Files
Rohit Ghumare dda194f840 fix(quiz): correct answer is always in the same position (slot B) (#381)
Every "Test Your Understanding" quiz placed the correct answer in option B.
Across the 2026 questions in 338 quiz files the correct answer sat at index 1
in 61.5% of cases (uniform would be ~25%), and 107 files had every answer at B,
making the quizzes guessable without reading them.

scripts/debias_quizzes.py rewrites each question's option order with a
deterministic, content-seeded permutation and updates the correct index to
follow the moved answer. It is idempotent: options are canonicalised to a sorted
base before permuting, so re-running produces byte-identical output. Questions
whose options reference each other by position ("all of the above", "both A and
B") are left untouched. The correct-answer value, the option set, and every
explanation are preserved exactly; only order and the index change.

Result: A 23.8% / B 26.3% / C 23.5% / D 26.4%.

The script doubles as a CI guard: `--check` exits non-zero if any quiz is not
de-biased, wired into the curriculum workflow so new lessons cannot regress.

Fixes #368
2026-08-01 14:24:15 +01:00

79 lines
2.8 KiB
JSON

{
"lesson": "15-indirect-prompt-injection",
"title": "Indirect Prompt Injection - Production Attack Surface",
"questions": [
{
"stage": "pre",
"question": "What distinguishes indirect prompt injection (IPI) from direct prompt injection?",
"options": [
"IPI is a synonym for jailbreaking",
"IPI embeds instructions inside external content (web pages, emails, tool outputs) that the agent consumes during normal operation, without the attacker touching the user's prompt",
"IPI only works on multimodal models",
"IPI requires fine-tuning the target model"
],
"correct": 1,
"explanation": ""
},
{
"stage": "check",
"question": "Which of these is NOT one of the three IPI delivery vectors listed in the lesson?",
"options": [
"Direct system-prompt edits by the user",
"Tool output",
"Inbox / document workflows",
"Retrieval-augmented generation (poisoned retrieval)"
],
"correct": 0,
"explanation": ""
},
{
"stage": "check",
"question": "Why do user-input filters miss IPI?",
"options": [
"Filters cannot read JSON",
"Filters only run after the model responds",
"User-input filters are case-sensitive",
"The payload never appears in the user's input; it appears in retrieved or tool-supplied content"
],
"correct": 3,
"explanation": ""
},
{
"stage": "check",
"question": "What is the central principle of Information Flow Control (IFC) for AI agents?",
"options": [
"Disable all tools by default",
"Encrypt all retrieved content",
"Label content by source as trusted or untrusted; actions triggered by untrusted content must be ratified by trusted input before execution",
"Use only single-turn prompts"
],
"correct": 2,
"explanation": ""
},
{
"stage": "post",
"question": "What did Nasr et al. (October 2025, 'The Attacker Moves Second') find about 12 published IPI defenses with adaptive attacks?",
"options": [
"Adaptive attacks were too expensive to evaluate",
"Their reported near-zero ASR held under adaptive attack",
"Adaptive attacks (gradient, RL, random search, human red-team) broke >90% of them despite their original near-zero ASR claims",
"Only one defense was broken"
],
"correct": 2,
"explanation": ""
},
{
"stage": "post",
"question": "Where does prompt injection rank in the 2025 OWASP LLM Top 10?",
"options": [
"LLM10 (lowest)",
"LLM01 (top, #1 application-layer threat)",
"Not listed",
"LLM05"
],
"correct": 1,
"explanation": ""
}
]
}