发表机构
Microsoft; KTH Royal Institute of Technology; Nokia Bell Labs; Technical University of Munich; University of Cambridge(微软; 皇家理工学院; 诺基亚贝尔实验室; 慕尼黑工业大学; 剑桥大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出 NERVE 攻击类别,系统刻画脑机接口的五类攻击维度,并开发 EEGle 框架评估,发现 17 种新型攻击,揭示生成式 AI 降低了攻击门槛。
AI 中文摘要
人工智能在脑机接口(BCI)等人本系统中的快速集成,创造了一个连接神经信号与物理系统、且尚未被充分理解的攻击面。该领域的漏洞利用威胁着认知自主性、心理隐私和人身安全,从神经数据窃取到对连接 BCI 的设备的恶意控制,不一而足。我们提出了 NERVE 攻击类别,系统性地刻画了五个正交的攻击维度,它们共同覆盖了完整的 BCI 技术栈:神经拟态伪造(N)、去同步规避(E)、基于重放的劫持(R)、静脉窃听(V)和嵌入式后门(E)。为评估该攻击类别,我们提出了 EEGle,一个用于系统性 BCI 安全分析的人工智能辅助可扩展框架。我们的评估发现了 17 种新颖的神经特异性攻击实例,并揭示了 BCI 后门设计所特有的隐蔽-有效性谱系。我们还表明,生成式人工智能降低了非专业攻击者的入门门槛,并向社区提供 EEGle,以构建和验证这些高度个人化设备的安全性。
英文摘要
The rapid integration of AI into human-centred systems such as Brain-Computer Interfaces (BCIs) has created a poorly understood attack surface linking neural signals to physical systems. Exploits in this domain threaten cognitive autonomy, mental privacy, and physical safety, from neural data exfiltration to malicious control of BCI-tethered devices. We introduce the NERVE Attacks class, a systematic characterisation of five orthogonal attack dimensions that together span the complete BCI stack: Neuro-mimetic Forgery (N), Evasion via Desynchronization (E), Replay-based Hijacking (R), Vein Tapping (V), and Embedded Backdoors (E). To evaluate this class, we present EEGle, an AI-assisted extensible framework for systematic BCI security analysis. Our evaluation uncovers 17 novel neuro-specific attack instances and reveals a stealth-effectiveness spectrum unique to BCI backdoor design. We also show that generative AI lowers the barrier to entry for non-expert attackers and provide EEGle to the community for building and verifying the security of these deeply personal devices.