New Research Tests Cybersecurity Risks of Brain Chips

Futuristic electronic device with blue and yellow signal waveforms

A preprint article co-authored by experts affiliated with the University of Cambridge, explored how AI-powered non-invasive brain-computer interfaces (BCIs) can be exploited through a variety of tricks, including signal forgery, replay, and AI backdoors.

The experiments involved sending forged signals to the BCIs and measuring their response. The results show that BCIs have difficulty distinguishing between naturally produced brain signals and similar artificial signals that can be sent by external sources.

Note that these experiments do not establish that a clinical brain implant has been compromised or that a patient has been injured. They identify security questions that warrant testing across the systems used to translate neural signals into actions.

The BCIs used in this study work by recording the patient’s brain activity, then using AI-powered algorithms to decode that activity in real time into intended actions and movements. These intended actions are then relayed to an external device. In this study, the researchers used controls for a game as the output, but in practice these commands could also be sent to prosthetic limbs.

Within this whole process, the researchers targeted several different transfer points, such as the recording of the signal by the BCI, or how that recording is decoded into intent by the AI-powered algorithm. The researchers were able to trick the decoding algorithm into thinking an external signal it received was in fact coming from the patient’s brain. This means that someone who can exploit these devices can cause the user’s prosthetic to follow a command that was never generated by the user themselves. The researchers were also able to hijack saved commands within the BCI and replay them without any input from the user, which could potentially cause the prosthetic to take actions again that were never intended. Another approach involved deliberately modifying AI models to contain backdoors. An altered model could behave normally on ordinary inputs but produce an attacker-selected output when a particular trigger pattern appeared. For example, if the patient decides to tap their prosthetic fingers, the backdoor trigger can instead cause the prosthetic to do something else, like swing violently.

What Does This Mean for Patient and Consumer Safety?

When BCIs become commercialized, nefarious actors can have access to potentially thousands of users at a time. A coordinated cyber attack can leave dozens of patients losing control of their prosthetics. This scenario highlights the importance of building secure and safeguards.

The findings expose weaknesses in the tested configurations and highlight the importance of protecting the link between a user’s intention and a device’s response. It also illustrates the complex form these exploits can potentially take on.

It also reinforces the need for manufacturers to build in safeguards for their devices. Manufacturers should evaluate protections against forged and replayed signals, verify software and model updates, and provide accessible ways to confirm consequential commands or safely pause operation.

For the future of BCI development, independent assessment and clear information about affected versions and fixes remain necessary.

For patients and consumers, the central issue will hinge on whether they can trust a BCI’s output to reflect their own intended input

The article can be found here https://arxiv.org/abs/2609.08971

Leave a Reply

Discover more from Neurotech Advocacy

Subscribe now to keep reading and get access to the full archive.

Continue reading