[论文解读] Subliminal Probing for Private Information via EEG-Based BCI Devices
本文提出了一种基于脑电图(EEG)脑机接口(BCI)设备的隐性攻击方法,通过呈现低于意识感知阈值的视觉刺激(小于13.3毫秒),推断用户隐私信息(如对熟悉面孔的识别)。利用脑电信号的机器学习分析,该攻击在27名参与者中的18名中成功识别出识别反应,准确率达66.7%,将猜测熵降低了最高达48.8%,证明了隐性探测在技术上可行且对用户不可察觉。
Martinovic et al. proposed a Brain-Computer-Interface (BCI) -based attack in which an adversary is able to infer private information about a user, such as their bank or area-of-living, by analyzing the user's brain activities. However, a key limitation of the above attack is that it is intrusive, requiring user cooperation, and is thus easily detectable and can be reported to other users. In this paper, we identify and analyze a more serious threat for users of BCI devices. We propose a it subliminal attack in which the victim is attacked at the levels below his cognitive perception. Our attack involves exposing the victim to visual stimuli for a duration of 13.3 milliseconds -- a duration usually not sufficient for conscious perception. The attacker analyzes subliminal brain activity in response to these short visual stimuli to infer private information about the user. If carried out carefully, for example by hiding the visual stimuli within screen content that the user expects to see, the attack may remain undetected. As a consequence, the attacker can scale it to many victims and expose them to the attack for a long time. We experimentally demonstrate the feasibility of our subliminal attack via a proof-of-concept study carried out with 27 subjects. We conducted experiments on users wearing Electroencephalography-based BCI devices, and used portrait pictures of people as visual stimuli which were embedded within the background of an innocuous video for a time duration not exceeding 13.3 milliseconds. Our experimental results show that it is feasible for an attacker to learn relevant private information about the user, such as whether the user knows the identity of the person for which the attacker is probing.
研究动机与目标
- 调查是否能够从消费者级BCI设备对隐性视觉刺激的EEG反应中提取私人信息。
- 克服以往超阈攻击依赖有意识感知、易被察觉的局限性。
- 评估通过脑电波分析对用户进行隐性探测作为隐蔽手段推断私人信息的可行性。
- 评估攻击者是否可通过不可察觉刺激引发的EEG信号,降低对私人数据的猜测熵。
提出的方法
- 攻击通过呈现时间少于13.3毫秒的视觉刺激,使其低于意识感知阈值。
- 记录了27名参与者在观看包含目标人物隐性图像的视频时的EEG信号。
- 利用机器学习分类器对EEG反应进行训练,以区分目标面孔与控制刺激引发的脑活动。
- 比较感知到刺激与未感知到刺激的受试者之间的分类性能,以评估攻击的可检测性。
- 计算猜测熵的降低量,以量化攻击者相对于随机猜测的推断能力提升。
- 测试了预警条件,以评估用户意识是否能缓解隐性探测的风险。
实验结果
研究问题
- RQ1是否能够从用户未有意识感知的视觉刺激引发的EEG反应中推断出私人信息?
- RQ2隐性刺激在多大程度上能引发可被机器学习分类的可测量脑电波反应?
- RQ3隐性探测的成功率是否在察觉刺激的用户与未察觉的用户之间存在差异?
- RQ4攻击者通过隐性EEG探测最多能将猜测私人信息的熵降低多少?
- RQ5用户意识或预警是否能有效缓解通过EEG-BMI设备造成的隐性信息泄露风险?
主要发现
- 分类器在27名参与者中的18名中正确识别出目标面孔识别,成功率达66.7%。
- 该攻击平均使攻击者的猜测熵降低20.8%,在高性能攻击变体中最高降低达48.8%。
- 察觉与未察觉刺激的参与者之间成功率无显著差异,表明该攻击对用户不可察觉。
- 即使在刺激后给予预警,隐性脑电反应仍可被检测到,表明基于意识的缓解措施效果有限。
- 结果表明,通过EEG-BMI设备进行隐性探测在技术上可行,且可在用户无察觉的情况下提取概率性私人信息。
- 研究表明,即使在不同EEG反应类型上训练的机器学习模型,仍能泛化检测隐性刺激,提升了该攻击的实际可行性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。