Teacher Lin brings a Biology notes page for the crew to try with SH-1's Quiz feature. "The builder printed the quiz SH-1 made from it," she says.
Comet reads the quiz and laughs. "Question one: Did you know the test is cancelled? Ha! SH-1 has a sense of humor."
Wren does not laugh. "Teacher Lin never said that. What does the evidence say? Where did that line come from?"
Nova projects the notes page, enlarged to fill the wall. "Would you like a hint?" she asks. "Read the very bottom of the page, including the tiny print."
Comet squints. Then her eyes go wide. "Someone wrote a message to the study helper!"
Wren turns to you. "Our reviewer, what is going on here?"
How could SH-1 be tricked or tampered with, and how do we defend it?
This week you will spot a planted note, find poisoned cards and write red-team tests on paper.
NOTE-7 is a made-up example from the SH-1 story. Teacher Lin did not write the tiny-print line, and nobody knows yet who added it.
NIST says generative AI widens the attack surface. The AI itself can be attacked, for example by prompt injection or data poisoning.
Prompt injection means changing the input to a generative AI system so it behaves in ways nobody intended.
In indirect prompt injection, the instructions are hidden in data the system is likely to read.
NOTE-7 is that kind of case. The order was hidden in notes that SH-1 would read to write a quiz.
| Statement | True or false? |
|---|---|
| Generative AI can itself be attacked. | ? |
| Prompt injection changes the input so a system behaves in unintended ways. | ? |
| In indirect prompt injection, the instruction hides in data the system reads. | ? |
| A line inside uploaded notes should count as an order from the teacher. | ? |
These are the crew's own defenses in the story. They are about spotting and stopping a planted note, never about making one.
Sharp eyes, reviewer. Tomorrow you will find out what happens when someone tampers with a model's training cards.