Courseiva

AIF-C01 Guidelines for Responsible AI Practice Question

A company deploys a deep learning model for image classification using Amazon SageMaker. They are concerned about adversarial attacks that could misclassify images with small perturbations. Which of the following is the most effective approach to improve model robustness?

⚠ Common exam trap

A common misconception is that increasing model complexity or using standard regularization (like early stopping) inherently improves robustness against adversarial attacks. However, adversarial training is the only listed method that directly exposes the model to adversarial perturbations during training, thereby improving its resistance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply adversarial training

Adversarial training is the most effective approach because it explicitly augments the training dataset with adversarial examples—inputs crafted with small, intentional perturbations designed to fool the model. By training on these perturbed samples, the model learns to recognize and resist such attacks, directly improving its robustness against adversarial perturbations in image classification tasks on SageMaker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduce training data size

    Why it's wrong here

    Reducing training data shrinks the decision boundary's coverage, typically worsening robustness to perturbed inputs. Adversarial robustness needs more diverse examples, often augmented with adversarial perturbations. It is tempting because smaller datasets shorten training time, which is mistaken for improved model quality.

  • ✗

    Use early stopping during training

    Why it's wrong here

    Early stopping halts training when validation loss stops improving, which regularises against overfitting, not against input perturbations. Adversarial robustness requires training on perturbed examples, such as adversarial training. Early stopping is tempting because it is a standard, cheap generalisation technique that improves held-out accuracy.

  • ✓

    Apply adversarial training

    Why this is correct

    Adversarial training augments the training set with perturbed examples, forcing the network to learn decision boundaries robust to small input changes. That directly counters the perturbation-based misclassification described, unlike input sanitisation or monitoring, which do not alter learned weights.

  • ✗

    Increase model complexity

    Why it's wrong here

    Increasing model complexity, such as adding more layers or parameters, does not address the specific vulnerability to adversarial perturbations; it often exacerbates overfitting to training data, making the model more sensitive to small input changes. This option is tempting because deeper models generally improve accuracy on clean data, and in a scenario where underfitting or low capacity was the primary issue, increasing complexity would be the correct remedy.

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.