Courseiva
AI Security →easyMultiple Select

AI0-001 AI Security Practice Question

A company is deploying a pre-trained image classification model for facial recognition in a security system. They are concerned about adversarial examples. Which TWO of the following are effective defenses against adversarial examples?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adversarial training during model development

Adversarial training during model development (A) is correct because it augments the training set with adversarial examples generated by attacks like FGSM or PGD, so the model learns to classify perturbed inputs correctly and gains genuine robustness. Input sanitization techniques such as JPEG compression or denoising (C) are correct because they destroy or attenuate the small, high-frequency perturbations that adversarial attacks add, reducing the attack's effectiveness before inference. Gradient masking (B) is not a reliable defense: it only obscures gradients and is routinely bypassed by transferability or gradient-free attacks, giving a false sense of security. Homomorphic encryption (D) protects data confidentiality during computation but does not remove or neutralize adversarial perturbations, so it is irrelevant to adversarial robustness. Federated learning (E) addresses privacy and distributed training, not the integrity of predictions against crafted inputs, so it does not defend against adversarial examples.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Adversarial training during model development

    Why this is correct

    Adversarial training augments the training set with perturbed images labelled correctly, so the model learns decision boundaries robust to small input changes. This directly hardens the pre-trained classifier against the evasion attacks the security system fears, satisfying the stem's adversarial-example constraint at development time.

  • ✗

    Gradient masking to hide model gradients

    Why it's wrong here

    Gradient masking obscures gradients but is defeated by transferability and gradient-free attacks, so it provides no robust guarantee. It is tempting because hiding gradients appears to deny attackers the information they exploit, yet adversarial training and input preprocessing are the defences that actually reduce attack success.

  • ✓

    Input sanitization techniques such as JPEG compression or denoising

    Why this is correct

    JPEG compression and denoising strip the high-frequency perturbations adversarial attacks rely on, disrupting the carefully crafted noise before inference. This satisfies the stem's requirement for an effective defence without retraining the pre-trained model, making it a practical mitigation for the facial recognition security system.

  • ✗

    Homomorphic encryption of input images

    Why it's wrong here

    Homomorphic encryption protects data confidentiality during computation; it does not alter the model's decision surface, so adversarial perturbations still flip predictions. It is tempting because it secures processing of sensitive biometric data, and would be the right control when privacy of outsourced inference is the requirement rather than robustness.

  • ✗

    Federated learning to train on distributed data

    Why it's wrong here

    Federated learning distributes training across data holders for privacy, which does nothing to harden a model against perturbed inputs at inference. It is tempting because it changes the training regime, but adversarial defences require adversarial training or input validation, not a different data-residency architecture.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.