Transfer of backdoor defences to EEG foundation models

Determine whether Fine-Pruning and Neural Attention Distillation (NAD) transfer effectively to EEG foundation models, including BIOT, LaBraM, and EEGPT, for mitigating embedded backdoors.

Background

The paper surveys model-signing, trigger-detection, activation-analysis, and backdoor-mitigation techniques, including Fine-Pruning and NAD. It notes that recent work indicates that backdoors can persist after many such defences and that modified triggers may reactivate them.

The authors specifically identify an unresolved transfer question for large EEG foundation models. The issue matters because the paper’s experiments primarily evaluate EEGNet and DeepSleepNet, whereas BIOT, LaBraM, and EEGPT represent larger foundation-model architectures with potentially different representations and backdoor behaviours.

References

Whether Fine-Pruning and NAD transfer to foundation models (BIOT, LaBraM, EEGPT) is unknown.

NERVE Attacks: Breaking AI-Powered Brain-Computer Interfaces  (2609.08971 - Tarkhani et al., 8 Sep 2026) in Section 6, subsection “Embedded Backdoors”