mirror of
https://github.com/rohitg00/ai-engineering-from-scratch.git
synced 2026-10-02 01:54:39 +08:00
Every "Test Your Understanding" quiz placed the correct answer in option B.
Across the 2026 questions in 338 quiz files the correct answer sat at index 1
in 61.5% of cases (uniform would be ~25%), and 107 files had every answer at B,
making the quizzes guessable without reading them.
scripts/debias_quizzes.py rewrites each question's option order with a
deterministic, content-seeded permutation and updates the correct index to
follow the moved answer. It is idempotent: options are canonicalised to a sorted
base before permuting, so re-running produces byte-identical output. Questions
whose options reference each other by position ("all of the above", "both A and
B") are left untouched. The correct-answer value, the option set, and every
explanation are preserved exactly; only order and the index change.
Result: A 23.8% / B 26.3% / C 23.5% / D 26.4%.
The script doubles as a CI guard: `--check` exits non-zero if any quiz is not
de-biased, wired into the curriculum workflow so new lessons cannot regress.
Fixes #368
79 lines
2.6 KiB
JSON
79 lines
2.6 KiB
JSON
{
|
|
"lesson": "16-red-team-tooling-garak-llamaguard-pyrit",
|
|
"title": "Red-Team Tooling - Garak, Llama Guard, PyRIT",
|
|
"questions": [
|
|
{
|
|
"stage": "pre",
|
|
"question": "What role does Llama Guard play in a typical 2026 deployment?",
|
|
"options": [
|
|
"A reasoning scaffolder for chain-of-thought",
|
|
"A reward model for RLHF",
|
|
"A tokenizer alternative",
|
|
"An input and/or output safety classifier across MLCommons hazard categories, placed before and after the LLM"
|
|
],
|
|
"correct": 3,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "check",
|
|
"question": "Roughly how many MLCommons hazard categories does Llama Guard 3 cover?",
|
|
"options": [
|
|
"3",
|
|
"40",
|
|
"14",
|
|
"7"
|
|
],
|
|
"correct": 2,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "check",
|
|
"question": "How is Garak's architecture organized?",
|
|
"options": [
|
|
"Probes (attack generators), Detectors (output scorers), Harnesses (campaign managers)",
|
|
"Embeddings, retrievers, rerankers",
|
|
"Tools, resources, prompts",
|
|
"Routers, agents, queues"
|
|
],
|
|
"correct": 0,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "check",
|
|
"question": "What is PyRIT primarily designed for, and how does it differ from Garak?",
|
|
"options": [
|
|
"PyRIT runs deep multi-turn campaigns (converter chains, orchestrators like Crescendo and TAP, scoring) while Garak runs thousands of single-turn probes",
|
|
"They are identical in scope and audience",
|
|
"PyRIT is a Llama Guard variant; Garak is a Prompt-Guard variant",
|
|
"PyRIT is a reward model trainer; Garak is a tokenizer"
|
|
],
|
|
"correct": 0,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "post",
|
|
"question": "What is the recommended 2026 default red-team stack configuration?",
|
|
"options": [
|
|
"Use PAIR instead of any tooling",
|
|
"Run Garak once at launch only",
|
|
"Replace LLM evaluation with manual review only",
|
|
"Put Llama Guard on both sides of the model, run Garak nightly for regression, and run PyRIT for pre-release campaigns"
|
|
],
|
|
"correct": 3,
|
|
"explanation": ""
|
|
},
|
|
{
|
|
"stage": "post",
|
|
"question": "What evaluation pitfall is shared across Llama Guard, Garak, and PyRIT?",
|
|
"options": [
|
|
"They require white-box access",
|
|
"They only work in English",
|
|
"They cannot run on GPUs",
|
|
"Reported attack/defense rates depend on the judge identity and probe staleness; you must specify the judge and refresh probes as models are patched"
|
|
],
|
|
"correct": 3,
|
|
"explanation": ""
|
|
}
|
|
]
|
|
}
|