BCI-to-agent pipelines turn decoded neural activity into an authorization channel for tool-use agents, exposing a new attack surface we call \emph{brain-prompt injection}: signal-side perturbations, context-only injections, and adaptive dual-decoder attacks can all change the routed action while EEG-side or text-side monitors remain blind. Route safety in this stack depends on what the audit log can observe, not on decoder accuracy or agreement alone. We define a Route-Safety Audit Contract: a minimal log schema, denominator hierarchy, and endpoint specification, and prove an audit-schema separation theorem together with a C3 attacked-dependence decomposition; clean agreement and marginal robustness do not identify the joint term that controls C3 routing. As a calibration layer on top of the contract, we apply split-conformal calibration to a non-oracle EEG confirmation channel and report the resulting false-accept frontier under an explicit threat-archetype matrix. We instantiate the contract on EEGMMI native left/right command-control over 5{,}400 events, harmless tool stubs, and seed/case denominators. Provenance blocks C2 routes ($0.000$); agreement-plus-provenance routes C3 flips ($1.000$); confirmation-plus-provenance routes them ($0.000$). The conformal frontier reaches FAR $0.000$ at clean utility $0.150$ for $α=.005$ and FAR $0.119$ at clean utility $0.452$ for $α=.10$ under acquisition isolation; an attacker-controllable confirmation channel breaks the bound to $\approx\!1$. Subject-cluster bootstrap confirms these intervals on $60$ subjects; cross-architecture (TinyEEGNet, EEGNetV4) and capacity-sweep results show within-regime saturation. Mediation and confirmation reduce risk; they are not intent certificates.
翻译:脑机接口到代理的流水线将解码后的神经活动转化为工具使用代理的授权通道,由此暴露了一个我们称之为"脑-提示注入"的新型攻击面:信号侧扰动、仅上下文注入以及自适应双解码器攻击均能在脑电图侧或文本侧监测器保持盲态的情况下改变路由动作。该架构中的通路安全性取决于审计日志可观测的内容,而非仅依赖解码器准确率或一致性。我们定义了一个通路安全性审计契约:包含最小日志模式、分母层级和端点规范,并证明了一个审计-模式分离定理与C3攻击依赖性分解;纯粹的一致性和边际鲁棒性无法识别控制C3路由的联合项。作为契约之上的校准层,我们将分裂保形校准应用于非神谕脑电图确认通道,并在显式威胁原型矩阵下报告所得到的伪接受边界。我们利用EEGMMI原生左/右指令控制(涉及5,400个事件)、无害工具存根以及种子/事件分母实例化该契约。来源溯源封阻C2路由(0.000);一致性加来源溯源路由C3翻转(1.000);确认加来源溯源路由它们(0.000)。保形边界在采集隔离条件下,对于α=0.005时达到伪接受率0.000(清洁效用0.150),对于α=0.10时达到伪接受率0.119(清洁效用0.452);攻击者可控制的确认通道将该界限打破至约1。基于60名受试者的受试者聚类自助法验证了这些置信区间;跨架构(TinyEEGNet、EEGNetV4)与容量扫描结果显示域内饱和。中介与确认可降低风险,但它们并非意图证书。