QIF-T0019
mediumUniversal adversarial perturbation (UAP)
Tier 3 — Demonstrated (Lab-proven)
Legacy status: DEMONSTRATED
Single perturbation pattern that fools BCI decoder regardless of input. Works across subjects and sessions. Pre-computed offline, applied in real-time. Lower sophistication than targeted attacks.
Technique Details
- Tactic
- QIF-M.SV
- Status
- DEMONSTRATED
- Bands
- S1, S2
✚ Therapeutic Application
Single perturbation vector effective against any input sample to a BCI classifier
Neural Impact
2 of 7 neural bands affected
Drag to rotate. Click a region to learn more.
Click or hover over a glowing region to see the attack techniques targeting it and their severity.
Scoring
NISS:1.1/BI:L/CR:H/CD:H/CV:I/RV:P/NP:N CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L Governance
Neurorights at Risk
This technique threatens 3 of the 4 proposed neurorights (Ienca & Andorno, 2017).
FDORA §3305 Compliance
- ! CVSS partially captures risk; neural dimensions missing
Population Vulnerability
CRB vulnerability adjustment (γ=0.30) accounts for age, diagnosis severity, consent capacity, and device dependency.
| Population | NISS Base | Adjusted | Severity | Delta |
|---|---|---|---|---|
| Adult (Default) | 5.4 | 5.4 | Medium | - |
| Child (10yr) + ADHD | 5.4 | 6.4 | Medium | +0.95 |
| Adult with ALS | 5.4 | 6.3 | Medium | +0.87 |
Validation Status
Theoretical / Not yet validated. This technique has not been independently tested. See the validation dashboard for what has been tested.