No Brain No Gain
Mehmet Önder Key, Temel Demir, Dr Ahmet Furkan Aydogan
DEF CON 33 · Day 1 · Main Stage
Overview
This talk, "No Brain No Gain," presented by Temel Demir, Mehmet Önder Key, and Dr. Ahmet Furkan Aydogan, introduces a novel approach to authentication in Industrial Internet of Things (IIoT) and Industrial Control Systems (ICS) environments using brain waves, specifically Electroencephalography (EEG). The speakers propose an EEG-based biometric system designed to address the inherent weaknesses of traditional authentication methods and even existing biometrics, which are often susceptible to spoofing, coercion, and lack of liveness detection.

Key moments
- 0:00 Introduction and inspiration for brainwave authentication
- 2:20 Talk agenda and EEG fundamentals for authentication
- 4:00 Understanding Industrial Control Systems (ICS) and IoT
- 6:00 Failures of traditional authentication methods
- 6:50 EEG biometric superiority using Gaussian Mixture Model
- 8:00 Categorization of critical infrastructure and cyber threats
No Brain No Gain
Speakers: Mehmet Önder Key, Cyber Security Consultant (Red Teamer); Temel Demir, Cyber Security Lead, KPMG Turkey; Dr. Ahmet Furkan Aydogan, Assistant Professor, North Carolina University
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=_ENNd1XMPyk
Overview
This talk, "No Brain No Gain," presented by Temel Demir, Mehmet Önder Key, and Dr. Ahmet Furkan Aydogan, introduces a novel approach to authentication in Industrial Internet of Things (IIoT) and Industrial Control Systems (ICS) environments using brain waves, specifically Electroencephalography (EEG). The speakers propose an EEG-based biometric system designed to address the inherent weaknesses of traditional authentication methods and even existing biometrics, which are often susceptible to spoofing, coercion, and lack of liveness detection.
The core premise is that each individual's brain wave patterns are unique and dynamic, forming a distinct "mental signature" that can be leveraged for highly secure authentication. This system aims to provide a robust solution for critical infrastructure, where the compromise of authentication can lead to severe real-world consequences, from widespread service disruption to threats to national security and public safety. By utilizing advanced signal processing and machine learning models like the Gaussian Mixture Model (GMM) and Expectation-Maximization (EM) algorithm, the researchers demonstrate a proof of concept that promises a new frontier in secure identity verification.
Background
▶ Watch: Introduction and inspiration for brainwave authentication (0:00)
The increasing convergence of Internet of Things (IoT) devices with Industrial Control Systems (ICS) has introduced significant security vulnerabilities into critical infrastructure. These systems, vital for sectors like manufacturing, power generation, and water treatment, are rapidly adopting IoT for efficiency and real-time monitoring. However, this integration often comes at the cost of security, as many IIoT devices are designed with longevity and availability as primary concerns, often neglecting robust security practices. The speakers highlight that the traditional CIA triad (Confidentiality, Integrity, Availability) is often inverted to AIC (Availability, Integrity, Confidentiality) in ICS, prioritizing uptime over data protection, leading to widespread systemic weaknesses.
Common vulnerabilities in these environments include reliance on weak or default passwords, insecure network services, outdated firmware, and a pervasive lack of encryption. A staggering statistic cited in the talk reveals that 98% of IoT traffic is unencrypted, leaving nearly all data open to interception and compromise. The real-world impact of these vulnerabilities is severe, as evidenced by incidents like the 2021 Colonial Pipeline ransomware attack, which caused fuel shortages and panic, and the BlackEnergy attack on Ukraine's power grid in 2015, resulting in a blackout for 230,000 people. These events underscore that cyberattacks on critical infrastructure don't just lead to data breaches but directly impact physical processes and human safety.
Traditional authentication methods—passwords, PINs, physical tokens, and even common biometrics like fingerprints and facial recognition—are frequently circumvented. Passwords can be brute-forced, phished, or socially engineered. Biometrics, while unique, suffer from the critical flaw of potential replication; deepfakes can bypass facial recognition, and high-resolution images can be used to forge fingerprints. Furthermore, once a biometric like a fingerprint or iris scan is compromised, it cannot be revoked or reset, unlike a password. Many traditional systems also lack liveness detection, failing to verify if the authenticating entity is a living, active user, leaving them vulnerable to attacks using static replicas. This persistent threat landscape necessitates a more advanced, resilient authentication mechanism, which the EEG-based system aims to provide.
Key Findings
▶ Watch: Understanding Industrial Control Systems (ICS) and IoT (4:00)
The central finding of this research is that Electroencephalography (EEG), which captures the brain's electrical activity, offers a significantly more secure and resilient method for authentication, particularly in high-stakes environments like IIoT and ICS. The speakers demonstrate that individual brain wave patterns are not only highly unique but also dynamic, context-dependent, and inherently tied to a living, metabolically active brain.
Key contributions and findings include:
- Superior Liveness Detection: EEG signals are generated only by a living brain. This makes the system highly resistant to post-mortem acquisition or attacks using static replicas, a common vulnerability in other biometric systems.
- High Spoof Resistance: Brain electrical activity is incredibly sensitive to an individual's emotional and cognitive states. It is nearly impossible for an attacker to perfectly replicate the complex, dynamic brain wave patterns associated with a specific cognitive task. Each authentication attempt, even for the same user and task, generates slightly different but recognizable patterns, making static spoofing infeasible.
- Coercion Resistance: Studies show that states of stress, fear, or compulsion drastically alter normal brain patterns. This physiological response makes it exceedingly difficult, if not impossible, for an individual under duress to produce the expected EEG signals for successful authentication, providing an additional layer of security.
- Revocability of Biometrics: Unlike traditional biometrics, which are permanently compromised once stolen, EEG-based authentication can be "revoked" by simply changing the cognitive task required for authentication. If a specific "memory" or thought pattern used for registration is compromised, a new, different cognitive task can be assigned for re-registration.
- Probabilistic Modeling with GMM: The successful application of Gaussian Mixture Models (GMMs) combined with the Expectation-Maximization (EM) algorithm enables the system to learn and recognize the complex, unique "mental signatures" from noisy raw EEG data, transforming brain activity into a reliable biometric "padlock."
These findings collectively position EEG authentication as a promising solution that addresses critical limitations of current authentication technologies, offering enhanced security against sophisticated cyber threats in sensitive industrial and critical infrastructure contexts.
Technical Deep Dive
▶ Watch: Failures of traditional authentication methods (6:00)
The proposed EEG authentication system builds upon the fundamental understanding of brain physiology and advanced signal processing techniques. At its core, the system harnesses the unique electrical impulses generated by the brain to create a dynamic, individualized biometric.
The brain's fundamental units are neurons, billions of cells that communicate via electrical impulses. These impulses are primarily of two types: action potentials, which are fast and weak, making them difficult to capture with current EEG devices; and post-synaptic potentials, which are relatively slower and sum up from multiple neurons, making them detectable by EEG. These electrical signals are driven by chemical substances, primarily potassium (K), sodium (Na), chloride (Cl), and calcium (Ca) ions. A signal causes channels in the neuron's membrane to open, allowing positively charged ions (like sodium) to rush in, creating a brief yet powerful electrical impulse.
EEG devices are essentially highly sensitive microphones that "listen" to the collective electrical activity of the brain. Electrodes are placed on the scalp to capture these signals. An EEG electrode measures the difference in potential between two points on the scalp, rather than an absolute voltage. By mapping these patterns of potential differences, the system can precisely locate the source of electrical activity within the brain. This is a non-invasive neurophysiological method, meaning it records brain activity without penetrating the skin.
The electrical activity captured by EEG is categorized into distinct frequency bands, commonly known as brain waves, each correlated with specific mental states:
- Delta waves: Associated with deep, restorative sleep; generally not used for active authentication.
- Theta waves: Linked to drowsiness and memory processing; useful for recognizing patterns during focus and visualization tasks.
- Alpha waves: Present during relaxed wakefulness; provide unique patterns in calm and alert states.
- Beta waves: Associated with active thinking and concentration; useful for verification during active thought tasks.
- Gamma waves: Involved in higher cognitive functions and conscious awareness; indicators of complex mental processes.
By leveraging the correlation between these frequencies and a person's mental state, the system creates an authentication method that relies on both who a person is and what their brain is actively doing or thinking.
The high-level architecture for EEG-based authentication in an IoT context involves a user interacting directly with an EEG device while performing a specific cognitive activity (e.g., thinking of a memory). The raw EEG data generated is then processed by a series of algorithms and stored as a "padlock." For authentication, new EEG data (the "key") is collected during the same cognitive activity and compared against the registered padlock.
Raw EEG signals are inherently noisy and complex, necessitating a robust pre-processing pipeline:
- Filtering: Isolates relevant brain wave frequencies while removing unwanted interference (both very low and very high frequencies).
- Denoising and Artifact Removal: Systematically removes various types of noise, including biological artifacts (e.g., eye blinks, muscle movements, cardiac noise) and environmental interference (from power lines or phones). For instance, in their experiment, the first 10 seconds of recordings were removed, during which the user focused on a blank screen, to mitigate initial noise from movement or stress.
- Segmentation: Divides the continuous EEG data stream into manageable segments based on time or events, preparing it for feature extraction and model training.
After cleaning the raw data, the next step is feature extraction, transforming the cleaned EEG signals into quantifiable features for the machine learning model. This process aims to extract a unique "fingerprint" from the data, utilizing several domains:
- Frequency Domain: Measures the power or energy in particular frequency bands (e.g., Alpha, Beta).
- Temporal Domain: Analyzes patterns over time, like the specific sequence of notes in a melody.
- Sample Entropy: Quantifies the regularity and predictability of the signal.
- Spatial Domain: Examines where on the scalp the brain activity is strongest and how it spreads across the electrodes.
At the heart of the authentication system lies the Gaussian Mixture Model (GMM), coupled with the Expectation-Maximization (EM) algorithm. The GMM acts as a "smart detective" that learns the distinct "moods" or "personalities" that constitute a person's overall brain signature. It models a person's entire brain signature not as a single profile, but as a blend or mixture of several such profiles. The EM algorithm is an iterative guessing game that refines these personality profiles:
- Expectation Step: The algorithm calculates the probability that each piece of brain activity belongs to each of its currently guessed personality profiles.
- Maximization Step: It then refines its guesses for each personality profile to best fit the data, taking into account the probabilities from the previous step.
These steps are repeated until the profiles stop changing significantly, yielding the best possible set of "personality profiles" for that individual's unique brain signature.
Once trained, this personalized GMM model becomes the individual's unique biometric signature, usable in two main modes:
- "Who's this?" (1-to-N verification): The system compares a live EEG signature against a database of all registered users to identify the individual.
- "Are you who you say you are?" (1-to-1 verification): A user claims an identity, and the system compares their live EEG signature only to that specific person's registered brain ID card. This mode is ideal for logging into devices or secure areas.
The speakers also referenced a 1999 study by Greek researchers who achieved over 80% success in identifying a person using brain signals from just a single EEG channel, highlighting the long-standing potential of this technology. Their own experiments utilized a five-channel EEG device, building upon these foundational findings.
Demo / Proof of Concept
▶ Watch: EEG biometric superiority using Gaussian Mixture Model (6:50)
The demonstration showcased a practical implementation of the EEG-based authentication system, illustrating both the registration and authentication phases in an IoT context. The setup involved a user wearing an EEG headset connected to a system running the authentication software, which in turn controlled an LED connected to a Raspberry Pi device. The LED served as a visual indicator of successful authentication.
For registration (padlock generation), the user was first shown a blank screen for 10 seconds. This served as a "calm down" period to mitigate initial noise from movement or stress, ensuring cleaner baseline EEG data. Following this, the user was presented with four distinct images, each displayed for 50 seconds. The cognitive activity requested from the user was to "hide a wallet" within one of the images (e.g., in a cabinet or drawer within the picture). The system registered the user's brain waves specifically during this mental task associated with the chosen image. The intent was to create a unique mental signature for that specific memory and image combination. The system also tested against the other three images where no "wallet" was hidden, to ensure it would not authenticate under those conditions, thus verifying the specificity of the "padlock." The raw EEG data, as seen during the demo, showed five different values at each row, corresponding to the five channels of the EEG device used.
For authentication (key generation), a similar process was followed. Again, a 10-second blank screen was displayed to ease the user. Then, the specific image associated with the registered "wallet hiding" memory was shown, but this time for a reduced duration of 30 seconds to test the system's efficiency. The user was asked to recall the same cognitive activity. If the live EEG data (the "key") collected during this phase sufficiently matched the registered GMM-based "padlock," the system would authenticate the user, causing the LED connected to the Raspberry Pi to light up. This demonstrated the end-to-end functionality of using brain waves to control an IoT device.
During the Q&A, the speakers acknowledged that factors like sleep deprivation or stress could alter brain waves. While they mitigated this in experiments by having users relax, they recognized that real-world deployment would need to account for such variables, potentially through re-authentication or adaptive models. They also noted that the system, in its current form, requires the presence of the image for authentication, though they plan to explore scenarios where users could mentally replicate the image/memory without visual aid.
Defensive Implications
▶ Watch: Categorization of critical infrastructure and cyber threats (8:00)
The "No Brain No Gain" talk presents a compelling case for integrating EEG-based authentication into high-security environments, particularly within Industrial Control Systems (ICS) and Industrial Internet of Things (IIoT), which manage critical infrastructure. The defensive implications are profound, offering a significant leap in security posture against modern cyber threats.
Firstly, the system's inherent liveness detection capability directly addresses a major vulnerability in many existing biometric systems. By requiring a metabolically active brain, it effectively neutralizes attacks that rely on static replicas, deepfakes, or post-mortem acquisition of biometric data. This is crucial for critical infrastructure where human presence and intent must be unequivocally verified.
Secondly, its high resistance to spoofing and coercion provides a robust defense against sophisticated attackers. The dynamic and context-dependent nature of brain waves, coupled with their sensitivity to emotional and cognitive states, makes it exceedingly difficult for an adversary to force or imitate a user's mental signature. In high-stakes scenarios, where an operator might be physically coerced, the system's ability to detect abnormal brain patterns due to stress or fear adds an invaluable layer of protection, potentially preventing a compromised user from successfully authenticating malicious commands.
Thirdly, the concept of revocable biometrics is a game-changer. Unlike fingerprints or iris scans, which are permanently compromised once stolen, an EEG-based biometric can be reset by simply changing the cognitive task required for authentication. This flexibility allows organizations to adapt their security protocols in response to compromise, maintaining the integrity of the biometric system over time.
For organizations operating critical infrastructure, adopting such a system could significantly mitigate risks associated with:
- Stolen Credentials: The system is immune to password theft or brute-force attacks, as it bypasses traditional password mechanisms.
- Insider Threats: While not foolproof against all insider threats, the coercion resistance makes it harder for malicious actors to force an authorized user to grant access.
- Supply Chain Attacks: If integrated into device authentication, it could provide a strong verification layer for maintenance or operational access to potentially compromised IIoT devices.
While the speakers acknowledge current limitations such as user comfort, technical complexity, and cost, these are areas of ongoing research and improvement. The long-term vision is an authentication system that is highly secure, efficient, and cost-effective for resource-constrained IoT devices. Defenders in critical sectors should closely monitor the development of EEG authentication, considering its potential to provide an unparalleled level of trust in user identity and intent for the most sensitive and impactful systems.
Key Takeaways
- EEG offers superior authentication: Brain wave patterns provide a highly unique, dynamic, and context-dependent "mental signature" for authentication, surpassing traditional methods and many existing biometrics.
- Enhanced security for critical infrastructure: The proposed system is particularly valuable for IIoT and ICS, addressing systemic weaknesses like weak passwords and unencrypted traffic that plague critical infrastructure.
- Robust resistance to common attacks: EEG authentication provides high liveness detection, strong spoof resistance, and unique coercion resistance, making it difficult for attackers to bypass or force authentication.
- Revocable biometric capability: Unlike permanent biometrics, EEG authentication can be "reset" by changing the cognitive task, offering a crucial advantage in managing compromised credentials.
- Advanced ML for signal processing: The system leverages sophisticated techniques like Gaussian Mixture Models (GMM) and the Expectation-Maximization (EM) algorithm to process noisy raw EEG data into reliable biometric profiles.
- Potential for future adoption: While current comfort and cost are considerations, ongoing advancements in portable EEG devices and processing power suggest a promising future for this technology in high-security applications.
About the Speaker(s)
Temel Demir is a Cyber Security Lead at KPMG Turkey. He has a background in cybersecurity and is passionate about exploring innovative authentication methods. He was instrumental in developing the core concepts and architecture for the EEG-based authentication system presented in the talk.
Mehmet Önder Key is a Cyber Security Consultant, primarily known as a red teamer. He played a crucial role in identifying weaknesses and vulnerabilities within the proposed EEG system, ensuring a robust and resilient design. His prior work includes a Defcon 29 talk on spoofing restricted zones for DJI drones.
Dr. Ahmet Furkan Aydogan is an Assistant Professor at North Carolina University. His academic expertise significantly contributed to the foundational understanding and advanced technical aspects of the brain wave research, particularly in areas like identifying individuals using brain waves.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Novel enough premise — EEG as a revocable, coercion-aware biometric for ICS — but the execution is proof-of-concept thin. The demo works, the ML pipeline is explained coherently, and the framing around coercion resistance is genuinely interesting. What's missing is the hard data: accuracy numbers across subjects, false acceptance/rejection rates, performance under real-world noise, and any serious adversarial testing.
Heather Calloway (CISO) — WEAK
Interesting academic proof-of-concept that never closes the gap to operational deployment. The research question is legitimate, but the talk spends most of its time explaining how EEG works rather than confronting the hard problems that stand between a lab demo and a critical infrastructure environment.