Universal adversarial perturbations for CNN classifiers in EEG-based BCIs.
basic_science · Level V
Where this comes from
- Record sourced from PubMed, PMID 34181585.
- Also identified by DOI 10.1088/1741-2552/ac0f4c.
- No licence information is recorded for this record.
- Because redistribution is not established, this page shows the abstract only. Follow the links below for the full text.
Abstract
<i>Objective</i>. Multiple convolutional neural network (CNN) classifiers have been proposed for electroencephalogram (EEG) based brain-computer interfaces (BCIs). However, CNN models have been found vulnerable to universal adversarial perturbations (UAPs), which are small and example-independent, yet powerful enough to degrade the performance of a CNN model, when added to a benign example.<i>Approach</i>. This paper proposes a novel total loss minimization (TLM) approach to generate UAPs for EEG-based BCIs.<i>Main results</i>. Experimental results demonstrated the effectiveness of TLM on three popular CNN classifiers for both target and non-target attacks. We also verified the transferability of UAPs in EEG-based BCI systems.<i>Significance</i>. To our knowledge, this is the first study on UAPs of CNN classifiers in EEG-based BCIs. UAPs are easy to construct, and can attack BCIs in real-time, exposing a potentially critical security concern of BCIs.
Medical subject headings
- Brain-Computer Interfaces