# Bidirectional BCI Security
**Entity class:** Security architecture
## Definition
**Bidirectional BCI security** protects systems that both decode neural activity and write signals back through stimulation or neuromodulation. Read and write paths create different attack surfaces: the forward path can expose, corrupt, or misclassify neural signals; the backward path can deliver unauthorized or unsafe commands to the nervous system.
## Control requirements
The architecture requires authenticated commands, least-privilege authorization, cryptographic integrity, bounded stimulation parameters, anomaly detection, auditable state changes, fail-safe modes, secure updates, trusted recovery configurations, and verification of the resulting biological state. A technically repaired implant is not fully restored if a malicious or malfunctioning write operation has left an adverse state downstream.
## Relationships
- **general field:** [[wiki/Neurosecurity|Neurosecurity]].
- **system boundary:** [[wiki/Cyber-Biological System|Cyber-Biological System]].
- **write path:** [[wiki/Neural Command Channel|Neural Command Channel]].
- **attack class:** [[wiki/Brainjacking|Brainjacking]].
- **interface:** [[wiki/Brain-Computer Interfaces|Brain-Computer Interfaces]].
## Sources / Provenance
- Xinyu Jiang et al., [“Cybersecurity in neural interfaces: Survey and future trends”](https://pubmed.ncbi.nlm.nih.gov/37883851/), 2023.
- U.S. Food and Drug Administration, [“Cybersecurity in Medical Devices Frequently Asked Questions”](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs), current page accessed 2026-09-23.
**As of:** 2026-09-23