By using this repository, you consent to the terms in CODE_OF_CONDUCT.md. This is early-stage research — not a validated standard, not a clinical tool, not production software. The human brain is not a test environment. See Code of Conduct and Security Policy.
Neuroethics has two hemispheres (Roskies, 2002): the ethics of neuroscience governs how brain research is conducted, while the neuroscience of ethics asks what the brain reveals about moral reasoning. Neurosecurity follows the same structure:
Security of Neuroscience — Defending neural systems. Threat modeling, scoring, encryption, monitoring. Engineering that works today.
Neuroscience of Security — What the brain teaches us about security. New threats, new rights, and the boundaries between attack and therapy that need to be drawn before the technology outpaces governance.
| Security of Neuroscience | Neuroscience of Security | |
|---|---|---|
| Question | How do we defend neural systems? | What are we defending, and from what? |
| Method | Engineering | Research + philosophy |
| Output | Tools, protocols, detections | Principles, rights, governance |
| In this repo | TARA, NISS, NSP, Neurowall, QIF Model | Governance, neurorights, dual-use insight |
This project does both. It asks: what happens to a patient when their brain-computer interface is compromised? Not the data. Not the device. The person.
neurosecurity/
├── osi-of-mind/ QIF Model — specs, whitepapers, derivation logs, threat catalog
├── research/ Blog posts, academic paper, clinical notes
├── governance/ Policy, ethics, consent, changelog, security policy
├── src/ Website source (Astro) + build scripts
└── _archive/ Historical (ONI framework, old prompts)
Each directory has a CONTEXT.md with a summary and file map. Start with any directory's README.md for full documentation.
| Start here | If you want to... |
|---|---|
| osi-of-mind/ | Read the QIF Model, TARA specs, or whitepapers |
| research/blog/ | Read field journal entries and technical posts |
| governance/ | Review policy, ethics, or the decision log |
| src/ | Work on the website or build scripts |
| qinnovate.com | Browse everything rendered |
Full transparency: Transparency Statement | Derivation Log (113 entries) | Decision Log | Validation Status
(See Repository above for the full directory map.)
Tools
| Tool | What It Does | Install |
|---|---|---|
| Quorum | Orchestrate a swarm of AI experts on any question. Structured dissent, fact-checking, multi-agent validation. | claude install qinnovates/quorum |
| BCI Security Plugin | First BCI security toolkit for AI coding assistants. Scans code for neural data handling issues. | claude install qinnovates/bci-security-plugin |
| NeuroSIM | Neural Security Operations Simulator. BCI signal processing meets security operations. | See repo |
| macshield | Network-aware macOS security hardening. | brew install qinnovates/tools/macshield |
Validation Summary
Solo research, tested honestly. Full methodology and limitations at VALIDATION.md | Live dashboard
| What | Result | Tier |
|---|---|---|
| Neurowall coherence monitor | 11/14 at 15s, 9/9 at 20s, 50-run stats, 0% FPR | Simulation + Independent |
| BrainFlow validation | 16-channel, 100% detection, 0% FPR | Independent |
| Physics security guardrails | 12/13 constraints verified, 4-layer architecture | Analytical + Cross-AI |
| Protocol vulnerability | Real vulnerability in BCI streaming protocol, responsibly disclosed | Disclosed |
| NSP transport | Round-trip simulation PASS, 65-90% compression | Simulation |
| NISS scoring engine | 109/109 techniques scored, PINS flags correct | Simulation |
| Citation verification | 3 fabricated citations caught and removed from preprint v1.0 | Audit |
| Not yet tested | NISS clinical validation, DSM-5-TR mappings, BCI Limits Eq, real EEG, real hardware, real attacks |
This is early-stage research by a solo researcher. Empirical validation requires BCI hardware, IRB approval, and clinical expertise. Everything is published openly so research groups with those resources can test, validate, refute, or extend it.
What This Project Contains
| Component | Description | Status |
|---|---|---|
| QIF | 11-band hourglass security architecture for BCIs | Proposed, v6.3 (v8.0) |
| TARA | 165 BCI technique pairs, STIX 2.1 registry | v1.7 |
| qtara | Python SDK for TARA registry management and STIX export | v0.2.0 |
| NSP | Post-quantum wire protocol for BCI data links | In development, v0.5 |
| NISS | CVSS v4.0 extension proposal for neural interfaces (6 neural metrics) | Proposed, v1.1 |
| Runemate | Native DSL compiler (67.8% compression in simulation) | v1.0 Compiler |
| Security Guardrails | Physics-derived defense architecture for BCIs | Concept |
| Component | Description | Status |
|---|---|---|
| Neural Atlas | Browser-based neural security monitoring with sample EEG data, threat detection, and NISS scoring | Published (Demo) |
| Neurowall | Neural firewall prototype (differential privacy + NISS + policy engine) | In development, v0.8 |
| Component | Description | Status |
|---|---|---|
| Governance Wiki | Ethics, consent, regulatory compliance, accessibility | Published |
| Neurosecurity Governance | Neurorights mapping, UNESCO alignment, GRC gap analysis | Published |
| Policy Proposal | 6 recommendations for NIST, MITRE, FIRST, IEEE, FDA, UNESCO | v1.2 |
| Component | Description | Status |
|---|---|---|
| Zenodo | Working paper, CC-BY 4.0, LaTeX source included | Published |
| Research Sources | 340+ verified sources across 9 domains | Active |
| CVE-TARA Mapping | 55 NVD-verified CVEs mapped to 21 TARA techniques | Published |
| EEG Data Pipeline | Curated EEG datasets, synthetic generation, KQL tagging, license verification | Active |
| FIRST.org CVSS SIG | NISS proposed as CVSS v4.0 extension; outreach in progress | In progress |
| Peer review / empirical validation | Requires collaborators, IRB, BCI hardware | Blocked |
The TARA Insight
TARA started as an attack matrix. 165 BCI techniques catalogued from published literature. Something unexpected emerged: the same mechanisms kept showing up on the therapeutic side.
Signal injection is an attack vector. It is also the basis of neurostimulation therapy for depression, Parkinson's, and chronic pain. The boundary between attack and therapy is not the mechanism. It is consent, dosage, and oversight.
About 75% of the 165 techniques map to a therapeutic counterpart today. This means the same framework that scores whether an attack is dangerous can also help bound whether a therapy is safe. TARA is both a threat registry and a safety reference.
Why Neurosecurity
Three fields converge on BCIs. None covers the full problem alone.
| Field | Contributes | Cannot Do Alone |
|---|---|---|
| Neuroethics | Policies, rights frameworks, consent models | Detect a P300 interrogation attack in real time |
| Neuroscience | Mechanism knowledge, attack surface understanding | Score severity, map attack chains, build detection systems |
| Cybersecurity | TTPs, scoring, detection, incident response | Understand neural biology or define neurorights |
Neurosecurity (Denning, Matsuoka & Kohno, 2009) bridges all three. QIF is one attempt to operationalize that bridge — taking phenomena described by neuroscientists and concerns raised by neuroethicists and putting them into a testable security framework.
Neurosecurity Governance | Origin classification of all 165 techniques
Architecture
An 11-band hourglass architecture: 7 neural bands (N7 Neocortex down to N1 Spinal Cord), a physical interface boundary (I0, the electrode-tissue interface), and 3 synthetic bands organized by physics regime and spatial scale (S1 Near-Field/On-Device, S2 Guided-Wave/Host-Local, S3 Far-Field/Wide-Area).
- Site: qinnovate.com/framework
- Whitepaper: qinnovate.com/research/whitepaper (v6.3, v8.0 in progress)
- Working Paper: DOI: 10.5281/zenodo.18640105
165 techniques spanning 8 domains and 17 tactics. Each technique scored with CVSS v4.0 base vectors + proposed NISS extension metrics. MITRE-compatible IDs.
[Legacy: Requires further updates and refining]
- Atlas: qinnovate.com/atlas/tara
- API:
/api/tara.json(full dataset, no auth) |/api/stix.json(STIX 2.1 bundle) - SDK:
pip install qtara
A proposed CVSS v4.0 extension for neural interfaces. Six metrics that CVSS cannot express:
| Metric | Code | What It Measures |
|---|---|---|
| Biological Impact | BI | Tissue damage, neural pathway disruption |
| Cognitive Reconnaissance | CR | Thought decoding, neural data inference |
| Cognitive Disruption | CD | Perception manipulation, cognitive coercion |
| Consent Violation | CV | Whether the subject knew and agreed |
| Reversibility | RV | Can the damage be undone? |
| Neuroplasticity | NP | Long-term adaptive/maladaptive neural changes |
- Scoring: qinnovate.com/atlas/scoring
- Parser: src/lib/niss-parser.ts
Post-quantum wire protocol (v0.5). ML-KEM-768, ML-DSA, AES-256-GCM-SIV at the frame level. Designed for implant-class hardware. Performance claims are from simulation only — hardware validation pending.
- Spec: qinnovate.com/guardrails/nsp
- Implementation: osi-of-mind/nsp/nsp-core/ (Rust)
Native DSL compiler (67.8% compression in simulation). Phase 2/3 goal: compile semantic content into electrode stimulation patterns for direct cortical rendering (vision restoration). This is speculative — the compiler exists, the cortical rendering does not.
- Spec: qinnovate.com/guardrails/runemate
- Compiler: osi-of-mind/runemate/forge/ (Rust)
Terminology
| Term | Usage |
|---|---|
| Neurosecurity | The research discipline (Denning, Matsuoka & Kohno, 2009). Use when referencing the academic field. |
| BCI security | The applied engineering domain. Use when describing what QIF tools do in practice. |
| Neuroethics | Foundational scholarship informing QIF's design constraints. QIF is informed by neuroethics; QIF is not a neuroethics project. |
| Governance | Policy bridge between security and ethics. Spans the full stack, not just neural. Do not use "neurogovernance." |
Governance & Logging Architecture
This project uses a single-source-of-truth model for decision tracking. One file captures everything; other documents are generated from it.
┌──────────────────────────────┐
│ QIF-DERIVATION-LOG.md │ ← Single source of truth
│ (113 entries, lab notebook) │ Write here. Everything else derives.
└──────────┬───────────────────┘
│
┌────────────────┼────────────────┐
▼ ▼ ▼
┌─────────────────┐ ┌─────────────┐ ┌──────────────┐
│ DECISION-LOG.md │ │TRANSPARENCY │
│ (auto-generated)│ │.md (auto) │
│ npm run decisions│ │npm run │ │ ✅🚧📋❌ │
└─────────────────┘ │transparency │ └──────────────┘
└─────────────┘
| Document | Purpose | Audience | Maintained |
|---|---|---|---|
| QIF-DERIVATION-LOG.md | Lab notebook — every framework insight, decision, correction. RACI attribution, AI contribution level per entry. | Kevin (future self), peer reviewers, collaborators | Per session (max 1 entry) |
| DECISION-LOG.md | RACI tables — who decided, who built, who reviewed. | Governance auditors, future collaborators | Auto-generated: npm run decisions |
| TRANSPARENCY.md | AI collaboration disclosure — contribution matrix, correction count, tool versions. | Peer reviewers, venues (arXiv, ACM, IEEE) | Auto-generated: npm run transparency |
| QIF-FIELD-JOURNAL.md | Personal/experiential observations. Kevin's raw voice. AI cannot write this. | Kevin only | When something surprises him |
| CHANGELOG.md | Auto-generated from git commits. What changed, not why. | Developers, contributors | Auto: npm run changelog |
Sensitive Information Controls
A 3-tier filter prevents sensitive data from reaching the public repo:
- Tier 1 (auto-redact): Emails, API keys, subject IDs, IRB numbers, home paths — Claude blocks inline, pre-commit hook catches in staged diffs
- Tier 2 (warn-before-write): Unpublished vulns, personal medical details, draft applications — Claude asks Kevin before including
- Tier 3 (allowed): Published names, DOIs, technique IDs, architecture decisions, NISS scores
Pre-commit hook: src/scripts/governance-precommit.sh (13 regex patterns, whitelist for known-safe)
Developer Commands
All commands run from the repo root.
| Command | What It Does |
|---|---|
npm run eeg:list |
List available EEG datasets and their status |
npm run eeg:download |
Download all redistributable EEG datasets |
npm run eeg:process |
Run MNE-Python pipeline: EDF/MAT → Parquet |
Contributing Workflow
If AI tools were used in your contribution:
- The derivation log entry is written by the project maintainer (Kevin)
npm run governanceregenerates the Decision Log and Transparency Statement from the derivation log- This runs automatically in
npm run prebuild— you don't need to do it manually
Site Revision History
Each weekly snapshot is tagged in git. Click the tag to browse code at that point, or checkout locally to run the site (git checkout <tag> && npm ci && npm run dev).
| Week | Date | Tag | Key Changes |
|---|---|---|---|
| W10 | Mar 5 | site-archive-2026-03-05 |
Academic review response, 5-pillar architecture, 404 redirects, scaffold framing, working paper rename |
| W09 | Mar 2 | site-W09-2026-03-02 |
NISS v1.1 CR/CD split, Zenodo v1.5, guardrails formalization, research landscape expansion |
| W08 | Feb 23 | site-W08-2026-02-23 |
Zenodo v1.4, skills hardening, epistemic integrity rules, CVE disclosure response |
| W07 | Feb 16 | site-W07-2026-02-16 |
NSP v0.5, NISS v1.0, Zenodo v1.0, Neurowall sim, T0079 ear canal case study |
| W06 | Feb 9 | site-W06-2026-02-09 |
14-layer to hourglass migration, TARA atlas, OG social cards |
| W05 | Feb 2 | site-W05-2026-02-02 |
Initial launch: landing page, 9 blog posts |
Browse the Full History
Every decision, revision, and deleted line in this repository is preserved in git. You can time-travel to any point in the project's history using GitHub's native tools.
Browse the repo at any point in time:
https://github.com/qinnovates/neurosecurity/tree/<COMMIT_SHA>
Go to Commits, click any commit, then Browse files to see the entire repo as it existed at that moment.
Get a permanent link to any file:
Press Y on any file page in GitHub. The URL converts from a branch reference (which moves) to a commit SHA permalink (which never changes). Append #L10-L20 to link to specific lines.
Compare any two points:
https://github.com/qinnovates/neurosecurity/compare/v1.0...v2.0
Replace v1.0 and v2.0 with any two tags, branches, or commit SHAs. GitHub renders a full diff of everything that changed between them.
Visual file history:
Replace github.com with github.githistory.xyz in any file URL to see an animated diff of every commit that touched that file. Example:
https://github.githistory.xyz/qinnovates/neurosecurity/blob/main/osi-of-mind/QIF-DERIVATION-LOG.md
Permanent archive (survives repo deletion): This repository is archived by Software Heritage. Software Heritage assigns ISO-standard identifiers (SWHID) to every commit, directory, and file. If this repo ever disappears from GitHub, the archive persists.
Full reference guide: _archive/README.md — complete docs on all history tools, security scanning references, and key documents to track.
The same git history that lets you trace how a security framework evolved is the same history that bug bounty hunters use to find leaked secrets in force-pushed commits. Tools like TruffleHog and Gitleaks scan git history to surface credentials that developers thought they deleted. The mechanism is identical. The difference is consent and intent.
This is the same principle that runs through the entire project. TARA documents 165 BCI techniques where the attack mechanism and the therapeutic mechanism are physically identical. Signal injection is how you compromise a neural interface. It is also how you treat Parkinson's disease. The tool does not determine the use. The boundary is always consent, oversight, and intent.
We publish full history because transparency is the foundation of trust in security research. Every claim in this repo can be traced to the commit where it was introduced, the source that informed it, and the derivation log entry where the decision was made. If something was wrong, you can see when it was corrected and why.
Collaboration
This work needs collaborators. The research base is compiled (340+ verified sources). The threat taxonomy and scoring system exist. What comes next — empirical validation, clinical mappings, signal integrity formalization — requires domain expertise the author does not have alone.
If you work with neural data, BCI design, neuroethics, health policy, or regulatory compliance, please reach out.
Contact: GitHub Issues Website: qinnovate.com GitHub: github.com/qinnovates
Open security research for brain-computer interfaces
Apache 2.0 · Vendor-agnostic
Founded 2026