Tech4Humanity AtlasGround ZeroCurrent ThemesFuture ResearchGalleryLive Q&ASearch

Biological & Neural Integrity / Neurosecurity

SUB-T05-025 · Evidence — SEEDED / PARTIAL — defensible non-empirical baseline; validation and replayable search outstanding

BCI Threat Modelling

1. Hypothesis

A transparent, safety-bounded and person-centred approach to bci threat modelling, combining validated measurement, informed consent, privacy and security controls, human oversight and longitudinal monitoring, will improve benefit–risk outcomes compared with opaque or technology-centred approaches.

2. Experiment design

Design: adversarial neurosecurity assurance programme combining laboratory testing, simulated compromise and operational recovery exercises focused on BCI Threat Modelling Methods: cybersecurity threat modelling; penetration testing; signal spoofing simulation; adversarial input testing; device-failure analysis; red-team exercises; incident-response drills; expert and affected-user review; reproducibility testing; methods adapted specifically to BCI Threat Modelling Independent variables: technology type; exposure or intervention intensity; duration; assurance controls; human oversight; user characteristics; operating context Dependent variables: functional outcome; biological or neural safety; user agency; privacy; reliability; recovery; subtopic-specific outcome for systematic identification of assets, actors, attack paths and consequences in BCI systems Confounders: age; health; disability; medication; prior experience; baseline physiology; environment; device quality; clinician or operator expertise; socioeconomic access Measures: attack success rate; detection latency; signal integrity; device availability; safety impact; recovery time; residual risk; patch effectiveness; validated subtopic measures for systematic identification of assets, actors, attack paths and consequences in BCI systems; subgroup effects; false-positive and false-negative rates; user-reported burden Success criteria: Statistically and clinically or practically meaningful benefit; acceptable adverse-event profile; preserved agency and privacy; no disproportionate subgroup harm; reproducible performance; explicit safety limits; effective recovery and human escalation. Failure conditions: No meaningful benefit; biological, neural, psychological, privacy or rights harm exceeds benefit; performance fails outside narrow conditions; unsafe dependency emerges; consent or refusal is compromised; incidents cannot be detected, reversed or remediated.

3. Seed result / current evidence

DEFENSIBLE SEED RESULT — NON-EMPIRICAL. The current evidence supports BCI Threat Modelling as a testable research proposition. Problem basis: Connected neurotechnology introduces attack surfaces that can affect confidentiality, device behaviour, physiological safety, identity and trust. The specific unresolved issue is systematic identification of assets, actors, attack paths and consequences in BCI systems. Directional expectation: If supported, the proposed approach should improve functional outcome; biological or neural safety; user agency; privacy; reliability; recovery; subtopic-specific outcome for systematic identification of assets, actors, attack paths and consequences in BCI systems while reducing adverse effects, misuse, exclusion, dependency and recovery time. Proposed observations: attack success rate; detection latency; signal integrity; device availability; safety impact; recovery time; residual risk; patch effectiveness; validated subtopic measures for systematic identification of assets, actors, attack paths and consequences in BCI systems; subgroup effects; false-positive and false-negative rates; user-reported burden. Seed data profile: Evidence Strength 10/100; Confidence 25/100; Maturity 20/100; Overall Health 35/100; Novelty 80/100; Strategic Importance 95/100. Evidence boundary: No validated results yet.; experiments 0, studies 0, participants 0. This is suitable for protocol formation and baseline comparison, not as a finding of effect.

4. Seed conclusion

DEFENSIBLE SEED CONCLUSION — PROVISIONAL. BCI Threat Modelling warrants structured testing because the CSV identifies a defined problem, falsifiable hypothesis, measurable outcomes and relevant literature foundations. The present position is that “A transparent, safety-bounded and person-centred approach to bci threat modelling, combining validated measurement, informed consent, privacy and security controls, human oversight and longitudinal monitoring, will improve benefit–risk outcomes compared with opaque or technology-centred approaches.” is plausible and decision-relevant, but unvalidated. Proceed to controlled testing against the stated success and failure conditions. Confirm, narrow or reject this seed after effect sizes, uncertainty, subgroup outcomes, adverse effects, persistence and handback performance are observed.

Prior-art search performed before starting

PRIOR-ART SEED BASELINE — PARTIAL. The CSV records these literature domains: Neuroscience; neurotechnology; physiology; medical-device safety; rehabilitation; cybersecurity; bioethics; human rights; literature specific to BCI Threat Modelling. It also records: NIST Cybersecurity Framework — https://www.nist.gov/cyberframework; FDA medical-device cybersecurity guidance — https://www.fda.gov/; CISA medical-device security resources — https://www.cisa.gov/; MITRE ATT&CK — https://attack.mitre.org/. Evidence register status: “Seeded; authoritative source register initiated; empirical evidence not yet ingested”. This is defensible as a starting prior-art inventory, but not as proof of a completed systematic search because search dates, databases, exact queries, reviewer, result counts, screening decisions, claim mapping and a replayable receipt are absent.

Prior-art material named: Existing literature: Neuroscience; neurotechnology; physiology; medical-device safety; rehabilitation; cybersecurity; bioethics; human rights; literature specific to BCI Threat Modelling. References: NIST Cybersecurity Framework — https://www.nist.gov/cyberframework; FDA medical-device cybersecurity guidance — https://www.fda.gov/; CISA medical-device security resources — https://www.cisa.gov/; MITRE ATT&CK — https://attack.mitre.org/

Critical gap / next action

Create and attach a dated prior-art search log; lock the protocol; execute the proposed study; link raw data and analysis; then replace the results and conclusion placeholders with evidence-bounded findings.

Evidence classification: SEEDED / PARTIAL — defensible non-empirical baseline; validation and replayable search outstanding — provisional research record, not a validated finding.