The team calls the attack class NERVE Attacks. Its five dimensions are Neuro-mimetic Forgery, Evasion via Desynchronization, Replay-based Hijacking, Vein Tapping and Embedded Backdoors. The paper describes the five as orthogonal, together spanning the complete BCI stack.
To evaluate the taxonomy, the team built EEGle, an AI-assisted extensible framework for systematic BCI security analysis. The evaluation uncovered 17 novel neuro-specific attack instances and revealed what the paper calls a stealth-effectiveness spectrum unique to BCI backdoor design.
The paper also argues that generative AI lowers the barrier to entry for non-expert attackers. The team is releasing EEGle to the community for building and verifying the security of these devices. The abstract frames the risk in three terms: cognitive autonomy, mental privacy and physical safety, with scenarios ranging from neural data exfiltration to malicious control of BCI-tethered devices.