AI0-001 AI Security, Ethics and Governance Practice Question
A research lab trains a language model using DP-SGD. What primary privacy risk does this technique mitigate?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between privacy risks (membership inference, model inversion) and security risks (poisoning, adversarial examples), and the trap here is that candidates confuse 'privacy risk' with 'security risk' and pick data poisoning or adversarial attacks instead of recognizing that DP-SGD is specifically designed for differential privacy against membership inference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Membership inference attacks
DP-SGD (Differentially Private Stochastic Gradient Descent) mitigates membership inference attacks by adding calibrated noise to gradients during training, which bounds the influence any single training example can have on the final model. This differential privacy guarantee makes it difficult for an adversary to determine whether a specific data point was included in the training set, directly addressing the core risk of membership inference.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data poisoning attacks
Why it's wrong here
DP-SGD adds calibrated noise to per-sample gradients, bounding what any single training record reveals; it does not detect or remove corrupted training data. Data poisoning is countered by provenance checks and data sanitisation, not differential privacy.
- ✓
Membership inference attacks
Why this is correct
DP-SGD adds calibrated noise to per-example gradients during training, bounding any single record's influence on the model. This directly limits an adversary's ability to determine whether a specific individual's data was in the training set, satisfying the stem's requirement to mitigate membership inference attacks.
- ✗
Adversarial patch attacks
Why it's wrong here
Adversarial patches are crafted input perturbations applied at inference time; DP-SGD operates during training and provides no robustness against them. It is tempting because both concern model security, but adversarial robustness needs adversarial training or input filtering.
- ✗
Model inversion attacks
Why it's wrong here
DP-SGD adds calibrated noise to per-example gradients, bounding the influence any single training record exerts on the published weights, which mitigates membership inference. Model inversion reconstructs representative inputs from a deployed model's outputs, a threat DP-SGD's training-time guarantee does not directly address.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.