EEG Foundation Model Attribute Leakage
Abstract
EEG foundation-model releases are usually audited one endpoint at a time: raw-reconstruction, membership inference, identity linkage, or DP-SGD on the downstream head. We audit the same released embeddings under all four endpoints jointly, on BIOT, LaBraM, and EEGPT, and show that each single-endpoint audit clears releases that still leak spectral attributes. The decisive evidence is a cross-encoder transfer audit: a single ridge attribute decoder learned from one frozen encoder transfers, via a fitted linear bridge, to held-outsubject test splits of every other encoder, with subject-disjoint matched-control 95% CI lower bound at least 0 _._ 081 across all six BIOT/LaBraM/EEGPT directions. We prove a sufficient conditiontwo encoders sharing a nontrivial attributecoordinate projector overlap __ admit a chained ridge bridge attacker with centered-gain lower bound ~~~~ _/_ (1 + _t_[2][)] _[] _ br _ _ 0and back-solve _ _ [0 _._ 008 _,_ 0 _._ 198]. To turn the joint audit into a deployment-readable decision rule we introduce an audit-endpoint disagreement score (AEDS), prove sufficient conditions for its positivity, and bootstrap-calibrate it per cell; AEDS is positive in all eight matched-CI cells (BIOT/LaBraM/EEGPT on EEGMMI; LaBraM on SleepEDF, 54-channel LIMO, CHB-MIT pediatric scalp EEG) with _p <_ 0 _._ 001, while a head-level Carlini LiRA membership audit reaches AUC only 0 _._ 500 _._ 70. Standard defenses fail under audit: a Wiener-style noise-aware adaptive attacker, the LiRA audit, and DP-SGD at every utility-preserving _ {_ 4 _,_ 8 _}_ leave the attribute channel essentially unchanged. The contribution is an audit framework that turns scattered singleendpoint defenses into a joint release decision, supported by a cross-encoder bridge theorem and adaptive-attacker, LiRA, and DP-SGD baselines; the audit licenses release-blocking, not raw-waveform exfiltration or held-out-subject identity recovery.