Adversarial Artifact Detection in EEG-Based Brain-Computer Interfaces
arXiv:2212.00727 · doi:10.1088/1741-2552/ad8964
Abstract
Machine learning has achieved great success in electroencephalogram (EEG) based brain-computer interfaces (BCIs). Most existing BCI research focused on improving its accuracy, but few had considered its security. Recent studies, however, have shown that EEG-based BCIs are vulnerable to adversarial attacks, where small perturbations added to the input can cause misclassification. Detection of adversarial examples is crucial to both the understanding of this phenomenon and the defense. This paper, for the first time, explores adversarial detection in EEG-based BCIs. Experiments on two EEG datasets using three convolutional neural networks were performed to verify the performances of multiple detection approaches. We showed that both white-box and black-box attacks can be detected, and the former are easier to detect.
References in corpus (7)
- Explaining and Harnessing Adversarial Examples
- Theoretically Principled Trade-off between Robustness and Accuracy
- Adversarial Example Detection for DNN Models: A Review and Experimental Comparison
- The Vulnerability of Semantic Segmentation Networks to Adversarial Attacks in Autonomous Driving: Enhancing Extensive Environment Sensing
- Adversarial Attacks and Defenses in Physiological Computing: A Systematic Review
- Alignment-Based Adversarial Training (ABAT) for Improving the Robustness and Accuracy of EEG-Based BCIs
- Adversarial Filtering Based Evasion and Backdoor Attacks to EEG-Based Brain-Computer Interfaces