box attacks against machine lea rning,
N. Papernot, P . McDaniel, I. Goodfellow, S. Jha, Z. B. Ce lik, and A. Swami, “Practical black-box attacks against machine lea rning,” in Proc. ACM on Asia Conf. on Computer and Communications Secur ity, Abu Dhabi, United Arab Emirates, Apr. 2017, pp. 506–519
2017
-
[35]
Privacy-preserving mach ine learning: Threats and solutions,
M. Al-Rubaie and J. M. Chang, “Privacy-preserving mach ine learning: Threats and solutions,” IEEE Security & Privacy , vol. 17, no. 2, pp. 49–58, 2019
2019
-
[36]
Can we stil l avoid automatic face detection?
M. J. Wilber, V . Shmatikov, and S. Belongie, “Can we stil l avoid automatic face detection?” in Proc. IEEE Winter Conf. on Applications of Computer Vision , Lake Placid, NY , Mar. 2016, pp. 1–9
2016
-
[37]
De-anony mization attack on geolocated data,
S. Gambs, M. Killijian, and M. N. d. P . Cortez, “De-anony mization attack on geolocated data,” in Proc. 12th IEEE Int’l Conf. on Trust, Security and Privacy in Computing and Communications , Melbourne, Australia, Jul. 2013, pp. 789–797
2013
-
[38]
Structural data de- anonymization: Theory and practice,
S. Ji, W. Li, M. Srivatsa, and R. Beyah, “Structural data de- anonymization: Theory and practice,” IEEE/ACM Trans. on Network- ing, vol. 24, no. 6, pp. 3523–3536, 2016
2016
-
[39]
Faceles s person recognition: Privacy implications in social media,
S. J. Oh, R. Benenson, M. Fritz, and B. Schiele, “Faceles s person recognition: Privacy implications in social media,” in Proc. European Conf. on Computer Vision , Amsterdam, The Netherlands, Oct. 2016, pp. 19–35
2016
-
[40]
Defeating i mage obfus- cation with deep learning,
R. McPherson, R. Shokri, and V . Shmatikov, “Defeating i mage obfus- cation with deep learning,” arXiv preprint arXiv:1609.00408 , 2016
2016 arXiv
-
[41]
P3: Toward privac y-preserving photo sharing,
M.-R. Ra, R. Govindan, and A. Ortega, “P3: Toward privac y-preserving photo sharing,” in Proc. 10th USENIX Symposium on Networked Systems Design and Implementation , Lombard, IL, Apr. 2013, pp. 515– 528
2013
-
[42]
Priva cy leakage via de-anonymization and aggregation in heterogen eous social networks,
H. Li, Q. Chen, H. Zhu, D. Ma, H. Wen, and X. S. Shen, “Priva cy leakage via de-anonymization and aggregation in heterogen eous social networks,” IEEE Trans. on Dependable and Secure Computing , vol. 17, no. 2, pp. 350–362, 2020
2020
-
[43]
Fingerprint reconstruction: Fr om minutiae to phase,
J. Feng and A. K. Jain, “Fingerprint reconstruction: Fr om minutiae to phase,” IEEE Trans. on Pattern Analysis and Machine Intelligence , vol. 33, no. 2, pp. 209–223, 2011
2011
-
[44]
Learning fingerprint reconstruct ion: From minutiae to image,
K. Cao and A. K. Jain, “Learning fingerprint reconstruct ion: From minutiae to image,” IEEE Trans. on Information F orensics and Security, vol. 10, no. 1, pp. 104–117, 2015. 11
2015
-
[45]
Reconstruction attacks a gainst mobile- based continuous authentication systems in the cloud,
M. Al-Rubaie and J. M. Chang, “Reconstruction attacks a gainst mobile- based continuous authentication systems in the cloud,” IEEE Trans. on Information F orensics and Security , vol. 11, no. 12, pp. 2648–2663, 2016
2016
-
[46]
A review of classification algorith ms for EEG-based brain-computer interfaces: A 10-year update,
F. Lotte, L. Bougrain, A. Cichocki, M. Clerc, M. Congedo , A. Rako- tomamonjy, and F. Yger, “A review of classification algorith ms for EEG-based brain-computer interfaces: A 10-year update,” Journal of Neural Engineering , vol. 15, 2018
2018
-
[48]
Do we really need to access t he source data? Source hypothesis transfer for unsupervised domain a daptation,
J. Liang, D. Hu, and J. Feng, “Do we really need to access t he source data? Source hypothesis transfer for unsupervised domain a daptation,” in Proc. 37th Int’l Conf. on Machine Learning , Vienna, Austria, Jul. 2020
2020
-
[49]
Machine lear ning models that remember too much,
C. Song, T. Ristenpart, and V . Shmatikov, “Machine lear ning models that remember too much,” in Proc. ACM SIGSAC Conf. on Computer and Communications Security , Dallas, TX, Oct. 2017, pp. 587–601
2017
-
[51]
Memb ership inference attacks against machine learning models,
R. Shokri, M. Stronati, C. Song, and V . Shmatikov, “Memb ership inference attacks against machine learning models,” in Proc. IEEE Symposium on Security and Privacy , San Jose, CA, May 2017, pp. 3–18
2017
-
[52]
Model invers ion attacks that exploit confidence information and basic countermeasures,
M. Fredrikson, S. Jha, and T. Ristenpart, “Model invers ion attacks that exploit confidence information and basic countermeasures, ” in Proc. 22nd ACM SIGSAC Conf. on Computer and Communications Securi ty, Denver, CO, Oct. 2015, pp. 1322–1333
2015
-
[54]
Active learning for black -box adver- sarial attacks in EEG-based brain-computer interfaces,
X. Jiang, X. Zhang, and D. Wu, “Active learning for black -box adver- sarial attacks in EEG-based brain-computer interfaces,” i n Proc. IEEE Symposium Series on Computational Intelligence , Xiamen, China, Dec. 2019
2019
-
[55]
Tiny noise, big mistakes: Adversarial per turbations induce errors in brain-computer interface spellers,
X. Zhang, D. Wu, L. Ding, H. Luo, C.-T. Lin, T.-P . Jung, an d R. Chavarriaga, “Tiny noise, big mistakes: Adversarial per turbations induce errors in brain-computer interface spellers,” National Science Review, vol. 8, no. 4, 2021
2021
-
[56]
White-box tar get attack for EEG-based BCI regression problems,
L. Meng, C.-T. Lin, T.-P . Jung, and D. Wu, “White-box tar get attack for EEG-based BCI regression problems,” in Proc. Int’l Conf. on Neural Information Processing, Sydney, Australia, Dec. 2019
2019
-
[57]
Universal adversarial perturbations for CNN classifiers in EEG-based BCIs,
Z. Liu, L. Meng, X. Zhang, W. Fang, and D. Wu, “Universal adversarial perturbations for CNN classifiers in EEG-based BCIs,” Journal of Neural Engineering , vol. 18, no. 4, p. 0460a4, 2021. [Online]. Available: https://arxiv.org/abs/1912.01171
2021 arXiv
-
[58]
Task- independent EEG identification via low-rank matrix decompo sition,
X. Kong, W. Kong, Q. Fan, Q. Zhao, and A. Cichocki, “Task- independent EEG identification via low-rank matrix decompo sition,” in IEEE Int’l Conf. on Bioinformatics and Biomedicine , Madrid, Spain, Dec. 2018, pp. 412–419
2018
-
[59]
BCI competition 2008 – Graz data set A,
C. Brunner, R. Leeb, G. M¨ uller-Putz, A. Schl¨ ogl, and G . Pfurtscheller, “BCI competition 2008 – Graz data set A,” Institute for Knowledge Discovery (Laboratory of Brain-Computer Interfaces), Gra z University of Technology, vol. 16, pp. 1–6, 2008
2008
-
[60]
Attention and p3 00-based BCI performance in people with amyotrophic lateral sclerosis,
A. Riccio, L. Simione, F. Schettini, A. Pizzimenti, M. I nghilleri, M. O. Belardinelli, D. Mattia, and F. Cincotti, “Attention and p3 00-based BCI performance in people with amyotrophic lateral sclerosis, ” Frontiers in Human Neuroscience, vol. 7, no. 1, p. 732, 2013
2013
-
[61]
Investigating critical freq uency bands and channels for EEG-based emotion recognition with deep ne ural networks,
W.-L. Zheng and B.-L. Lu, “Investigating critical freq uency bands and channels for EEG-based emotion recognition with deep ne ural networks,” IEEE Trans. on Autonomous Mental Development , vol. 7, no. 3, pp. 162–175, 2015
2015
-
[62]
Do EEG-biometric templates thre aten user privacy?
Y . H¨ oller and A. Uhl, “Do EEG-biometric templates thre aten user privacy?” in Proc. 6th ACM W orkshop on Information Hiding and Multimedia Security , Innsbruck, Austria, Jun. 2018, pp. 31–42
2018
-
[63]
Efficient and privacy-preserving medical research suppor t platform against COVID-19: A blockchain-based approach,
K. Y u, J. Huang, L. Tan, G. Srivastava, X. Shang, and P . Ch atterjee, “Efficient and privacy-preserving medical research suppor t platform against COVID-19: A blockchain-based approach,” IEEE Consumer Electronics Magazine, vol. 10, no. 2, pp. 111–120, 2020
2020
-
[64]
N-Sanitization: A semantic privacy-preserving framework for unstructured medical datasets,
C. Iwendi, S. A. Moqurrab, A. Anjum, S. Khan, S. Mohan, an d G. Sri- vastava, “N-Sanitization: A semantic privacy-preserving framework for unstructured medical datasets,” Computer Communications , vol. 161, no. 2020, pp. 160–171, 2020
2020
-
[65]
Machine le arning classification over encrypted data,
R. Bost, R. A. Popa, S. Tu, and S. Goldwasser, “Machine le arning classification over encrypted data,” in Proc. Network and Distributed System Security Symposium , San Diego, CA, Feb. 2015
2015
-
[66]
CryptoNets: Applying neural networks to encr ypted data with high throughput and accuracy,
N. Dowlin, R. Gilad-Bachrach, K. Laine, K. Lauter, M. Na ehrig, and J. Wernsing, “CryptoNets: Applying neural networks to encr ypted data with high throughput and accuracy,” in Proc. 33rd Int’l Conf. on Int’l Conf. on Machine Learning , New Y ork, NY , Jun. 2016, pp. 201–210
2016
-
[67]
Privacy preserving extreme learnin g machine using additively homomorphic encryption,
S. Kuri, T. Hayashi, T. Omori, S. Ozawa, Y . Aono, L. T. Pho ng, L. Wang, and S. Moriai, “Privacy preserving extreme learnin g machine using additively homomorphic encryption,” in Proc. IEEE Symposium Series on Computational Intelligence , Honolulu, HI, Nov. 2017, pp. 1–8
2017
-
[68]
Private mac hine learning classification based on fully homomorphic encrypt ion,
X. Sun, P . Zhang, J. K. Liu, J. Y u, and W. Xie, “Private mac hine learning classification based on fully homomorphic encrypt ion,” IEEE Trans. on Emerging Topics in Computing , vol. 8, no. 2, pp. 352–364, 2020
2020
-
[69]
How to generate and exchange secrets,
A. C. Y ao, “How to generate and exchange secrets,” in Proc. 27th Annual Symposium on F oundations of Computer Science , Toronto, Canada, Oct. 1986
1986
-
[70]
Common randomness in infor mation theory and cryptography. I. secret sharing,
R. Ahlswede and I. Csiszar, “Common randomness in infor mation theory and cryptography. I. secret sharing,” IEEE Trans. on Information Theory, vol. 39, no. 4, pp. 1121–1132, 1993
1993
-
[71]
Privacy-preserving ridge regression on hundreds of millions of records,
V . Nikolaenko, U. Weinsberg, S. Ioannidis, M. Joye, D. B oneh, and N. Taft, “Privacy-preserving ridge regression on hundreds of millions of records,” in Proc. IEEE Symposium on Security and Privacy , Berkeley, CA, May 2013, pp. 334–348
2013
-
[72]
Oblivious multi-party machine le arning on trusted processors,
O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowo zin, K. V aswani, and M. Costa, “Oblivious multi-party machine le arning on trusted processors,” in Proc. 25th USENIX Security Symposium , Austin, TX, Aug. 2016, pp. 619–636
2016
-
[73]
SGX-Big Matrix: A practical encrypted data analytic framework with trusted p rocessors,
F. Shaon, M. Kantarcioglu, Z. Lin, and L. Khan, “SGX-Big Matrix: A practical encrypted data analytic framework with trusted p rocessors,” in Proc. ACM SIGSAC Conf. on Computer and Communications Secur ity, Dallas, TX, Oct. 2017, pp. 1211–1228
2017
-
[74]
Privacy-preserving linear r egression for brain-computer interface applications,
A. Agarwal, R. Dowsley, N. D. McKinney, D. Wu, C.-T. Lin, M. De Cock, and A. C. A. Nascimento, “Privacy-preserving linear r egression for brain-computer interface applications,” in Proc. IEEE Int’l Conf. on Big Data , Seattle, W A, Dec. 2018, pp. 5277–5278
2018
-
[75]
Protecting privacy of users i n brain- computer interface applications,
A. Agarwal, R. Dowsley, N. D. McKinney, D. Wu, C.-T. Lin, M. De Cock, and A. C. A. Nascimento, “Protecting privacy of users i n brain- computer interface applications,” IEEE Trans. on Neural Systems and Rehabilitation Engineering , vol. 27, no. 8, pp. 1546–1555, 2019
2019
-
[76]
Privacy-preserving mach ine learning through data obfuscation,
T. Zhang, Z. He, and R. B. Lee, “Privacy-preserving mach ine learning through data obfuscation,” arXiv preprint arXiv:1807.01860 , 2018
2018 arXiv
-
[77]
Differentially priv ate data publishing and analysis: A survey,
T. Zhu, G. Li, W. Zhou, and P . S. Y u, “Differentially priv ate data publishing and analysis: A survey,” IEEE Trans. on Knowledge and Data Engineering , vol. 29, no. 8, pp. 1619–1638, 2017
2017
-
[78]
A firm foundation for private data analysis,
C. Dwork, “A firm foundation for private data analysis,” Communica- tions of the ACM , vol. 54, no. 1, pp. 86–95, 2011
2011
-
[79]
Mechanism design via differ ential pri- vacy,
F. McSherry and K. Talwar, “Mechanism design via differ ential pri- vacy,” in Proc. 48th Annual IEEE Symposium on F oundations of Computer Science , Providence, RI, Oct. 2007, pp. 94–103
2007
-
[80]
Learning in a large function space: Privacy-preserving mechanisms f or SVM learning,
B. I. P . Rubinstein, P . L. Bartlett, L. Huang, and N. Taft , “Learning in a large function space: Privacy-preserving mechanisms f or SVM learning,” Journal of Privacy and Confidentiality , vol. 4, no. 1, pp. 65–100, 2012
2012
-
[81]
Differ entially private empirical risk minimization,
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differ entially private empirical risk minimization,” Journal of Machine Learning Research, vol. 12, no. 41, pp. 1069–1109, 2011
2011
-
[82]
A comprehensi ve survey on local differential privacy,
X. Xiong, S. Liu, D. Li, Z. Cai, and X. Niu, “A comprehensi ve survey on local differential privacy,” Security and Communication Networks , vol. 2020, pp. 1–29, 2020
2020
-
[83]
Privacy-preser ving aggre- gation of time-series data,
E. Shi, T. H. H. Chan, and E. G. Rieffel, “Privacy-preser ving aggre- gation of time-series data,” in Proc. Network and Distributed System Security Symposium , San Diego, CA, Feb. 2011
2011
-
[84]
Protecting privacy in share d photos via adversarial examples based stealth,
Y . Liu, W. Zhang, and N. Y u, “Protecting privacy in share d photos via adversarial examples based stealth,” Security and Communication Networks, vol. 2017, pp. 1–16, 2017
2017
-
[86]
Random projection-ba sed mul- tiplicative data perturbation for privacy preserving dist ributed data mining,
K. Liu, H. Kargupta, and J. Ryan, “Random projection-ba sed mul- tiplicative data perturbation for privacy preserving dist ributed data mining,” IEEE Trans. on Knowledge and Data Engineering , vol. 18, no. 1, pp. 92–106, 2006. 12
2006
-
[87]
Non- linear dimensionality reduction for privacy-preserving d ata classifica- tion,
K. Alotaibi, V . J. Rayward-Smith, W. Wang, and B. de la Ig lesia, “Non- linear dimensionality reduction for privacy-preserving d ata classifica- tion,” in Proc. Int’l Conf. on Privacy, Security, Risk and Trust and In t’l Conf on Social Computing , Amsterdam, Netherlands, Sep. ...
2012
-
[88]
Repre- sentation transfer for differentially private drug sensit ivity prediction,
T. Niinim¨ aki, M. A. Heikkil¨ a, A. Honkela, and S. Kaski , “Repre- sentation transfer for differentially private drug sensit ivity prediction,” Bioinformatics, vol. 35, no. 14, pp. 218–224, 2019
2019
-
[89]
Deep generative image models using a Laplacian pyramid of adversarial netwo rks,
E. L. Denton, S. Chintala, A. Szlam, and R. Fergus, “Deep generative image models using a Laplacian pyramid of adversarial netwo rks,” in Proc. Advances in Neural Information Processing Systems , Montreal, Canada, Dec. 2015, pp. 1486–1494
2015
-
[90]
Gen- erative models for simulating mobility trajectories,
V . Kulkarni, N. Tagasovska, T. V atter, and B. Garbinato , “Gen- erative models for simulating mobility trajectories,” arXiv preprint arXiv:1811.12801, 2018
2018 arXiv
-
[91]
Learning sensitive images using generative models,
S. Samson Cheung, H. Wildfeuer, M. Nikkhah, X. Zhu, and W . Tan, “Learning sensitive images using generative models,” in Proc. 25th IEEE Int’l Conf. on Image Processing , Athens, Greece, Oct. 2018, pp. 4128–4132
2018
-
[92]
Differen- tially private mixture of generative neural networks,
G. Acs, L. Melis, C. Castelluccia, and E. De Cristofaro, “Differen- tially private mixture of generative neural networks,” IEEE Trans. on Knowledge and Data Engineering , vol. 31, no. 6, pp. 1109–1121, 2019
2019
-
[93]
A privacy-pres erving gen- erative adversarial network method for securing EEG brain s ignals,
E. Debie, N. Moustafa, and M. T. Whitty, “A privacy-pres erving gen- erative adversarial network method for securing EEG brain s ignals,” in Proc. Int’l Joint Conf. on Neural Networks , Glasgow, United Kingdom, Jul. 2020, pp. 1–8
2020
-
[94]
Privac y risk assessment for data subject-aware threat modeling,
L. Sion, D. V an Landuyt, K. Wuyts, and W. Joosen, “Privac y risk assessment for data subject-aware threat modeling,” in Proc. IEEE Security and Privacy W orkshops , San Francisco, CA, May 2019, pp. 64–71
2019
-
[95]
Connecting pixe ls to privacy and utility: Automatic redaction of private information in images,
T. Orekondy, M. Fritz, and B. Schiele, “Connecting pixe ls to privacy and utility: Automatic redaction of private information in images,” in Proc. IEEE/CVF Conf. on Computer Vision and Pattern Recogni tion, Salt Lake City, UT, Jun. 2018, pp. 8466–8475
2018
-
[96]
When machine learning meets privacy: A survey and outlook,
B. Liu, M. Ding, S. Shaham, W. Rahayu, F. Farokhi, and Z. L in, “When machine learning meets privacy: A survey and outlook,” arXiv preprint arXiv:2011.11819, 2020
2011 arXiv
-
[97]
The feasibility of dynamically granted pe rmissions: Aligning mobile privacy with user preferences,
P . Wijesekera, A. Baokar, L. Tsai, J. Reardon, S. Egelma n, D. Wagner, and K. Beznosov, “The feasibility of dynamically granted pe rmissions: Aligning mobile privacy with user preferences,” in Proc. IEEE Sym- posium on Security and Privacy , San Jose, CA, May 2017, pp. 1077– 1093
2017
-
[98]
Keeping conte xt in mind: Automating mobile app access control with user interface in spection,
H. Fu, Z. Zheng, S. Zhu, and P . Mohapatra, “Keeping conte xt in mind: Automating mobile app access control with user interface in spection,” in Proc. IEEE Conf. on Computer Communications , Paris, France, Apr. 2019, pp. 2089–2097
2019
-
[99]
A novel approach for ens uring the privacy of EEG signals using application-specific feature e xtraction and AES algorithm,
V . Robinson and E. B. V arghese, “A novel approach for ens uring the privacy of EEG signals using application-specific feature e xtraction and AES algorithm,” in Proc. Int’l Conf. on Inventive Computation Technologies, Coimbatore, India, Aug. 2016, pp. 1–6
2016
-
[100]
Privacy preserving classification of EEG data using machine learning and homomorphic encryption,
A. B. Popescu, L. A. Taca, C. I. Nita, A. Vizitiu, R. Deme ter, C. Suciu, and L. M. Itu, “Privacy preserving classification of EEG data using machine learning and homomorphic encryption,” Applied Sciences , vol. 11, no. 16, p. 7360, 2021
2021
-
[101]
Towards pr ivacy- preserving explanations in medical image analysis,
H. Montenegro, W. Silva, and J. S. Cardoso, “Towards pr ivacy- preserving explanations in medical image analysis,” arXiv preprint arXiv:2107.09652, 2021
2021 arXiv
-
[102]
D. L. Schomer and F. H. L. da Silva, Niedermeyer’s Electroencephalog- raphy Basic Principles, Clinical Applications, and Relate d Fields . Oxford, UK: Oxford University Press, 2017
2017
-
[103]
A survey on transfer learning,
S. J. Pan and Q. Y ang, “A survey on transfer learning,” IEEE Trans. on Knowledge and Data Engineering , vol. 22, no. 10, pp. 1345–1359, 2010
2010
-
[104]
Transfer learning for brain-computer interfaces: A Euclidean space data alignment approach,
H. He and D. Wu, “Transfer learning for brain-computer interfaces: A Euclidean space data alignment approach,” IEEE Trans. on Biomedical Engineering, vol. 67, no. 2, pp. 399–410, 2020
2020
-
[105]
Unsupervised domain adap- tation of black-box source models,
H. Zhang, Y . Zhang, K. Jia, and L. Zhang, “Unsupervised domain adap- tation of black-box source models,” arXiv preprint arXiv:2101.02839 , 2021
2021 arXiv
-
[106]
A survey on federated learning: The journey from centralized to distributed on-site learning and beyond,
S. A. Rahman, H. Tout, H. Ould-Slimane, A. Mourad, C. Ta lhi, and M. Guizani, “A survey on federated learning: The journey from centralized to distributed on-site learning and beyond,” IEEE Internet of Things Journal , 2020, i
2020
-
[107]
A secure f ederated transfer learning framework,
Y . Liu, Y . Kang, C. Xing, T. Chen, and Q. Y ang, “A secure f ederated transfer learning framework,” IEEE Intelligent Systems , vol. 35, no. 4, pp. 70–82, 2020
2020
-
[108]
Feder ated transfer learning for EEG signal classification,
C. Ju, D. Gao, R. Mane, B. Tan, Y . Liu, and C. Guan, “Feder ated transfer learning for EEG signal classification,” in Proc. 42nd Annual Int’l Conf. of the IEEE Engineering in Medicine and Biology S ociety, Montreal, Canada, Jul. 2020, pp. 3040–3045
2020
-
[109]
Neurocrypt: Machine learning over encrypted distri buted neu- roimaging data,
N. Senanayake, R. Podschwadt, D. Takabi, V . D. Calhoun , and S. M. Plis, “Neurocrypt: Machine learning over encrypted distri buted neu- roimaging data,” Neuroinformatics, 2021
2021
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.