Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 4Objective 3

Model Extraction and Theft COASP Practice Questions (Page 6)

Part of the Adversarial Machine Learning and Model Privacy Attacks domain, which makes up ~13% of our current practice bank.

41questions here
9free pages
5concepts

Questions 26–30

  1. 26application · medium

    An attacker is extracting a remote sentiment-analysis model. The API returns only the predicted class (positive/negative) and not confidence scores. The attacker wants to approximate the model's decision boundary. Which query strategy is most effective under this constraint?

    Select an answer first
  2. 27foundation · easy

    In a model extraction attack, what does the attacker typically have access to?

    Select an answer first
  3. 28application · medium

    A security team is reviewing logs and notices that a client IP sends a high volume of queries to a model API, with inputs that are slightly perturbed versions of each other. The team suspects model extraction. Which detection method is most effective in this scenario?

    Select an answer first
  4. 29application · medium

    A company has deployed a model that is a key differentiator for its product. The security team wants to detect if an attacker has successfully extracted the model. Which approach is most practical?

    Select an answer first
  5. 30foundation · easy

    Which extraction attack vector relies on observing physical characteristics of the hardware running the model?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.