Brain-computer interfaces (BCIs) offer a direct link between the grey matter of our human brains and silicon and circuitry of computers. New technologies always bring with them new security threats, but with the human brain a single store of the most sensitive and private information it's possible to imagine, the security stakes couldn't be higher.
If we're soon to be plugging computers directly into our brains, how can we protect that connection from those who want to attack them?
The first wave of brain-computer interfaces are beginning to make their way onto the market, offering users a way of keeping tabs on theirstress levels, control apps, and monitor their emotions. BCI tech is also progressing outside the consumer area, with medical researchers using them to help those with spinal injuries to move paralysed limbs andrestore a lost sense of touch.
SEE: Managing AI and ML in the enterprise 2020: Tech leaders increase project development and implementation (TechRepublic Premium)
Ultimately, BCIs could offer a way of communicating thoughts a form of human-machine telepathy.
So why would someone want to hack a BCI?
Being able to read the thoughts or memories of a political leader, or a business executive, could be a huge coup for intelligence agencies trying to understand rival states, or for criminals looking to steal commercial secrets or for blackmail. There's a military angle too; the US is already looking at BCIs as a way of controlling fleets of drones or cyber defences far more effectively than is now possible being able to hack into those systems would create a huge advantage on the battlefield.
The consequences of an attack or data breach from a BCI could be an order of magnitude worse than other systems: leaked email logs are one thing, leaked thought logs are another. Similarly, the risks of ransomware become far greater if it's targeted at BCIs rather than corporate systems; making it impossible to use a PC or a server is one thing; locking up the connection between someone's brain and the wider world could be far worse.
BCIs could ultimately become an authentication mechanism in their own right: our patterns of brain activity are so unique they could ultimately be used as a way of permitting access to sensitive systems, which could make it worthwhile to try to copy them. "Attempts to trick such a biometric will likely be very difficult, because brainwaves are not visible (like other biometrics like a fingerprint, iris, etc.) and cannot be replicated by another person... without direct access to the person and their brain to record the person," researchers at Israel's Ben-Gurion University of the Negevwrote in a recent paper.
It's early days, but there are already some signs that security will be a key consideration. For example, researchers have already shown that BCIs could be used to get people todisclose information from their PIN numberstotheir religious convictions.
Some of the potential threats to BCIs will be carry-overs from other tech systems. Malware could cause problems with acquiring data from the brain, as well as sending signals from the device back to the cortex, either by altering or exfiltrating the data.
Man-in-the-middle attacks could also be recast for BCIs: attackers could either intercept the data being gathered from the headset and replace it with their own, or intercept the data being used to stimulate the user's brain and replace it with an alternative. Hackers could use methods like these to get BCI users to inadvertently give up sensitive information, or gather enough data to mimic the neural activity needed to log into work or personal accounts.
Other threats to BCI security will be unique to brain-computer interfaces. Researchershave identifiedmalicious external stimuli as one of the most potentially damaging attacks that could be used on BCIs: feeding in specially crafted stimuli to affect either the users or the BCI itself to try to get out certain information, showing users images to gather their reactions to them, for example. Other similar attacks could be carried out to hijack users' BCI systems, by feeding in fake versions of the neural inputs causing them to take unintended actions potentially turning BCIs into bots, for example.
Other attacks hinge on the introduction or removal of data from BCIs: introducing noise to diminish the signal-to-noise ratio, for example, and making the signal being received from the brain difficult or impossible to read. Similarly, attackers interfering with the noise cancellation of BCI systems which separates the useful brain signals from the general background fuzz could cause a denial of service: annoying if it's an entertainment system that's cracked, life-altering if it's a BCI that allows someone to walk or control a wheelchair, for example.
SEE: Scientists are using brain-computer connections to restore a lost sense of touch
Currently, while we know something about the effect of normal BCI use on the brain, we don't know how an attack on a BCI could, deliberately or inadvertently, damage the grey matter. A hijacked BCI causing disruption to the way a user's brain works sounds like a sci-fi plot, but it could certainly be possible.
"What type of damage will [an attack] do to the brain, will it erase your skills or disrupt your skills? What are the consequences would they come in the form of just new information put into the brain, or would it even go down to the level of damaging neurons that then leads to a rewiring process within the brain that then disrupts your thinking?" says Dr Sasitharan Balasubramaniam, director of research at the Waterford Institute of Technology's Telecommunication Software and Systems Group (TSSG). "It's not only at the information level, it could also be the physical damage as well," he says.
Brains of BCI users will change and adapt as they learn to use the system, in the same way as they would to fresh experiences or acquiring new skills in the course of normal life. However, BCIs' ability to cause neuroplasticity could bring with it a new level of risk. "BCIs have the potential to change the brain of the user (e.g. to facilitate motor or cognitive improvements to people with disabilities). To preserve the physical and mental integrity of the user, BCI systems need to ensure that no unauthorized person can modify their functioning," Javier Mnguez, cofounder and CSO of neurotechnology companyBitbrain, tells ZDNet.
So how can you protect such systems, particularly given the information they hold and the potentially disastrous effects? While BCIs themselves may still be relatively novel, the technologies needed to secure them likely won't be: anonymisers, security standards and protocols, antivirus, and encryption are all being suggested as means of staving off BCI attacks.
And, like any other technologies, brain-computer interfaces will need a multi-layered security approach to keep them safe, locking down each individual element of the BCI. "I don't think that the countermeasures would be individual solutions. Going forward, we need to integrate so many different things, from how signals are wirelessly sent to the interface that might be just outside the head, all the way to integrating that with the machine learning for determining whether it's the right or wrong pattern [a BCI is using], and then using that to actually deter the attacks," TSSG's Balasubramaniam says.
The level of risk in using BCIs also varies according to which type of system someone's using: a headset-based, no-invasive system will get a low-quality signal and will be easy for a user to switch off and block external communication; an invasive system, meanwhile, gathers high-quality signals direct from the brain's surface and requires surgery to disengage it fully.
"The more accurate and powerful a BCI is, the higher the risk could be," says Mnguez. A more comprehensive measurement of the brain will potentially contain more sensitive information and, therefore, requires more strict safety standards, as do devices that modify brain function. "This is especially relevant, because the target users of these systems are generally a vulnerable population, including patients with certain neurological disorders," he says.
SEE: Mind-controlled drones and robots: How thought-reading tech will change the face of warfare
What's more, many of the standards and principles of good tech security and data hygiene used in other systems can be brought across for use in BCIs: educating users, gathering only the minimum amount of data necessary for the system to work, locking down when, how and who can access the system, and so on. However, while the technology side of the equation may have good security precedents elsewhere, the unknown unknowns of the human brain could prove BCIs' greatest security challenge.
"In terms of the security of computational systems in general, this is a branch of science that is advanced enough and we probably have good enough understanding to know how to do the right thing from a technical perspective," says Tamara Bonaci, affiliate faculty member at the National Science Foundation's Center for Neurotechnology.
"What's probably a little more interesting and likely much harder is the question of, do we know enough about the brain and about the human body and electrophysiological signals. Something that may not mean very much today might be recognised as something that is revealing sensitive information about the person tomorrow," she warns.
However, the complexity of the human brain also brings good news for BCI security. Unlike other typically compromised systems like smartphones and tablets, BCIs aren't one size fits all: they require a lot of training to make them compatible with their individual user.
"That signal on the surface looks pretty much like white noise. It's very hard to discern any useful information there. You kind of have to zoom in on specific parts of the signal and know exactly what you're looking for," Bonaci says.
The rest is here:
Soon, your brain will be connected to a computer. Can we stop hackers breaking in? - ZDNet
- Systems-Based Neurotechnology for Emerging Therapies (SUBNETS) - December 8th, 2016 [December 8th, 2016]
- Backing British innovation: Royal Academy of Engineering launches ... - Elite Business Magazine - February 13th, 2017 [February 13th, 2017]
- Global Fingerprint Biometrics in the VAR Market 2016 Fulcrum Biometrics, Neurotechnology, 360 Biometrics ... - Albanian Times - February 16th, 2017 [February 16th, 2017]
- Israel and Indiana: Why You're Getting an Invitation to the Holy Land ... - 93.1 WIBC Indianapolis - February 22nd, 2017 [February 22nd, 2017]
- 5th Annual Big Idea Competition Nets Three Winners Colorado ... - Colorado College News - February 23rd, 2017 [February 23rd, 2017]
- 3Q: US Patent Office's Ruling on CRISPR - Bioscience Technology - February 24th, 2017 [February 24th, 2017]
- 7 reasons you must attend WIRED Health 2017 - Wired.co.uk - February 24th, 2017 [February 24th, 2017]
- Edward Boyden - Big Think - February 25th, 2017 [February 25th, 2017]
- What Health Care Can Learn from Wal-Mart - Wall Street Journal (subscription) (blog) - March 4th, 2017 [March 4th, 2017]
- A report released today by RBC Capital Markets about Stryker Corporation (NYSE:SYK) ups the target price to $135.00 - Breaking Finance News - March 4th, 2017 [March 4th, 2017]
- Paralysis patients achieve fastest typing yet with new brain-computer interface - The Brown Daily Herald - March 7th, 2017 [March 7th, 2017]
- How 'brain wearables' can address 21st century needs - IoT Tech News - March 7th, 2017 [March 7th, 2017]
- Stryker's AVAflex Vertebral Balloon System Receives FDA 510(k ... - OrthoSpineNews - March 8th, 2017 [March 8th, 2017]
- Stryker's Spine Division To Feature Novel 3D-Printed Spinal Implants at AAOS Conference - OrthoSpineNews - March 9th, 2017 [March 9th, 2017]
- Stryker's Spine division to exhibit key technologies at AAOS 2017 - Yahoo Finance - March 9th, 2017 [March 9th, 2017]
- Stryker Corporation named one of Fortune Magazine's 100 Best Companies to Work For for seventh consecutive year - Yahoo Finance - March 9th, 2017 [March 9th, 2017]
- How to ensure future brain technologies will help and not harm society - USAPP American Politics and Policy (blog) - March 10th, 2017 [March 10th, 2017]
- Preview: MedX Future of Healthcare conference - The Mancunion - March 11th, 2017 [March 11th, 2017]
- Stryker's Spine division to exhibit key technologies at AAOS 2017 - OrthoSpineNews - March 11th, 2017 [March 11th, 2017]
- Elon Musk Wants to Merge Man and MachineHere's What He'll ... - Observer - April 8th, 2017 [April 8th, 2017]
- Synchron Inc. Secures $10 Million in Series A Financing Round - PR Newswire (press release) - April 8th, 2017 [April 8th, 2017]
- How Neurotechnology Is Helping The San Francisco Giants Train Better - PSFK (subscription) - April 8th, 2017 [April 8th, 2017]
- Positive Media Coverage Very Likely to Affect Stryker (SYK) Share Price - Chaffey Breeze - June 6th, 2017 [June 6th, 2017]
- Shoosmiths advises PD Neurotechnology on 1.34m investment - Scottish Legal News - June 6th, 2017 [June 6th, 2017]
- Shoosmiths advises PD Neurotechnology on 1.34m (EUR) investment - Shoosmiths legal updates (press release) - June 7th, 2017 [June 7th, 2017]
- Comparing Accuray (ARAY) & Stryker (SYK) - The Cerbat Gem - June 9th, 2017 [June 9th, 2017]
- Welch Capital Partners Increased By $3.59 Million Its Eqt (EQT) Position, Stryker (SYK) Sellers Decreased By 3.59 ... - UtahHerald.com - June 10th, 2017 [June 10th, 2017]
- Head to Head Analysis: Accuray (ARAY) and Stryker Corporation (SYK) - Sports Perspectives - June 13th, 2017 [June 13th, 2017]
- Neurotechnology Announces MegaMatcher Accelerator Extreme ... - findBIOMETRICS - June 13th, 2017 [June 13th, 2017]
- Comparing Stryker Corporation (SYK) & Accuray (ARAY) - Markets Daily - June 14th, 2017 [June 14th, 2017]
- Neurotechnology Releases MegaMatcher Accelerator Extreme, the Fastest Biometric Engine in the World - PR Newswire (press release) - June 14th, 2017 [June 14th, 2017]
- Neurotech panel shares successes from first year - Cornell Chronicle - June 14th, 2017 [June 14th, 2017]
- Neurotechnology Researchers Win Kaggle Competition with Deep Neural Network Solution for The Nature ... - PR Newswire (press release) - June 14th, 2017 [June 14th, 2017]
- Neurotechnology Wins Fisheries-Focused Computer Vision Competition - findBIOMETRICS - June 14th, 2017 [June 14th, 2017]
- Helping or Hacking? Engineers, Ethicists Must Work Together on Brain-Computer Interface Technology - Government Technology - June 16th, 2017 [June 16th, 2017]
- Accuray (ARAY) versus Stryker Corporation (SYK) Head-To-Head Review - The Cerbat Gem - June 17th, 2017 [June 17th, 2017]
- The Funded: Justin Kan's latest startup gets backing from more than 100 investors - Silicon Valley Business Journal - June 17th, 2017 [June 17th, 2017]
- New SentiVeillance Server from Neurotechnology Adds Face Recognition and Analytics to Video Management Systems - PR Newswire (press release) - June 20th, 2017 [June 20th, 2017]
- Neurotechnology Announces SentiVeillance Server Facial Recognition Solution - findBIOMETRICS - June 20th, 2017 [June 20th, 2017]
- SentiVeillance Server - Face Recognition and Analytics to Video Management Systems - Officer.com (press release) (registration) (blog) - June 21st, 2017 [June 21st, 2017]
- Neurotechnology Announces MegaMatcher 10 - findBIOMETRICS - June 21st, 2017 [June 21st, 2017]
- Neurotechnology adds face recognition, tracking to video surveillance systems; researchers win competition - Biometric Update - June 22nd, 2017 [June 22nd, 2017]
- Neurotechnology makes a number of updates to the MegaMatcher product line - Biometric Update - June 23rd, 2017 [June 23rd, 2017]
- Neurotechnology Develops 3D Printing Method with Non-Contact Ultrasonic Manipulation Technology - 3DPrint.com - June 26th, 2017 [June 26th, 2017]
- Mind-blowing ultrasonic 'printer' uses lasers and high-frequency sound to assemble electronics - Digital Trends - June 29th, 2017 [June 29th, 2017]
- HIRREM Neurotechnology Better Than Placebo for Insomnia - Sleep Review - July 10th, 2017 [July 10th, 2017]
- DARPA invests further in neurotechnology - SD Times - SDTimes.com - July 14th, 2017 [July 14th, 2017]
- Infinitely Flexible 3D Printing with Ultrasonic Manipulation? - ENGINEERING.com - July 15th, 2017 [July 15th, 2017]
- Insider Activity Stryker Corporation (NYSE:SYK) - Highlight Press - July 16th, 2017 [July 16th, 2017]
- Comparing Uroplasty (UPI) and Stryker Corporation (NYSE:SYK) - The Cerbat Gem - July 17th, 2017 [July 17th, 2017]
- Biomimetic Underwater Robot Program - July 17th, 2017 [July 17th, 2017]
- Preserving the Right to Cognitive Liberty - Scientific American - July 18th, 2017 [July 18th, 2017]
- BRAIN center gathers to ponder future, direction - Arizona State University - July 20th, 2017 [July 20th, 2017]
- Stryker Expands Its Interventional Spine Segment - Market Realist - July 22nd, 2017 [July 22nd, 2017]
- Trivascular Technologies (TRIV) & Stryker Corporation (SYK) Critical Review - Stock Observer - July 26th, 2017 [July 26th, 2017]
- Arshya Vahabzadeh: Innovating at the Intersection of Brain ... - HuffPost - July 27th, 2017 [July 27th, 2017]
- fMRI and EEG May Be Able to Reveal Consciousness in Comatose Patients - Physical Therapy Products - July 29th, 2017 [July 29th, 2017]
- Stryker reports 6.1% Q2 growth, installs 26 Mako systems: 7 things to know - Becker's Orthopedic & Spine - July 29th, 2017 [July 29th, 2017]
- Tufts Hosts Engineering Conference - Tufts Now - July 29th, 2017 [July 29th, 2017]
- Stryker Corporation (NYSE:SYK) and Uroplasty (UPI) Financial Survey - Stock Observer - July 29th, 2017 [July 29th, 2017]
- Elon Musk speaks of being 'bipolar' on Twitter - Mashable - July 31st, 2017 [July 31st, 2017]
- Team Neurotechnology Innovations Translator - July 31st, 2017 [July 31st, 2017]
- Elon Musk opens up about the highs and lows of his life on Twitter - Firstpost - August 1st, 2017 [August 1st, 2017]
- Train your brain at Ky learning centre - Shepparton News - August 2nd, 2017 [August 2nd, 2017]
- Stryker Exceeded Analysts' Sales Estimates in 2Q17 - Market Realist - August 2nd, 2017 [August 2nd, 2017]
- $2.6 million to build versatile genetic toolkit for studying animal ... - Washington University in St. Louis Newsroom - August 3rd, 2017 [August 3rd, 2017]
- National Science Foundation $9M grant will fund neurotech research hub at Cornell - The Ithaca Voice - August 3rd, 2017 [August 3rd, 2017]
- NSF awards Cornell $9M grant for neurotech research hub - The Central New York Business Journal - August 4th, 2017 [August 4th, 2017]
- NSF issues awards to advance a national research infrastructure for neuroscience - National Science Foundation (press release) - August 4th, 2017 [August 4th, 2017]
- $9M Grant Will Create Neurotech Research Hub - Lansing Star - August 4th, 2017 [August 4th, 2017]
- NSF backs photonics-enabled neuroscience networks - Optics.org - August 9th, 2017 [August 9th, 2017]
- Washington University awarded $2.6 million for neurotechnology research - St. Louis Business Journal - August 9th, 2017 [August 9th, 2017]
- fMRI, EEG may detect consciousness in TBI patients - Medical Physics Web (subscription) - August 10th, 2017 [August 10th, 2017]
- Financial Analysis: Stryker Corporation (NYSE:SYK) vs. Uroplasty (UPI) - The Cerbat Gem - August 12th, 2017 [August 12th, 2017]
- In the Future, Humans Will Use Brain to Brain Communication and Download Their Memories If Elon Musk Has His Way - Newsweek - August 13th, 2017 [August 13th, 2017]
- How Elon Musk Plans to Turn Humans Into Robots - Yahoo News - August 14th, 2017 [August 14th, 2017]
- Critical Comparison: Stryker Corporation (SYK) versus Glaukos Corporation (GKOS) - TrueBlueTribune - August 21st, 2017 [August 21st, 2017]
- Early career scientists named Mong Fellows in Cornell Neurotech - Cornell Chronicle - August 21st, 2017 [August 21st, 2017]
- Could this back-pain device end need for opioids? - The Columbus Dispatch - August 21st, 2017 [August 21st, 2017]
- New technologies to diagnose and treat neurological diseases - Medical Xpress - August 22nd, 2017 [August 22nd, 2017]