mirror of
https://github.com/rohitg00/ai-engineering-from-scratch.git
synced 2026-10-02 01:54:39 +08:00
Every "Test Your Understanding" quiz placed the correct answer in option B.
Across the 2026 questions in 338 quiz files the correct answer sat at index 1
in 61.5% of cases (uniform would be ~25%), and 107 files had every answer at B,
making the quizzes guessable without reading them.
scripts/debias_quizzes.py rewrites each question's option order with a
deterministic, content-seeded permutation and updates the correct index to
follow the moved answer. It is idempotent: options are canonicalised to a sorted
base before permuting, so re-running produces byte-identical output. Questions
whose options reference each other by position ("all of the above", "both A and
B") are left untouched. The correct-answer value, the option set, and every
explanation are preserved exactly; only order and the index change.
Result: A 23.8% / B 26.3% / C 23.5% / D 26.4%.
The script doubles as a CI guard: `--check` exits non-zero if any quiz is not
de-biased, wired into the curriculum workflow so new lessons cannot regress.
Fixes #368
79 lines
2.8 KiB
JSON
79 lines
2.8 KiB
JSON
{
|
|
"lesson": "15-indirect-prompt-injection",
|
|
"title": "Indirect Prompt Injection - Production Attack Surface",
|
|
"questions": [
|
|
{
|
|
"stage": "pre",
|
|
"question": "What distinguishes indirect prompt injection (IPI) from direct prompt injection?",
|
|
"options": [
|
|
"IPI is a synonym for jailbreaking",
|
|
"IPI embeds instructions inside external content (web pages, emails, tool outputs) that the agent consumes during normal operation, without the attacker touching the user's prompt",
|
|
"IPI only works on multimodal models",
|
|
"IPI requires fine-tuning the target model"
|
|
],
|
|
"correct": 1,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "check",
|
|
"question": "Which of these is NOT one of the three IPI delivery vectors listed in the lesson?",
|
|
"options": [
|
|
"Direct system-prompt edits by the user",
|
|
"Tool output",
|
|
"Inbox / document workflows",
|
|
"Retrieval-augmented generation (poisoned retrieval)"
|
|
],
|
|
"correct": 0,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "check",
|
|
"question": "Why do user-input filters miss IPI?",
|
|
"options": [
|
|
"Filters cannot read JSON",
|
|
"Filters only run after the model responds",
|
|
"User-input filters are case-sensitive",
|
|
"The payload never appears in the user's input; it appears in retrieved or tool-supplied content"
|
|
],
|
|
"correct": 3,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "check",
|
|
"question": "What is the central principle of Information Flow Control (IFC) for AI agents?",
|
|
"options": [
|
|
"Disable all tools by default",
|
|
"Encrypt all retrieved content",
|
|
"Label content by source as trusted or untrusted; actions triggered by untrusted content must be ratified by trusted input before execution",
|
|
"Use only single-turn prompts"
|
|
],
|
|
"correct": 2,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "post",
|
|
"question": "What did Nasr et al. (October 2025, 'The Attacker Moves Second') find about 12 published IPI defenses with adaptive attacks?",
|
|
"options": [
|
|
"Adaptive attacks were too expensive to evaluate",
|
|
"Their reported near-zero ASR held under adaptive attack",
|
|
"Adaptive attacks (gradient, RL, random search, human red-team) broke >90% of them despite their original near-zero ASR claims",
|
|
"Only one defense was broken"
|
|
],
|
|
"correct": 2,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "post",
|
|
"question": "Where does prompt injection rank in the 2025 OWASP LLM Top 10?",
|
|
"options": [
|
|
"LLM10 (lowest)",
|
|
"LLM01 (top, #1 application-layer threat)",
|
|
"Not listed",
|
|
"LLM05"
|
|
],
|
|
"correct": 1,
|
|
"explanation": ""
|
|
}
|
|
]
|
|
}
|