Validated defence against Temporal Desynchronization Attacks

Develop a principled, validated defence against Temporal Desynchronization Attacks (TDA) in event-locked P300, SSVEP, and motor-imagery brain-computer-interface paradigms without reopening the attack surface through wider acceptance windows or degrading benign classification accuracy.

Background

Temporal Desynchronization Attacks exploit the event-locking assumption of several BCI paradigms by shifting EEG epochs so that class-defining features fall outside the model’s receptive field. The paper reports that existing mitigations, including overlapping windows, multi-scale temporal pooling, and stimulus-locked integrity checks, provide only partial protection.

The authors identify temporal alignment as a security property and state that authenticated-clock validation and rejection of epochs lacking confirmed stimulus locking are currently immature. They characterize the absence of a validated defence against TDA as the clearest open problem exposed by their analysis.

References

We stress that the fourth is the least mature: as noted above, no validated defence against TDA currently exists, and this is the clearest open problem the NERVE analysis exposes.

NERVE Attacks: Breaking AI-Powered Brain-Computer Interfaces  (2609.08971 - Tarkhani et al., 8 Sep 2026) in Section 6, Potential Defenses, subsection “Design principles for BCI vendors”