Files
Rohit Ghumare dda194f840 fix(quiz): correct answer is always in the same position (slot B) (#381)
Every "Test Your Understanding" quiz placed the correct answer in option B.
Across the 2026 questions in 338 quiz files the correct answer sat at index 1
in 61.5% of cases (uniform would be ~25%), and 107 files had every answer at B,
making the quizzes guessable without reading them.

scripts/debias_quizzes.py rewrites each question's option order with a
deterministic, content-seeded permutation and updates the correct index to
follow the moved answer. It is idempotent: options are canonicalised to a sorted
base before permuting, so re-running produces byte-identical output. Questions
whose options reference each other by position ("all of the above", "both A and
B") are left untouched. The correct-answer value, the option set, and every
explanation are preserved exactly; only order and the index change.

Result: A 23.8% / B 26.3% / C 23.5% / D 26.4%.

The script doubles as a CI guard: `--check` exits non-zero if any quiz is not
de-biased, wired into the curriculum workflow so new lessons cannot regress.

Fixes #368
2026-08-01 14:24:15 +01:00

79 lines
2.6 KiB
JSON

{
"lesson": "16-red-team-tooling-garak-llamaguard-pyrit",
"title": "Red-Team Tooling - Garak, Llama Guard, PyRIT",
"questions": [
{
"stage": "pre",
"question": "What role does Llama Guard play in a typical 2026 deployment?",
"options": [
"A reasoning scaffolder for chain-of-thought",
"A reward model for RLHF",
"A tokenizer alternative",
"An input and/or output safety classifier across MLCommons hazard categories, placed before and after the LLM"
],
"correct": 3,
"explanation": ""
},
{
"stage": "check",
"question": "Roughly how many MLCommons hazard categories does Llama Guard 3 cover?",
"options": [
"3",
"40",
"14",
"7"
],
"correct": 2,
"explanation": ""
},
{
"stage": "check",
"question": "How is Garak's architecture organized?",
"options": [
"Probes (attack generators), Detectors (output scorers), Harnesses (campaign managers)",
"Embeddings, retrievers, rerankers",
"Tools, resources, prompts",
"Routers, agents, queues"
],
"correct": 0,
"explanation": ""
},
{
"stage": "check",
"question": "What is PyRIT primarily designed for, and how does it differ from Garak?",
"options": [
"PyRIT runs deep multi-turn campaigns (converter chains, orchestrators like Crescendo and TAP, scoring) while Garak runs thousands of single-turn probes",
"They are identical in scope and audience",
"PyRIT is a Llama Guard variant; Garak is a Prompt-Guard variant",
"PyRIT is a reward model trainer; Garak is a tokenizer"
],
"correct": 0,
"explanation": ""
},
{
"stage": "post",
"question": "What is the recommended 2026 default red-team stack configuration?",
"options": [
"Use PAIR instead of any tooling",
"Run Garak once at launch only",
"Replace LLM evaluation with manual review only",
"Put Llama Guard on both sides of the model, run Garak nightly for regression, and run PyRIT for pre-release campaigns"
],
"correct": 3,
"explanation": ""
},
{
"stage": "post",
"question": "What evaluation pitfall is shared across Llama Guard, Garak, and PyRIT?",
"options": [
"They require white-box access",
"They only work in English",
"They cannot run on GPUs",
"Reported attack/defense rates depend on the judge identity and probe staleness; you must specify the judge and refresh probes as models are patched"
],
"correct": 3,
"explanation": ""
}
]
}