
EC-CouncilCertified Offensive AI Security Professional
Domain 4Objective 2
FGSM and PGD Attacks on Image Classifiers COASP Practice Questions (Page 7)
Part of the Adversarial Machine Learning and Model Privacy Attacks domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
6concepts
Questions 31–35
- 31
A security team is reporting the attack success rate (ASR) of FGSM and PGD on a classifier. They notice that the ASR varies significantly depending on the random seed used for the test set. What is the most appropriate way to report the ASR to ensure reliability?
Select an answer first - 32
A developer is implementing FGSM in PyTorch. They want to ensure the adversarial image remains within the valid pixel range [0, 1]. Which operation should they apply after adding the perturbation?
Select an answer first - 33
A researcher is comparing FGSM and PGD on a classifier. They set the same epsilon for both attacks. PGD achieves a higher success rate. What is the most likely reason?
Select an answer first - 34
A security team evaluates the robustness of a facial recognition model. They run FGSM and PGD attacks on a test set of 1,000 images and report the attack success rate (ASR). They observe that PGD achieves a higher ASR than FGSM at the same epsilon. What is the most likely reason?
Select an answer first - 35
In the context of adversarial attacks, what does the epsilon parameter control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to COASP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.