Jasmeet Singh Bindra
Here's an uncomfortable finding: a formal math certificate can promise a brain-signal model is robust while the model quietly falls apart. At one perturbation level, an EEGNet classifier's accuracy dropped by nearly 26% under attack, yet the Lipschitz-style certificate still declared it safe for every subject tested. The proof held; the behavior didn't.
The authors call this one flavor of a bigger problem, where training goals drift from what users need, and lay out an audit framework covering three failure modes: certificates that pass while performance rots, task-tuned representations that damage the neural signal, and public embeddings that still leak private facts, like subject identity, recoverable at 48% versus a 7% chance rate. The verification gap showed up across several decoders, so it isn't an artifact of one architecture.
Their point, from the abstract: operational safety needs auditing, not certificate-trust alone. See the paper for the full test setup.
Formal robustness certificates for embedded neural-interface models can pass while task accuracy collapses: at perturbation budget e=0.25, EEGNet classification accuracy drops by 25.7% under projected-gradient attack while the Lipschitz-style certificate remains valid for all 9 tested subjects. We argue that this gap between mathematical certification and operational safety is one instance of a broader alignment failure in neural interfaces, where training objectives diverge…
Wavelet Scattering Transform for Interpretable Schizophrenia Biomarker Discovery and Classification from Resting-State EEG
arXiv (BCI) · July 4, 2026EEG-Based Imagined Speech Decoding Using a Hybrid CNN-SNN Architecture
arXiv (neural decoding) · July 3, 2026Rethinking Brain Decoding with CLIP: The Role of Adversarial Robustness
arXiv (BCI) · July 3, 2026Stacked LoRA for Subject-Adaptive EEG Foundation Models in Motor Imagery Decoding