Search⌘ K
AI Features

From Question to Plan

Discover how to construct well-defined, measurable ML security research questions by specifying system boundaries, attacker models, metrics, baselines, and evaluation constraints. This lesson guides you in transforming vague security concerns into clear, defensible evaluation plans for robust threat modeling and analysis.

Three questions can sound similar while producing very different evaluations. One question is too broad: “Does this image-classification API resist adversarial attacks?” It leaves the system boundary, attacker access, and success criterion unspecified, so the result can be challenged as applying to a different setting. A second question is more specific but still underspecified: “Under query-only access, how robust is the API to adversarial examples?” This is better, but the evaluation still needs a metric, baseline, and attack budget to determine whether the observed change is meaningful.

A third question is answerable. Under a rate-limited black-box attacker who can submit NN queries per day, does mitigation M reduce the attack success rate on target ...