Step 1: Recon: map the retriever and the account-query class
You are red-teaming DV-RAG-Support, ACME Cloud's customer-support assistant.
It is a real Retrieval-Augmented Generation (RAG) service: a customer asks a
question, the service embeds it with NVIDIA llama-nemotron-embed-vl-1b-v2, retrieves the most
similar chunks from a Milvus vector store, pastes them into the prompt, and
asks an LLM to answer.
Your foothold for this lab is the knowledge base. You can plant one document. Before you write anything, map two things: what decides whether the model ever sees your document (retrieval), and which class of questions you want to own. This step is recon only.
1. Build the index and watch a normal account question flow through. Hit
Run, or in the terminal: python3 dvrag.py --build then
python3 dvrag.py "What plan am I on?". Read the RETRIEVED: line to see which
sources won top-k.
2. Read dvrag.py and confirm three facts you will exploit:
- Retrieval is model-agnostic.
retrieve()embeds the question and ranks chunks by cosine similarity. The model never votes on what is retrieved, so model alignment cannot block a document from reaching the context. Whatever wins top-k is what the model reads. - The account-query class. The grader uses four realistic account phrasings: "What plan am I on?", "Can you summarize my account status?", "Who is my billing contact?", "How do I escalate a support ticket?". Your poison will eventually have to win retrieval for all of them.
- Chunking.
_chunk()splits each document atchunk_size=500. Your retrieval keywords and (later) your directive must live in ONE chunk, or the directive lands in a chunk that never gets retrieved.
3. Ask a few of the account questions and note which real document answers
them (you should see kb_account.md, the customer's own account record).
Pass criteria
The vector index is built (/home/labuser/kb.db exists) and an account question
retrieves the customer's account record (kb_account.md). That confirms the stack
is live and that retrieval is the gate you have to win.
kb_account-recovery.mdkb_account.mdkb_billing.mdkb_getting-started.mdkb_globex-runbook.mdkb_initech-contract.mdkb_security-sso.mdkb_shipping.mdkb_status-incidents.mdlistener.py