Courseiva
AI Security →mediumMultiple Select

AI0-001 AI Security Practice Question

A financial institution uses a machine learning model to approve loans. They want to protect against membership inference attacks. Which THREE techniques are effective?

⚠ Common exam trap

AI0-001 often tests the difference between techniques that directly mitigate membership inference (differential privacy, output perturbation) and those that are unrelated or even detrimental (federated learning alone, shadow models). Candidates may confuse federated learning as a privacy panacea.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying model truncation or output perturbation

Option A (model truncation or output perturbation) is correct because reducing the precision or adding calibrated noise to the model's outputs limits the information an attacker can extract about whether a specific record was in the training set, directly mitigating membership inference. Option B (training with differential privacy) is correct because DP-SGD and related mechanisms provide a formal guarantee that the inclusion or exclusion of any single training record has a bounded effect on the model's behavior, which is the canonical defense against membership inference. Option C (limiting the granularity of model outputs, e.g., returning scores instead of probabilities) is correct because coarse, bucketed outputs reduce the signal an attacker can use to distinguish members from non-members, lowering attack success rates. Option D (federated learning) is not inherently a membership-inference defense: it keeps raw data local but the shared model updates can still leak membership information, so it does not by itself provide the required protection. Option E (shadow models to distract attackers) is not a recognized defense; shadow models are an attacker technique used to train attack classifiers, not a mitigation, so it does not belong here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Applying model truncation or output perturbation

    Why this is correct

    Truncating outputs or perturbing returned values reduces the confidence information an adversary needs to infer whether a specific record was in the training set, satisfying the requirement to blunt membership inference against the loan model.

  • ✓

    Training with differential privacy

    Why this is correct

    Training with differential privacy injects calibrated noise into the training process, bounding how much any single record influences the model's parameters. This directly limits the confidence signal a membership inference attacker exploits, satisfying the requirement to protect against inferring whether a specific customer's data was in the loan-approval training set.

  • ✓

    Limiting the granularity of model outputs (e.g., returning scores instead of probabilities)

    Why this is correct

    Returning coarse scores rather than precise probabilities reduces the information each query leaks about individual training records, directly hindering a membership inference adversary's ability to distinguish members from non-members. This satisfies the stem's requirement to protect the loan-approval model against membership inference attacks by limiting output granularity.

  • ✗

    Implementing federated learning

    Why it's wrong here

    Federated learning keeps training data on clients, but the released model still memorises its training set, so membership inference remains feasible. It addresses data centralisation and privacy during training, not inference-time leakage; it would suit scenarios prohibiting raw data aggregation.

  • ✗

    Using shadow models to distract attackers

    Why it's wrong here

    Shadow models are used by attackers to replicate a target model's behaviour, not to defend it; deploying decoys does not alter the target's output distribution. Shadow models belong in an attack pipeline for crafting membership inference queries, not in a defence against them.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.