AAISM · Question #57
Which of the following is the MOST effective defense against cyberattacks that alter input data to avoid detection by the model?
The correct answer is B. Enhancing model robustness through adversarial training. The attack described - altering input data to evade model detection - is an adversarial evasion attack. The MOST effective countermeasure is adversarial training (B), which involves intentionally exposing the model to adversarial examples during training so it learns to…
Question
Which of the following is the MOST effective defense against cyberattacks that alter input data to avoid detection by the model?
Options
- AConducting periodic monitoring activities on the model's decisions
- BEnhancing model robustness through adversarial training
- CImplementing restricted access to the model's internal parameters
- DApplying differential privacy controls on training datasets
How the community answered
(38 responses)- A5% (2)
- B79% (30)
- C11% (4)
- D5% (2)
Explanation
The attack described - altering input data to evade model detection - is an adversarial evasion attack. The MOST effective countermeasure is adversarial training (B), which involves intentionally exposing the model to adversarial examples during training so it learns to correctly classify them. This directly hardens the model against this class of attack. Periodic monitoring (A) can detect problems after the fact but doesn't prevent evasion. Restricting access to internal parameters (C) is a model confidentiality control, not an evasion defense. Differential privacy (D) protects training data privacy, not model robustness against adversarial inputs at inference time.
Topics
Community Discussion
No community discussion yet for this question.