The Problem: Unencrypted IoT and Stolen Credentials

▶ Watch (9:58)

The Colonial Pipeline ransomware attack caused gasoline shortages across the U.S. It showed that cyber attacks on industrial control systems physically impact millions. The 2015 BlackEnergy attack on Ukraine’s power grid left 230,000 people without electricity. One study showed that 98% of IoT traffic is unencrypted. These systems rely on weak or default passwords. The traditional CIA triad is inverted: availability comes first, privacy last.

Why Fingerprints and Passwords Fall Short

▶ Watch (12:07)

Passwords can be brute-forced or phished. Biometrics like fingerprints and facial recognition can be replicated with deepfakes or lifted prints. Once a biometric is compromised, it cannot be revoked. EEG authentication offers liveness detection: brain signals stop at death. It is coercion-resistant because stress alters brain patterns. Even if forced, a user’s brain will not produce the expected signature. The system can be revoked by changing the cognitive task.

From Raw EEG to a Gaussian Mixture Model

▶ Watch (29:55)

Raw EEG signals are noisy. The system filters, removes artifacts like eye blinks and muscle movements, and segments the data. Features are extracted from frequency, temporal, and spatial domains. A Gaussian Mixture Model (GMM) is trained using the Expectation-Maximization algorithm. The GMM learns a multi-profile signature for each user. At authentication, the live EEG is compared to the stored model. A probability threshold determines acceptance. Success rates reach 95-99%.

Live Demo: Authenticating with a Raspberry Pi

▶ Watch (51:22)

The team connected a five-channel EEG headset to a Raspberry Pi. The Pi controlled an LED. During registration, the user watched a blank screen for 10 seconds, then a target image for 50 seconds while performing a mental task (hiding a wallet in the image). At authentication, the image was shown for 30 seconds. When the system matched the brain signal, the LED lit up. The demo confirmed the end-to-end pipeline worked on low-cost hardware.

Q&A

Does sleep deprivation or sadness affect brain waves and break authentication? Yes, brain activity changes significantly. The experiment controlled for this with a 15-minute relaxation period before testing, but it remains a constraint for time-critical systems. ▶ 45:49

Could music or other stimuli be used for users with visual disabilities? The team had not tested that yet, but agreed it is a valid alternative for visually impaired users. ▶ 46:52

Are brain wave profiles consistent over time, say 10 years? No, they change. The system would require re-enrollment after long periods, but short-term changes from stress are a bigger concern. ▶ 47:31

Notable Quotes

one study showed that 98% of IoT traffic is is unencrypted Mehmet Önder Key · ▶ 11:26

we can reset our passwords but we cannot reset our biometrics Mehmet Önder Key · ▶ 25:04

brain waves are inherently difficult to imitate or capture in today’s environment Mehmet Önder Key · ▶ 26:36

the brain’s electrical activity is incredibly sensitive to an individual emotional and cognitive states Mehmet Önder Key · ▶ 23:03

Key Takeaways

  • EEG authentication provides liveness detection and coercion resistance that passwords and fingerprints cannot match.
  • The system uses Gaussian Mixture Models to create a unique, revocable biometric from a user’s brain activity during a cognitive task.
  • A five-channel consumer EEG headset and a Raspberry Pi can authenticate users with 95-99% accuracy in under a minute.

About the Speaker(s)

Mehmet Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to Burkut, Ogrit, Ravenailabs and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.