Deployment-oriented compression is attractive for resource-constrained brain--computer interfaces (BCIs), but whether it changes adversarial vulnerability remains unclear. On BCI Competition IV-2a, we compare 32-bit floating-point (FP32) EEGNet and ShallowConvNet models with global magnitude pruning and simulated INT8 post training quantization (PTQ) and quantization-aware training (QAT) across nine subjects and three seeds. Simulation provides differentiable quantize--dequantize models for white-box attacks and gradient analysis, while native TensorRT deployment is used for validation. Accuracy-preserving compression does not improve direct robustness: at ε=0.005, EEGNet PGD accuracy remains 22--24% across FP32, 50% pruning (P50), PTQ, and QAT. However, P50 reduces bidirectional transfer efficiency to 0.963/0.928 (FP32→P50/P50→FP32), versus 0.994/0.997 for PTQ; the same trend holds for ShallowConvNet. Gradient alignment shows a corresponding separation, while native PTQ agrees with simulated clean/adversarial predictions in 95--98% of cases. These results show that direct robustness, adversarial transfer, and deployment efficiency are distinct properties of compressed EEG decoders.
Figures & tables
Figure 1 : Full Methodology uncovering AERIAL’s evaluation pipeline
Arch.
Variant
Clean
PGD
EEGNet
FP32
57.39
22.83
P30
57.47
23.06
P50
58.38
23.60
P70
25.96
24.01
PTQ8
57.42
22.57
QAT8
57.45
22.52
Table 1 : Clean and direct PGD accuracy (%) at ϵ=0.005 . P70 represents over-compression rather than a robust operating point.
Arch.
Direction
.001
.005
.01
Δ pp
pH
EEGNet
FP32 → P50
.921
.963
.980
1.22
.0156
P50 → FP32
.897
.928
.964
2.47
.0156
FP32 → PTQ
.981
.994
.999
0.21
.0313
PTQ → FP32
1.004
.997
1.000
0.09
.0938
Shallow
FP32 → P50
.914
.897
.918
1.57
.0156
P50 → FP32
.882
.904
.912
1.48
.0156
Table 2 : Transfer efficiency (TE) across shared PGD budgets. Δ and pH are reported at ϵ=0.005 ; Δ>0 denotes weaker transfer than direct PGD.
Metric
EEGNet
Shallow
Clean acc., sim./native (%)
59.22 / 58.99
58.37 / 57.45
PGD acc., sim./native (%)
27.58 / 27.78
42.36 / 42.90
Clean agreement (%)
97.42
94.91
PGD agreement (%)
97.84
94.98
Table 3 : Native TensorRT PTQ fidelity. Accuracy and prediction agreement are means over nine subjects using seed 1.
Electroencephalography (EEG) is a cornerstone of brain-computer interfaces and clinical neuroscience, yet deep learning models are typically trained and evaluated under a single, unreported preprocessing pipeline. We formalize preprocessing choices as a counterfactual intervention space and show that EEG predictions are surprisingly unstable under this space: across six datasets spanning four paradigms, up to 42% of trial-level predictions flip when only the preprocessing changes, a variability that standard uncertainty methods do not explicitly quantify because they condition on a fixed preprocessing pipeline. We provide three tools to make this instability measurable, decomposable, and reducible. First, a Walsh-Hadamard decomposition of the 2^7 pipeline space reveals that sensitivity is near-additive in practice under the binary intervention design, enabling efficient step-by-step optimization. Second, we introduce Preprocessing Uncertainty (PU), a per-trial diagnostic that captures a dimension of instability complementary to model-based confidence. Third, we study Normalized Adaptive PGI (NA-PGI), a graph-structured regularizer that exploits the compositional structure of preprocessing interventions as one mitigation strategy with clear scope conditions.
Dengzhe Hou, Zihao Wu, Lingyu Jiang +3
Tohoku University · University of Georgia · Texas A&M University +1
This work investigates whether Electroencephalograph (EEG) foundation models (EFMs) can be made faster and locally deployable without sacrificing accuracy. EEG foundation models are a major trend, offering strong general-purpose representations. However, their computational burden grows quadratically with input length, hindering deployment on resource-constrained scenario, particularly for real-time clinical monitoring. EEG's low SNR further suggests many of these tokens are redundant and compressible with little accuracy cost. We propose ZIPBrain, a novel redundancy-aware EEG token pooling module that leverages this low-SNR characteristic to reduce token count. Given a token sequence, ZIPBrain partitions tokens into redundant and unique groups, then merges each redundant token with its most similar counterpart in the unique group. Furthermore, ZIPBrain serves as a training-free, plug-and-play module that seamlessly integrates into standard Transformer encoders with negligible computational overhead. Extensive experiments across multiple EEG foundation models show ZIPBrain's strong versatility, achieving 1.3%-10.5% average improvement over baselines, while reducing wall-clock inference time by 32.7% (up to 41.8% with CUDA Graph) compared to the original EEG foundation models.
Lingwei Li, Yirong Kan, Peng Chen +3
Nara Institute of Science and Technology, Nara, Japan · RIKEN Center for Computational Science, Hyogo, Japan · University of Illinois Urbana-Champaign, USA +1
As demands for resource efficiency and safety in modern neural networks intensify, substantial research effort has gone into model compression and adversarial robustness. Yet despite progress on each in isolation, a systematic understanding of how compressibility shapes robustness remains elusive. In this paper, we develop a principled framework to analyze how different forms of structured compressibility - such as neuron-level and spectral compressibility - affect adversarial robustness. We show that structured compressibility can induce a small number of highly sensitive directions in the representation space, which adversaries can exploit to construct effective perturbations. Our analysis yields a robustness bound that reveals how neuron and spectral compressibility impact ℓ∞ and ℓ2 robustness via their effects on the learned representations. Crucially, the vulnerabilities we identify arise irrespective of how compressibility is achieved - whether via regularization, architectural bias, or learning dynamics. Through empirical evaluations across synthetic and realistic tasks, we confirm our theoretical predictions, and further demonstrate that these vulnerabilities persist under adversarial training and transfer learning, and contribute to the emergence of universal adversarial examples. Our findings show a fundamental tension between structured compressibility and robustness and highlight new pathways for designing models that are efficient and safe.
Melih Barsbey, Antônio H. Ribeiro, Umut Şimşekli +1
Department of Computing, Imperial College London, UK · Department of Information Technology, Uppsala University, Sweden · INRIA, CNRS, Département d’Informatique de l’Ecole Normale Supérieure / PSL, France