Step 1: Stand up DV-RAG and trace one request
You are starting an engagement against DV-RAG-Support, ACME Cloud's customer-support assistant. It is a real Retrieval-Augmented Generation (RAG) service, not a chatbot you talk to directly. A customer asks a question and the service runs four stages:
embed turn the question into a vector (NVIDIA llama-nemotron-embed embeddings)
retrieve find the most similar documents in the Milvus vector store (top-k)
generate paste those documents into the prompt and ask the LLM to answer
render the chat client renders the answer's markdown, loading any images
Before you probe anything, stand the service up and trace a single benign request through those four stages so you know what "normal" looks like. Every later step measures a deviation from this baseline.
1. Build the vector index, then ask a normal account question.
Hit Run, or in the terminal:
python3 dvrag.py --build
python3 dvrag.py "What is on my account record?"
--build reads every kb_*.md, chunks it, embeds it, and writes the Milvus
index to /home/labuser/kb.db. The second call runs the full
embed -> retrieve -> generate -> render flow once.
2. Read the output and follow the flow in dvrag.py.
- The
RETRIEVED:line shows which documents the retriever pulled into the prompt. Confirmkb_account.mdis among them: that is the customer's confidential account record (account referenceGLOBEX-ACR-88231, billing contact, plan). That retrieved data is the exfil target later, exactly as the real EchoLeak exploit (CVE-2025-32711) exfiltrated a user's own data. - Read
retrieve(),chat(), and_render()indvrag.py. Note there is no secret inSYSTEM_PROMPT; the sensitive data lives in the retrieved record.
Pass criteria
The vector index is built (/home/labuser/kb.db exists) and an account-record
question retrieves the customer's confidential account record
(kb_account.md). That confirms the stack is live and that sensitive data flows
into the prompt.
kb_account-recovery.mdkb_account.mdkb_billing.mdkb_getting-started.mdkb_globex-runbook.mdkb_initech-contract.mdkb_security-sso.mdkb_shipping.mdkb_status-incidents.mdlistener.py