BrainGuard: Cybersecurity for Neurotechnologies
30 min

Brain-computer interfaces can detect neural signals and translate them into commands for technical systems. Neuromodulatory implants can even directly influence neural processes through electrical stimulation. Neurotechnologies therefore open up new possibilities in medicine and rehabilitation – but at the same time, they introduce a new dimension of cybersecurity.
Where technical systems interact directly with the human nervous system and process highly sensitive neural data, traditional IT security concepts alone are no longer sufficient.
This is precisely where the BrainGuard research project comes in. Together with partners from neuroscience, IT security, and industry, PHYSEC is investigating how brain-computer interfaces and other neurotechnologies can be developed and operated securely from the ground up. The goal is to establish a systematic approach to neuro-cybersecurity.
As humans and technology become increasingly interconnected
Neurotechnologies have advanced significantly in recent years. Brain-computer interfaces, or BCIs, can detect neural activity and enable direct communication between the brain and technical systems. This creates new possibilities, for example, for people with severe motor impairments.
Other technologies go one step further. Neuromodulatory systems can not only read neural signals but also actively influence brain processes through electrical stimulation. One well-known medical application is deep brain stimulation.
However, the more closely such devices are connected to the human nervous system, the more important their security becomes.
A cyberattack on a conventional connected device can already have serious consequences. In a neurotechnology system, particularly sensitive information may also be at risk. Neural data can potentially reveal personal and highly private characteristics or states. In systems that actively provide stimulation, it is also essential to prevent unauthorized parties from manipulating functions or parameters.
Cybersecurity therefore becomes a prerequisite for the safe and trustworthy use of neurotechnologies.
BrainGuard is developing a systematic approach to neuro-cybersecurity
The BrainGuard research project therefore goes beyond investigating individual security mechanisms. Its goal is to develop a comprehensive approach that takes the specific characteristics of neurotechnology systems into account.
The project examines security across multiple layers. These include methods for identification and authorization, privacy-preserving handling of neural data, and protective measures against attacks on hardware and software. In addition, encryption, authentication, and monitoring methods are to be developed specifically for implantable and connected neurotechnologies.
BrainGuard thus follows a security-by-design approach: security should not be added as an afterthought but should be an integral part of the development of neurotechnology systems.
Neural data raises new questions for data privacy
A particular challenge lies in the nature of the information being processed.
In many digital applications, it is possible to clearly define which personal data is required. Neural signals, however, are more complex. A system may require information derived from brain activity for a specific medical function, while the same raw data may contain additional information that is entirely irrelevant to that purpose.
BrainGuard is therefore investigating how neural data can be processed in a way that ensures, as far as possible, that only the information actually required for the respective application is used. Additional highly personal information should not be unintentionally disclosed in the process.
This expands the traditional question of data privacy. It is no longer only about who is granted access to data, but also about what information can and should be extracted from neural data in the first place.
Cybersecurity meets ethics and regulation
In neurotechnology, technical questions cannot be fully separated from ethical and regulatory considerations.
Concepts such as mental privacy, neural integrity, and individual autonomy become increasingly important when technologies are capable of obtaining information directly from neural activity or influencing it. At the same time, existing legal frameworks are not yet specific enough to fully address these emerging challenges.
BrainGuard therefore combines technical, regulatory, and ethical perspectives. The research is intended not only to produce concrete security mechanisms but also to establish a scientific foundation that can inform future standards and guidelines for secure neurotechnologies.
Interdisciplinary research in Bochum
To address these questions, BrainGuard brings together expertise from multiple disciplines.
The project is being carried out by the research groups led by Prof. Dr. Christian Klaes and Prof. Dr. Christian Zenger at Ruhr University Bochum, together with PHYSEC and snap DISCOVERY. It is funded for three years under the ERDF programme by the State of North Rhine-Westphalia and the European Union.
The KlaesLab conducts research into brain-computer interfaces and neurotechnologies, among other areas. The Secure Mobile Networking research group investigates the security of connected and cyber-physical systems. snap DISCOVERY is developing an AI-powered brain-computer interface. PHYSEC contributes its expertise in securing connected and cyber-physical systems to the project.
This combination of expertise is particularly important for BrainGuard. Secure neurotechnologies require both an understanding of neural systems and expertise in communications, cryptography, hardware and software security, and cyber-physical security.
Why BrainGuard matters for the future of cybersecurity
BrainGuard illustrates how the boundaries of traditional IT security are shifting.
As connectivity increases, cybersecurity is no longer limited to protecting files, servers, or corporate networks. Digital technologies control machines, energy infrastructure, vehicles, and medical devices. With neurotechnologies, this development extends all the way to the direct interface between technical systems and the human nervous system.
As a result, the requirements placed on security concepts are also increasing.
Systems must not only be protected against unauthorized access. It must also be ensured that data is processed reliably, that devices cannot be manipulated, and that only the information actually required for a particular application is collected and analyzed.
For PHYSEC, BrainGuard therefore represents a core principle of cyber-physical security: The more closely digital technologies are connected to the physical world and to people, the earlier security must become an integral part of their development.
The research project is creating new scientific and technical foundations for this purpose – with the goal of making neurotechnologies not only more powerful, but also secure and trustworthy.