AI0-001 AI Security Practice Question
A security analyst is investigating a potential adversarial attack on a production image classifier. The attack involves tiny perturbations that are invisible to the human eye but cause the model to misclassify a stop sign as a speed limit sign. Which type of attack is this?
⚠ Common exam trap
Candidates often confuse adversarial examples with data poisoning because both involve modifying input data. However, adversarial examples are crafted during inference to cause misclassification, whereas data poisoning corrupts the training dataset to influence the model's learned behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adversarial example
This is an adversarial example attack, where imperceptible perturbations are added to the input (e.g., a stop sign) to cause the model to misclassify it (e.g., as a speed limit sign). The perturbations are crafted using gradient-based methods (like FGSM or PGD) to maximize the model's loss, exploiting its linearity in high-dimensional spaces. This differs from other attacks because it targets the inference phase, not the training data or model parameters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data poisoning
Why it's wrong here
Data poisoning corrupts the training set before deployment, so the model learns skewed decision boundaries; it cannot alter a live classifier's output for a single crafted input. It is tempting because it also degrades model accuracy, and would fit a scenario where an attacker plants mislabelled samples during retraining or fine-tuning.
- ✗
Model inversion
Why it's wrong here
Model inversion reconstructs representative training inputs from confidence scores, exposing sensitive data; it does not perturb an input to force a chosen misclassification. It is tempting because it also exploits model outputs, and would be correct where an attacker recovers a face or record the model was trained on.
- ✗
Membership inference
Why it's wrong here
Membership inference determines whether a specific record was in the training set by analysing prediction confidence; it never modifies an input to change the predicted class. It is tempting because it also probes model outputs, and would be correct where an attacker must confirm a patient's data trained a diagnostic model.
- ✓
Adversarial example
Why this is correct
Adversarial examples are inputs deliberately perturbed by imperceptible amounts to force misclassification, exactly matching the stop-sign-to-speed-limit scenario. Unlike data poisoning, which corrupts training data, or model inversion, which extracts training information, this attack manipulates inference-time input pixels, exploiting the model's learned decision boundaries without altering the model itself.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.