AAISM · Question #171
Which defense is MOST effective against cyberattacks that alter input data to avoid detection?
The correct answer is A. Enhancing model robustness through adversarial training. Attacks that alter input data to evade detection are adversarial examples - inputs crafted to cause misclassification. Adversarial training (A) directly counters this by exposing the model to adversarial examples during training, teaching it to correctly classify perturbed…
Question
Which defense is MOST effective against cyberattacks that alter input data to avoid detection?
Options
- AEnhancing model robustness through adversarial training
- BRestricting access to internal model parameters
- CConducting periodic monitoring of decisions
- DApplying differential privacy to training data
How the community answered
(37 responses)- A70% (26)
- B5% (2)
- C8% (3)
- D16% (6)
Explanation
Attacks that alter input data to evade detection are adversarial examples - inputs crafted to cause misclassification. Adversarial training (A) directly counters this by exposing the model to adversarial examples during training, teaching it to correctly classify perturbed inputs. This hardens the model's decision boundaries against such manipulation. Restricting access to model parameters (B) addresses model extraction threats, not input manipulation. Periodic monitoring (C) detects drift after the fact but does not prevent adversarial bypass. Differential privacy (D) protects training data confidentiality but does not make the model resistant to adversarial inputs at inference time.
Topics
Community Discussion
No community discussion yet for this question.