Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A security analyst is investigating a potential adversarial attack on a production image classifier. The attack involves tiny perturbations that are invisible to the human eye but cause the model to misclassify a stop sign as a speed limit sign. Which type of attack is this?

⚠ Common exam trap

Candidates often confuse adversarial examples with data poisoning because both involve modifying input data. However, adversarial examples are crafted during inference to cause misclassification, whereas data poisoning corrupts the training dataset to influence the model's learned behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adversarial example

This is an adversarial example attack, where imperceptible perturbations are added to the input (e.g., a stop sign) to cause the model to misclassify it (e.g., as a speed limit sign). The perturbations are crafted using gradient-based methods (like FGSM or PGD) to maximize the model's loss, exploiting its linearity in high-dimensional spaces. This differs from other attacks because it targets the inference phase, not the training data or model parameters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data poisoning

    Why it's wrong here

    Data poisoning corrupts the training set before deployment, so the model learns skewed decision boundaries; it cannot alter a live classifier's output for a single crafted input. It is tempting because it also degrades model accuracy, and would fit a scenario where an attacker plants mislabelled samples during retraining or fine-tuning.

  • ✗

    Model inversion

    Why it's wrong here

    Model inversion reconstructs representative training inputs from confidence scores, exposing sensitive data; it does not perturb an input to force a chosen misclassification. It is tempting because it also exploits model outputs, and would be correct where an attacker recovers a face or record the model was trained on.

  • ✗

    Membership inference

    Why it's wrong here

    Membership inference determines whether a specific record was in the training set by analysing prediction confidence; it never modifies an input to change the predicted class. It is tempting because it also probes model outputs, and would be correct where an attacker must confirm a patient's data trained a diagnostic model.

  • ✓

    Adversarial example

    Why this is correct

    Adversarial examples are inputs deliberately perturbed by imperceptible amounts to force misclassification, exactly matching the stop-sign-to-speed-limit scenario. Unlike data poisoning, which corrupts training data, or model inversion, which extracts training information, this attack manipulates inference-time input pixels, exploiting the model's learned decision boundaries without altering the model itself.

About these practice questions

This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.