10 Commits
Author SHA1 Message Date
Rohit Ghumare dda194f840 fix(quiz): correct answer is always in the same position (slot B) (#381)
Every "Test Your Understanding" quiz placed the correct answer in option B.
Across the 2026 questions in 338 quiz files the correct answer sat at index 1
in 61.5% of cases (uniform would be ~25%), and 107 files had every answer at B,
making the quizzes guessable without reading them.

scripts/debias_quizzes.py rewrites each question's option order with a
deterministic, content-seeded permutation and updates the correct index to
follow the moved answer. It is idempotent: options are canonicalised to a sorted
base before permuting, so re-running produces byte-identical output. Questions
whose options reference each other by position ("all of the above", "both A and
B") are left untouched. The correct-answer value, the option set, and every
explanation are preserved exactly; only order and the index change.

Result: A 23.8% / B 26.3% / C 23.5% / D 26.4%.

The script doubles as a CI guard: `--check` exits non-zero if any quiz is not
de-biased, wired into the curriculum workflow so new lessons cannot regress.

Fixes #368
2026-08-01 14:24:15 +01:00
Rohit Ghumare d1cb9d1933 feat: book edition pipeline, fundamentals-first headlines, animated figures, verified bug fixes (#348)
Book pipeline: six-volume EPUB/PDF compilation built by CI from lesson
sources (book/, scripts/build_book.py, themed title pages with edition
stamps, site-matching print theme), attached to every GitHub release.
Homepage Books section and README section link the latest release.

Fundamentals-first headline policy across the course: 16 lesson titles
and 30+ taglines/section headings now lead with the concept (agent
state machines, actor model, role-based teams, memory paging, serving
engine internals, permission modes); framework and product names are
demoted to attributed in-body examples. README, ROADMAP, quizzes, and
prerequisite references synced. New agent-memory taxonomy section maps
memory types to representative implementations.

Vendor-neutral model policy: runnable defaults read the LLM_MODEL env
var with undated aliases; dated snapshot ids removed; multi-provider
phrasing in the setup lesson.

Lessons deepened with original material: prediction-game origins of
perplexity (05/16), scripted-era chatbot lineage 1950-2001 (05/17),
causal-triangle derivation from prefix averaging plus GPT-5 date fix
(07/07). Three new animated site figures back them (figures-history.js).

llms.txt now carries per-lesson raw markdown links so agents can fetch
full lesson text directly.

Bug fixes verified with executed repros: capstone solved flag keyed to
test results, 405B cost estimator overflow, f-string crash on
Python <3.12, no-torch demo path, negative stable BCE, all-zero
stationary distribution, inverted Cohens d, per-lesson quiz panel,
lesson-fetch retry with honest errors, decision-trees doc completed,
editor shortcuts, rustc run command, Docker python3.12 build with doc
sync, git lesson fork flow, FIPA receiver field, fnm under Rosetta,
15 curl-verified link fixes, remaining imdb dataset id spot.
2026-07-25 20:24:56 +01:00
Rohit Ghumare 4026f961a1 fix(phase-05): randomize correct positions + fix ambiguous MCQ 2026-05-23 01:10:18 +01:00
Rohit Ghumare 988fb56e3b feat(phase-05/17): add quiz.json 2026-05-23 01:04:58 +01:00
Rohit Ghumare da76702a05 fix(phase-05): remove dead asset links and stray markdown link match
The 10 audit findings in phase 05 all pointed at SVG assets that were
never created. Nine were broken image embeds (./assets/<name>.svg) and
one was a code-fence false positive where '[tool_name](**args)' inside a
Python snippet looked like a Markdown link to the audit's regex.

This commit:
- Removes the nine broken figure embeds across lessons 01-09. The
  surrounding prose stands on its own; no caption text needed rewriting.
- Splits the offending Python expression in lesson 17 onto two lines
  (fn = tools[tool_name]; result = fn(**args)) so '](**args)' no longer
  appears as adjacent characters.
2026-05-20 18:10:25 +01:00
Rohit Ghumare 3ff25cc17f fix(phase-05/17): validate tool_call name and arguments in agent_loop 2026-04-22 19:43:36 +01:00
Rohit Ghumare cab7dc955a fix(phase-05/17): DialoGPT → flan-t5-small; calibrate injection stats; note deps
Three fixes from CodeRabbit review.

1. DialoGPT-medium with pipeline('text-generation') produces off-topic
   continuations because turn separators and EOS config are missing.
   Swap to google/flan-t5-small via text2text-generation for a coherent
   out-of-the-box teaching example.
2. Split the dense prompt-injection paragraph into four paragraphs:
   attack vectors, measured success rates (contextualize 84% vs broader
   0.5-8.5% range, name EchoLeak CVE with CVSS 9.3), mitigations, and
   the hard limit (no prompt engineering fully eliminates; external
   runtime defenses required).
3. Note that the retrieval-based FAQ snippet requires installing
   sentence-transformers and that the lesson's runnable main.py uses
   stdlib Jaccard so readers know what is illustrative vs runnable.
2026-04-22 18:04:27 +01:00
Rohit Ghumare 1807fbd0a4 fix(phase-05): correct image paths across lessons 10-18
docs/en.md and assets/ are sibling directories under each lesson dir.
GitHub's markdown renderer resolves ./assets/ from docs/en.md to
docs/assets/ (which doesn't exist), breaking every SVG in the rendered
lesson. Change all image references to ../assets/ so the rendered
markdown actually finds the SVG.

Verified via GitHub's rendered HTML: ./assets/pipeline.svg was
resolving to /.../docs/assets/pipeline.svg (404). After fix, resolves
to /.../assets/pipeline.svg (200).

Caught by CodeRabbit review of PR #48 (flagged lesson 16; same bug
applied to all other lessons in the branch).
2026-04-22 18:00:35 +01:00
Rohit Ghumare 3872dc3283 fix(phase-05/17): expand prompt-injection section with 2026 threat data
Add OWASP LLM01 ranking, 84% attack success rate in agentic systems,
CVSS 9.0+ production exploits, direct-vs-indirect distinction. Name
the Plan-Verify-Execute pattern that stops tool results from injecting
unplanned actions. Require user confirmation for destructive actions.
Note that no prompt engineering fully eliminates this risk; external
runtime defense layers (LLM Guard, allowlist validation) are required.

Add Further Reading links: OWASP LLM01, AWS Bedrock agents defense
guide, EchoLeak CVE-2025-32711 (zero-click exfiltration reference).

Source: genai.owasp.org, AWS ML blog on Bedrock agent security,
Vectra prompt injection analysis, MDPI 2078-2489/17/1/54.
2026-04-22 17:48:24 +01:00
Rohit Ghumare c5ef7ae9d0 feat(phase-05/17): chatbots — rule-based to neural to LLM agents
Walks the four-paradigm evolution: rule-based (ELIZA pattern matching
in 20 lines), retrieval-based (FAQ with similarity threshold), neural
seq2seq (and why it loses solo), LLM agent loop (plan → tool → verify).

Working demo: hybrid routing that sends destructive actions to
structured flows, FAQs to retrieval, and ambiguous queries to an LLM
agent fallback. This is the 2026 production pattern.

Names five failure modes still shipping: confident fabrication, prompt
injection, scope creep, infinite loops, context window exhaustion.
Each with mitigation.

Ship artifact: chatbot-architect skill that refuses pure-LLM agents
for destructive actions without structured confirmation flows and
requires prompt-injection audit for any write-access agent.

~75 minutes. Prerequisites lesson 05/13 and 05/14.
2026-04-22 17:39:34 +01:00