TY - JOUR
T1 - Spatialspectral-Backdoor
T2 - Realizing backdoor attack for deep neural networks in brain–computer interface via EEG characteristics
AU - Li, Fumin
AU - Huang, Mengjie
AU - You, Wenlong
AU - Zhu, Longsheng
AU - Cheng, Hanjing
AU - Yang, Rui
N1 - Publisher Copyright:
© 2024
PY - 2025/2/1
Y1 - 2025/2/1
N2 - In recent years, electroencephalogram (EEG) based on the brain–computer interface (BCI) systems have become increasingly advanced, with researcher using deep neural networks as tools to enhance performance. BCI systems heavily rely on EEG signals for effective human–computer interactions, and deep neural networks show excellent performance in processing and classifying these signals. Nevertheless, the vulnerability to backdoor attack is still a major problem. Backdoor attack is the injection of specially designed triggers into the model training process, which can lead to significant security issues. Therefore, in order to simulate the negative impact of backdoor attack and bridge the research gap in the field of BCI, this paper proposes a new backdoor attack method to call researcher attention to the security issues of BCI. In this paper, Spatialspectral-Backdoor is proposed to effectively attack the BCI system. The method is carefully designed to target the spectral active backdoor attack of the BCI system and includes a multi-channel preference method to select the electrode channels sensitive to the target task. Ultimately, the effectiveness of the comparison and ablation experiments is validated on the publicly available BCI competition datasets. The results show that the average attack success rate and clean sample accuracy of Spatialspectral-Backdoor in the BCI scenario are 97.12% and 85.16%, respectively, compared with other backdoor attack methods. Furthermore, by observing the infection ratio of backdoor triggers and visualization of the feature space, the proposed Spatialspectral-Backdoor outperforms other backdoor attack methods.
AB - In recent years, electroencephalogram (EEG) based on the brain–computer interface (BCI) systems have become increasingly advanced, with researcher using deep neural networks as tools to enhance performance. BCI systems heavily rely on EEG signals for effective human–computer interactions, and deep neural networks show excellent performance in processing and classifying these signals. Nevertheless, the vulnerability to backdoor attack is still a major problem. Backdoor attack is the injection of specially designed triggers into the model training process, which can lead to significant security issues. Therefore, in order to simulate the negative impact of backdoor attack and bridge the research gap in the field of BCI, this paper proposes a new backdoor attack method to call researcher attention to the security issues of BCI. In this paper, Spatialspectral-Backdoor is proposed to effectively attack the BCI system. The method is carefully designed to target the spectral active backdoor attack of the BCI system and includes a multi-channel preference method to select the electrode channels sensitive to the target task. Ultimately, the effectiveness of the comparison and ablation experiments is validated on the publicly available BCI competition datasets. The results show that the average attack success rate and clean sample accuracy of Spatialspectral-Backdoor in the BCI scenario are 97.12% and 85.16%, respectively, compared with other backdoor attack methods. Furthermore, by observing the infection ratio of backdoor triggers and visualization of the feature space, the proposed Spatialspectral-Backdoor outperforms other backdoor attack methods.
KW - Backdoor attack
KW - Brain–computer interfaces
KW - Deep neural networks
KW - Electroencephalogram
UR - http://www.scopus.com/inward/record.url?scp=85210010201&partnerID=8YFLogxK
U2 - 10.1016/j.neucom.2024.128902
DO - 10.1016/j.neucom.2024.128902
M3 - Article
AN - SCOPUS:85210010201
SN - 0925-2312
VL - 616
JO - Neurocomputing
JF - Neurocomputing
M1 - 128902
ER -