Active Poisoning: Efficient Backdoor Attacks on Transfer Learning-Based Brain-Computer Interfaces
arXiv:2412.09933 · doi:10.1007/s11432-022-3548-2
Abstract
Transfer learning (TL) has been widely used in electroencephalogram (EEG)-based brain-computer interfaces (BCIs) for reducing calibration efforts. However, backdoor attacks could be introduced through TL. In such attacks, an attacker embeds a backdoor with a specific pattern into the machine learning model. As a result, the model will misclassify a test sample with the backdoor trigger into a prespecified class while still maintaining good performance on benign samples. Accordingly, this study explores backdoor attacks in the TL of EEG-based BCIs, where source-domain data are poisoned by a backdoor trigger and then used in TL. We propose several active poisoning approaches to select source-domain samples, which are most effective in embedding the backdoor pattern, to improve the attack success rate and efficiency. Experiments on four EEG datasets and three deep learning models demonstrate the effectiveness of the approaches. To our knowledge, this is the first study about backdoor attacks on TL models in EEG-based BCIs. It exposes a serious security risk in BCIs, which should be immediately addressed.
References in corpus (8)
- EEGNet: A Compact Convolutional Network for EEG-based Brain-Computer Interfaces
- Deep learning with convolutional neural networks for EEG decoding and visualization
- Transfer Learning in Brain-Computer Interfaces
- Securing Connected & Autonomous Vehicles: Challenges Posed by Adversarial Machine Learning and The Way Forward
- Neural Trojans
- Attack of the Tails: Yes, You Really Can Backdoor Federated Learning
- Backdoor Attacks against Transfer Learning with Pre-trained Deep Learning Models
- Tiny noise, big mistakes: Adversarial perturbations induce errors in Brain-Computer Interface spellers