CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A red team is assessing a machine learning-based fraud detection system that is periodically retrained on new transaction data. Over several weeks, the team submits a large volume of carefully crafted fraudulent transactions labeled as legitimate into the system's training pipeline, aiming to degrade the model's future ability to detect similar fraud patterns. Which type of AI attack is being conducted?

  1. AModel inversion attack
  2. BPrompt injection
  3. CAdversarial evasion attack
  4. DData poisoning attack
Show answer & explanation

Correct answer: D. Data poisoning attack

A data poisoning attack corrupts the training dataset used to build or retrain a model, deliberately injecting mislabeled or malicious samples so the resulting model learns incorrect patterns, directly matching the scenario of feeding mislabeled data into the retraining pipeline.

Why the other options are wrong

  • A. Model inversion attempts to reconstruct training data from model outputs, the opposite goal.
  • B. Prompt injection manipulates an LLM's inference-time input/instructions, not the training data.
  • C. Adversarial evasion crafts inputs to fool an already-trained model at inference time, not during training.

Data Poisoning Attack

An AI attack that corrupts a model's training data, often with mislabeled or malicious samples, to degrade or manipulate the model's future behavior.

  • Targets the training/retraining phase, not inference
  • Can cause misclassification or backdoors in the model
  • Differs from evasion attacks, which target already-trained models

Memory trick: Poison the well before anyone drinks from the model.

More Attacks and Exploits questions