Related Experiment Videos
Evaluating multi-level membership inference risk in federated EEG learning
Taslima Khanam1, Siuly Siuly2, Kate Wang3
1Institute for Sustainable Industries and Liveable Cities, Victoria University, Melbourne, VIC, Australia. taslima.khanam@live.vu.edu.au.
Brain Informatics
|June 21, 2026
Summary
Federated learning (FL) for electroencephalography (EEG) brain-computer interfaces (BCIs) offers some privacy but requires explicit mechanisms like differential privacy (DP) to prevent sensitive data leakage from multiple attacks.
Area of Science:
- Neuroscience and Artificial Intelligence
- Focuses on the intersection of brain-computer interfaces (BCIs), electroencephalography (EEG) signal processing, and privacy-preserving machine learning techniques.
Background:
- Electroencephalography (EEG) is crucial for brain-computer interface (BCI) systems, but its neural recordings contain sensitive personal information.
- Federated learning (FL) enables collaborative training of BCI models without centralizing raw EEG data, offering a privacy-enhancing approach.
- Existing research indicates that FL models can still be vulnerable to privacy breaches via membership inference attacks (MIAs).
Purpose of the Study:
- To investigate the extent of privacy leakage in federated motor-imagery EEG (MI-EEG) classification systems when subjected to multiple types of membership inference attacks (MIAs).
- To evaluate the effectiveness of differential privacy (DP) in mitigating multi-level privacy risks within FL-based EEG systems.
- To determine the optimal balance between privacy protection and classification utility when applying DP to FL for EEG data.
Main Methods:
- Developed a federated motor-imagery EEG (MI-EEG) classification framework using two neural networks trained via per-subject FL.
- Evaluated privacy leakage using four complementary MIAs: record-level, feature-level, gradient-level, and client-identity inference.
- Applied differential privacy (DP) with varying epsilon (ε) values (1, 5, 10) to client updates during the federated training process.
Main Results:
- Standard federated learning (FL) alone provides minimal intrinsic privacy protection against the evaluated MIAs.
- Incorporating differential privacy (DP) significantly reduced attack success rates, particularly for gradient-level and client-identity inference attacks.
- Stronger DP settings (ε=1) maximized privacy but reduced classification accuracy, while moderate settings (ε=5) offered the best privacy-utility trade-off.
Conclusions:
- Federated learning (FL) is insufficient as a standalone privacy safeguard for EEG-BCI systems due to multi-level leakage risks.
- Explicit privacy-enhancing mechanisms, such as differential privacy (DP), are essential for mitigating these risks effectively.
- The findings support the development of more trustworthy and secure neural-learning technologies by highlighting the need for robust privacy measures in EEG-BCI applications.