A SOC analyst notices that after ingesting a third-party threat feed, the AI phishing classifier increasingly labels known malicious attachments as benign. Review shows the feed contained examples crafted to appear benign while hiding malicious payloads. Which risk to the AI model’s training pipeline does this most directly describe?
Select an answer to reveal the explanation.
Short Explanation
Think of training data like your recipe book: if someone sneaks in bad ingredients, every dish tastes wrong. You're seeing data poisoning, not just the model getting stale. The trap is calling it drift or evasion; the poison happened before detection, in the training set.
Full Explanation
Data poisoning targets the integrity of the training corpus. In this scenario, the classifier's accuracy degrades because malicious samples were intentionally mislabeled or crafted to look benign before the model learned from them. The model then generalizes a false boundary between phishing and legitimate attachments, which is why the degradation appears after new training data is ingested rather than at initial deployment.
Adversarial evasion differs because it changes inputs at inference time to slip past a correctly trained model, not corrupt the labels or examples used during training. Model drift and concept drift describe accuracy loss as the environment, traffic patterns, or problem definition evolve over time; they can produce similar symptoms but do not imply deliberate contamination of the training set. A third-party feed can also introduce benign distribution shift, but the described malicious intent and misleading examples point specifically to poisoned training data.
Exam caveat: CompTIA expects you to distinguish training-time data integrity attacks from inference-time evasion and from natural accuracy decay. Operational check: Validate newly ingested threat-feed samples against trusted labels, provenance, and duplicate/label-anomaly checks before retraining the model.