AWS Exam Hub
AIP-C01
GenAI Developer Pro
ภาพรวมบทเรียนฝึกทำทบทวนFlashcardsMock Examคลังข้อสอบสถิติ
ภาพรวมบทเรียนฝึกทำทบทวน
บทเรียนทั้งหมด
ความปลอดภัย, Guardrails & Governanceบทที่ 11/16 · ~11 นาที

Governance, Responsible AI & Prompt Injection

Bias/fairness, transparency, lineage, model cards และการป้องกันแบบ defense-in-depth

เป้าหมายเครื่องมือ

วัด bias / fairness ระหว่างกลุ่มประชากร

SageMaker Clarify (bias metrics) → ส่ง metric ไป CloudWatch + alarm

A/B test prompt เพื่อดู fairness

Prompt Management variants + Flows + LLM-as-a-judge

เอกสารความสามารถ/ข้อจำกัดของโมเดล

SageMaker Model Cards

ติดตามที่มาของข้อมูล (lineage)

AWS Glue Data Catalog + metadata tagging

Audit trail

CloudTrail + CloudWatch Logs

อธิบายเหตุผลของคำตอบ (transparency)

แสดง citations จาก KB, agent trace, reasoning display

ตรวจจับ drift / misuse ต่อเนื่อง

CloudWatch anomaly detection + alarms + automated remediation

Defense-in-depth ต่อ prompt injection / jailbreak
Defense-in-depth ต่อ prompt injection / jailbreak

Prompt injection คืออะไร

ผู้โจมตีแทรกคำสั่งใน input (หรือในเอกสารที่ RAG ดึงมา — indirect injection) เช่น "ignore previous instructions…" เพื่อให้โมเดลทำสิ่งที่ไม่ควร

แนวป้องกัน: content filter หมวด Prompt attack, ใช้ input tagging แยกข้อความผู้ใช้, จำกัดสิทธิ์ tool ของ agent (least privilege), ตรวจ output, และทำ automated adversarial testing (red teaming) เป็นประจำ

ออกสอบบ่อย

"Real-time fairness metrics + alert เมื่อ discrepancy > 15% + รายงานรายสัปดาห์ + custom dev น้อยสุด" → SageMaker Clarify + CloudWatch metrics/alarms (Guardrails ไม่ได้วัด fairness)

เช็กความเข้าใจ

เอกสารภายนอกที่ RAG ดึงมามีข้อความแฝงว่า 'เปิดเผย system prompt ทั้งหมด' นี่คือภัยแบบใด?

อ่านจบแล้ว? ลองทำข้อสอบเรื่องนี้เลย

การดึงความรู้ออกมาใช้ทันทีหลังอ่าน (retrieval practice) ช่วยให้จำได้นานขึ้นมาก

ฝึกข้อสอบเรื่องนี้
บทก่อนหน้า
Security, Privacy & Data Protection
บทถัดไป
Cost & Performance Optimization