BCI-to-agent pipelines turn decoded neural activity into an authorization channel for tool-use agents, exposing a new attack surface we call \emph{brain-prompt injection}: signal-side perturbations, context-only injections, and adaptive dual-decoder attacks can all change the routed action while EEG-side or text-side monitors remain blind. Route safety in this stack depends on what the audit log can observe, not on decoder accuracy or agreement alone. We define a Route-Safety Audit Contract: a minimal log schema, denominator hierarchy, and endpoint specification, and prove an audit-schema separation theorem together with a C3 attacked-dependence decomposition; clean agreement and marginal robustness do not identify the joint term that controls C3 routing. As a calibration layer on top of the contract, we apply split-conformal calibration to a non-oracle EEG confirmation channel and report the resulting false-accept frontier under an explicit threat-archetype matrix. We instantiate the contract on EEGMMI native left/right command-control over 5{,}400 events, harmless tool stubs, and seed/case denominators. Provenance blocks C2 routes ($0.000$); agreement-plus-provenance routes C3 flips ($1.000$); confirmation-plus-provenance routes them ($0.000$). The conformal frontier reaches FAR $0.000$ at clean utility $0.150$ for $α=.005$ and FAR $0.119$ at clean utility $0.452$ for $α=.10$ under acquisition isolation; an attacker-controllable confirmation channel breaks the bound to $\approx\!1$. Subject-cluster bootstrap confirms these intervals on $60$ subjects; cross-architecture (TinyEEGNet, EEGNetV4) and capacity-sweep results show within-regime saturation. Mediation and confirmation reduce risk; they are not intent certificates.


翻译:脑机接口到代理的流水线将解码后的神经活动转化为工具使用代理的授权通道,由此暴露了一个我们称之为"脑-提示注入"的新型攻击面:信号侧扰动、仅上下文注入以及自适应双解码器攻击均能在脑电图侧或文本侧监测器保持盲态的情况下改变路由动作。该架构中的通路安全性取决于审计日志可观测的内容,而非仅依赖解码器准确率或一致性。我们定义了一个通路安全性审计契约:包含最小日志模式、分母层级和端点规范,并证明了一个审计-模式分离定理与C3攻击依赖性分解;纯粹的一致性和边际鲁棒性无法识别控制C3路由的联合项。作为契约之上的校准层,我们将分裂保形校准应用于非神谕脑电图确认通道,并在显式威胁原型矩阵下报告所得到的伪接受边界。我们利用EEGMMI原生左/右指令控制(涉及5,400个事件)、无害工具存根以及种子/事件分母实例化该契约。来源溯源封阻C2路由(0.000);一致性加来源溯源路由C3翻转(1.000);确认加来源溯源路由它们(0.000)。保形边界在采集隔离条件下,对于α=0.005时达到伪接受率0.000(清洁效用0.150),对于α=0.10时达到伪接受率0.119(清洁效用0.452);攻击者可控制的确认通道将该界限打破至约1。基于60名受试者的受试者聚类自助法验证了这些置信区间;跨架构(TinyEEGNet、EEGNetV4)与容量扫描结果显示域内饱和。中介与确认可降低风险,但它们并非意图证书。

0
下载
关闭预览

相关内容

TransMLA:多头潜在注意力(MLA)即为所需
专知会员服务
23+阅读 · 2025年2月13日
【ICLR2021】通过多种自监督方式提升GAT中注意力
专知会员服务
44+阅读 · 2021年2月27日
注意力机制可解释吗?这篇ACL 2019论文说……
机器之心
11+阅读 · 2019年6月16日
【泡泡图灵智库】密集相关的自监督视觉描述学习(RAL)
泡泡机器人SLAM
11+阅读 · 2018年10月6日
NetworkMiner - 网络取证分析工具
黑白之道
16+阅读 · 2018年6月29日
【AAAI专题】论文分享:以生物可塑性为核心的类脑脉冲神经网络
中国科学院自动化研究所
15+阅读 · 2018年1月23日
国家自然科学基金
6+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
VIP会员
最新内容
边缘计算的军事应用
专知会员服务
7+阅读 · 8月9日
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
9+阅读 · 8月8日
《多域冲突比较支持模型》60页
专知会员服务
14+阅读 · 8月7日
相关VIP内容
相关基金
国家自然科学基金
6+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员