
EC-CouncilCertified Offensive AI Security Professional
Domain 4Objective 2
FGSM and PGD Attacks on Image Classifiers COASP Practice Questions (Page 3)
Part of the Adversarial Machine Learning and Model Privacy Attacks domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
6concepts
Questions 11–15
- 11
How does Projected Gradient Descent (PGD) differ from the Fast Gradient Sign Method (FGSM) in terms of the number of gradient computations?
Select an answer first - 12
A security researcher is testing a deployed image classifier for robustness. They want a quick, single-step adversarial attack that maximizes the chance of misclassification while minimizing computational cost. They plan to use the sign of the gradient. Which epsilon value should they choose to achieve the strongest single-step perturbation without exceeding the allowed perturbation budget?
Select an answer first - 13
In the Fast Gradient Sign Method (FGSM), how is the adversarial perturbation computed from the gradient of the loss with respect to the input image?
Select an answer first - 14
A data scientist generates adversarial examples using FGSM and wants to visually inspect the perturbation. They plot the original image, the adversarial image, and the difference between them. The difference image appears mostly black with faint white edges. What does this indicate?
Select an answer first - 15
A researcher generates adversarial examples using FGSM with epsilon=0.05 and saves them as PNG files. When they view the images, they look identical to the originals. What is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.