I Can See Your Brain: Investigating Home-Use Electroencephalography System Security

被引:23
|
作者
Xiao, Yinhao [1 ]
Jia, Yizhen [1 ]
Cheng, Xiuzhen [1 ]
Yu, Jiguo [2 ,3 ,4 ]
Liang, Zhenkai [5 ]
Tian, Zhi [6 ]
机构
[1] George Washington Univ, Dept Comp Sci, Washington, DC 20052 USA
[2] Qilu Univ Technol, Shandong Acad Sci, Sch Comp Sci & Technol, Jinan 250353, Shandong, Peoples R China
[3] Natl Supercomp Ctr Jinan, Shandong Comp Sci Ctr, Jinan 250014, Shandong, Peoples R China
[4] Qufu Normal Univ, Sch Informat Sci & Engn, Rizhao 276826, Shandong, Peoples R China
[5] Natl Univ Singapore, Sch Comp, Singapore, Singapore
[6] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
关键词
Electroencephalography; inference algorithms; Internet of Things (IoT); machine learning; security; EEG; HEALTH;
D O I
10.1109/JIOT.2019.2910115
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Health-related Internet of Things (IoT) devices are becoming more popular in recent years. On the one hand, users can access information of their health conditions more conveniently; on the other hand, they are exposed to new security risks. In this paper, we presented, to the best of our knowledge, the first in-depth security analysis on home-use electroencephalography (EEG) IoT devices. Our key contributions are twofold. First, we reverse-engineered the home-use EEG system framework via which we identified the design and implementation flaws. By exploiting these flaws, we developed two sets of novel easy-to-exploit PoC attacks, which consist of four remote attacks and one proximate attack. In a remote attack, an attacker can steal a user's brain wave data through a carefully crafted program while in the proximate attack, the attacker can steal a victim's brain wave data over-the-air without accessing the victim's device on any sense when he is close to the victim. As a result, all the 156 brain-computer interface (BCI) apps in the NeuroSky App store are vulnerable to the proximate attack. We also discovered that all the 31 free apps in the NeuroSky App store are vulnerable to at least one remote attack. Second, we proposed a novel deep learning model of a joint recurrent convolutional neural network (RCNN) to infer a user's activities based on the reduced-featured EEG data stolen from the home-use EEG IoT devices, and our evaluation over the real-world EEG data indicates that the inference accuracy of the proposed RCNN is can reach 70.55%.
引用
收藏
页码:6681 / 6691
页数:11
相关论文
共 50 条
  • [1] Home-use tests for HIV can be inaccurate
    不详
    LABORATORY MEDICINE, 1999, 30 (08) : 500 - 500
  • [2] I can see your halo
    Lockwood, Katie
    Mughal, Avad
    BMJ-BRITISH MEDICAL JOURNAL, 2023, 381
  • [3] Home-use tests for HIV can be inaccurate, FTC warns
    不详
    BIOTECHNIC & HISTOCHEMISTRY, 1999, 74 (04) : 220 - 220
  • [4] I Can See Tomorrow in Your Ludomusicology
    Smith, Jacob
    JOURNAL OF THE ROYAL MUSICAL ASSOCIATION, 2018, 143 (02) : 483 - 488
  • [5] Home-use pulse signal instrument system design
    Liu, Q.
    Gao, L.
    Yang, G.
    Wuhan Gongye Daxue Xuebao/Journal of Wuhan University of Technology, 2001, 23 (04): : 48 - 50
  • [6] Reverse effect of home-use binaural beats brain stimulation
    Michal Klichowski
    Andrzej Wicher
    Agnieszka Kruszwicka
    Roman Golebiewski
    Scientific Reports, 13
  • [7] Reverse effect of home-use binaural beats brain stimulation
    Klichowski, Michal
    Wicher, Andrzej
    Kruszwicka, Agnieszka
    Golebiewski, Roman
    SCIENTIFIC REPORTS, 2023, 13 (01)
  • [8] I CAN SEE YOUR HOUSE FROM HERE
    McGarry, Jean
    YALE REVIEW, 2019, 107 (03): : 109 - 120
  • [9] I can see your halo, halo, halo
    Woods, Paul
    NATURE ASTRONOMY, 2017, 1 (03):
  • [10] PERSONAL HANDY PHONE SYSTEM TERMINAL DESIGN FOR HOME-USE
    TANDA, T
    ADACHI, H
    AKAZAWA, N
    NAKAMURA, Y
    NTT REVIEW, 1995, 7 (01): : 67 - 73