BCI-LLM Brain-Prompt Injection

Arxiv pdf 2025-12-08T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

BCI-to-agent pipelines turn decoded neural activity into an authorization channel for tool-use agents, exposing a new attack surface we call brain-prompt injection : signal-side perturbations, context-only injections, and adaptive dualdecoder attacks can all change the routed action while EEGside or text-side monitors remain blind. Route safety in this stack depends on what the audit log can observe, not on decoder accuracy or agreement alone. We define a Route-Safety Audit Contract: a minimal log schema, denominator hierarchy, and endpoint specification, and prove an audit-schema separation theorem together with a C3 attacked-dependence decomposition; clean agreement and marginal robustness do not identify the joint term that controls C3 routing. As a calibration layer on top of the contract, we apply split-conformal calibration to a non-oracle EEG confirmation channel and report the resulting false-accept frontier under an explicit threat-archetype matrix. We instantiate the contract on EEGMMI native left/right command-control over 5,400 events, harmless tool stubs, and seed/case denominators. Provenance blocks C2 routes (0 _._ 000); agreement-plus-provenance routes C3 flips (1 _._ 000); confirmation-plus-provenance routes them (0 _._ 000). The conformal frontier reaches FAR 0 _._ 000 at clean utility 0 _._ 150 for __ = _._ 005 and FAR 0 _._ 119 at clean utility 0 _._ 452 for __ = _._ 10 under acquisition isolation; an attackercontrollable confirmation channel breaks the bound to __ 1. Subject-cluster bootstrap confirms these intervals on 60 subjects; cross-architecture (TinyEEGNet, EEGNetV4) and capacity-sweep results show within-regime saturation. Mediation and confirmation reduce risk; they are not intent certificates.

Loading executive summary...

LINK COPIED TO CLIPBOARD