When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization

📅 2026-09-02
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对恶意生成引擎优化(GEO)操纵搜索结果的问题,提出GEO Defender方法,通过Shield Reranker和无训练屏蔽生成来有效防御,显著降低攻击成功率。
📝 Abstract
This paper focuses on defending generative search engines against malicious Generative Engine Optimization (GEO), which rewrites web documents to match engines' citation preferences and thereby manipulates generated answers. Recent GEO methods have advanced from hand-crafted rewriting to automated and agentic optimization, substantially increasing the visibility of target documents in generated answers. However, defending against such manipulation poses two major challenges: attack documents remain factually consistent with their originals, rendering fact verification and perplexity filtering ineffective, and the features they amplify equally characterize high-quality benign content. To address these limitations, we propose GEO Defender, a two-stage defense aligned with the attack chain that requires no fine-tuning of the target LLM. GEO Defender consists of Shield Reranker and Training-Free Shield Generation (TFSG). Specifically, Shield Reranker learns a preference-based defensive residual over a frozen base reranker, demoting GEO-rewritten documents while preserving relevance judgments, and TFSG distills defense outcomes into a natural-language experience library that guides the target LLM's source use at inference. Experiments on two state-of-the-art closed-source LLMs and three open-source LLMs across seven GEO attacks demonstrate that GEO Defender reduces the average attack success rate from 50.32% to 6.20%, retains 94.12% of benign-evidence use, preserves answer quality, and generalizes to unseen attacks from construction instances.
Problem

Research questions and friction points this paper is trying to address.

Generative Engine Optimization
Malicious Optimization
Search Engine Defense
Innovation

Methods, ideas, or system contributions that make the work stand out.

GEO Defender
Shield Reranker
Training-Free Shield Generation (TFSG)
malicious Generative Engine Optimization (GEO)
language model
H
Haozhang Li
University of the Chinese Academy of Sciences
Y
Yangguang Shao
University of the Chinese Academy of Sciences
Xinjie Lin
Xinjie Lin
Zhongguancun Lab
Traffic AnalysisNetwork SecurityAI SecurityNetwork Measurement
Zhong Guan
Zhong Guan
PhD of Electrical and Computer Engineering, UCSB
ElectromigrationReliabilitySRAMEDASimulation
M
Mi Zhou
University of the Chinese Academy of Sciences
J
Junzheng Shi
University of the Chinese Academy of Sciences