
EC-CouncilCertified Offensive AI Security Professional
Domain 4Objective 2
FGSM and PGD Attacks on Image Classifiers COASP Practice Questions (Page 5)
Part of the Adversarial Machine Learning and Model Privacy Attacks domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
6concepts
Questions 21–25
- 21
A security team compares FGSM and PGD on a medical image classifier. They find that FGSM has a success rate of 60% and PGD has a success rate of 95% at the same epsilon. They need to report the robustness of the model. What is the most appropriate conclusion?
Select an answer first - 22
A security team is comparing the robustness of two classifiers. They run FGSM and PGD on both. Classifier A has a higher clean accuracy, but Classifier B has a lower PGD success rate. What can be concluded?
Select an answer first - 23
A data scientist is creating a report to show the impact of adversarial attacks. They generate adversarial examples using FGSM and want to display the perturbation. Which method is most effective?
Select an answer first - 24
A security analyst is evaluating a classifier's robustness. They run FGSM and PGD with the same epsilon on the same test set. PGD achieves a success rate of 95%, while FGSM achieves 70%. What does this comparison indicate?
Select an answer first - 25
A red team is evaluating a model's robustness and wants to use PGD to find the strongest possible adversarial example. They have a limited compute budget and need to choose between many iterations with a small step size or fewer iterations with a larger step size. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.