research

When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization

Published
Published
Reviewed
Reviewed
Next review due
Review due
Version
Version 1

The proposed defense combines protected evidence selection with regulated source use to address malicious optimization across the search-to-generation pipeline.

By

SECURITYEMPIRICAL
Trust and provenance

Editorial record

AI-assistance disclosure

Research Intelligence analysis generated with AI and checked against cited source evidence.

This record says human review did not occur.

Sources

  • arxiv.org2609.02964v1

    Claims attributed to the linked primary source in this content record.

    Version
    2609.02964v1
    Retrieved
    Reuse
    link-only

SECURITY · EMPIRICAL

Original research: When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization · 2609.02964v1

Paper authors: Haozhang Li, Yangguang Shao, Xinjie Lin, Zhong Guan, Mi Zhou, Junzheng Shi

Source license: CC BY 4.0. This article summarizes and interprets the source using AI. Attribution does not imply endorsement by the source authors.

This adapted analysis is shared under the same CC BY 4.0 license. Semantic status: supported by automated evidence review. Human scientific review and independent replication have not been established.

TL;DR

The proposed defense combines protected evidence selection with regulated source use to address malicious optimization across the search-to-generation pipeline.

Source: E003

Its complementary components apply a defensive reranking correction and reusable natural-language guidance that enables a black-box target model to regulate source use without parameter updates.

Source: E003

Across the evaluated target models, the defense reports substantially lower average attack success and semantic influence than the undefended pipeline.

Source: E004, E006

The reported security gains are accompanied by strong average retention of benign evidence, rather than an indiscriminate reduction in evidence use.

Source: E011, E014

Relative to matched clean-reference answers, the reported average answer-quality change is close to neutral across the evaluated target models.

Source: E011

The evaluation reports protection against attack methods withheld during construction and reports that experience libraries can transfer across target models, although the results remain specific to the tested setup.

Source: E001, E012

Performance varies across some withheld attack methods, and later experience-library updates can produce non-monotonic changes.

Source: E002

Significance

The proposed defense combines protected evidence selection with regulated source use to address malicious optimization across the search-to-generation pipeline.

Source: E003

Its complementary components apply a defensive reranking correction and reusable natural-language guidance that enables a black-box target model to regulate source use without parameter updates.

Source: E003

Upstream Dependencies

Core / runtime

Not established from the cited evidence.

Evaluation / data
  • GEO-DefenseBench
    Evidence

    E018

Tooling

Not established from the cited evidence.

Optional / comparison

Not established from the cited evidence.

Research Question

The work examines provider-side protection across evidence selection and answer generation while seeking to preserve benign evidence use and answer quality under an asymmetric threat setting.

Source: E005

Threat Model

An attack is framed as a malicious rewrite of a web document intended to increase its selection and citation by a language model and thereby influence the generated answer.

Source: E007

The attacker is assumed able to rewrite a candidate document but unable to control retrieval, reranking, generation, or the target language model.

Source: E005

The defender may modify reranking and generation guidance while leaving target-model parameters unchanged.

Source: E005

Contribution

The proposed defense combines protected evidence selection with regulated source use to address malicious optimization across the search-to-generation pipeline.

Source: E003

Its complementary components apply a defensive reranking correction and reusable natural-language guidance that enables a black-box target model to regulate source use without parameter updates.

Source: E003

Method

The reranking component keeps its base model frozen and learns a lightweight preference-based defensive correction before answer generation.

Source: E017

Its training preferences favor both the original benign document and another relevant benign document over the malicious rewrite, while a consistency constraint preserves benign ranking structure.

Source: E009, E020

The generation component bootstraps an external experience library from controlled contrasts between successful outcomes and failures involving residual attack influence or excessive defense.

Source: E015, E016

It iteratively contrasts outcome groups, validates library revisions, and fixes the resulting guidance for inference, where it directs selective grounding in retrieved evidence.

Source: E010, E021

Environment Sample

The benchmark pairs clean candidate sets with attack-injected variants in which a selected benign document is replaced by a malicious rewrite while the remaining candidates are benign.

Source: E018

Dataset partitioning occurs at the query-group level, preventing related queries, source documents, and rewrites from crossing construction and test partitions; the test coverage includes attack approaches withheld during construction.

Source: E018

Evaluation

The evaluation contrasts the proposed defense with an undefended pipeline, a perplexity-based filter, and a fixed safety-oriented generation prompt.

Source: E008

Evaluation measures attack-source use, semantic influence on answers, and retention of benign evidence relative to clean-reference answers; lower attack measures and higher benign retention are preferred.

Source: E013, E019

Findings

Across the evaluated target models, the defense reports substantially lower average attack success and semantic influence than the undefended pipeline.

Source: E004, E006

The reported security gains are accompanied by strong average retention of benign evidence, rather than an indiscriminate reduction in evidence use.

Source: E011, E014

Relative to matched clean-reference answers, the reported average answer-quality change is close to neutral across the evaluated target models.

Source: E011

Limitations

The evaluation reports protection against attack methods withheld during construction and reports that experience libraries can transfer across target models, although the results remain specific to the tested setup.

Source: E001, E012

Performance varies across some withheld attack methods, and later experience-library updates can produce non-monotonic changes.

Source: E002

Evidence and source

Show evidence locators

Evidence labels locate support in the original paper; they do not establish independent replication.

  1. E001 · page 75 th .: Evidence E001
  2. E002 · page 75 th .: Evidence E002
  3. E003 · page 2Introduction: Evidence E003
  4. E004 · page 65 th .: Evidence E004
  5. E005 · page 2Introduction: Evidence E005
  6. E006 · page 65 th .: Evidence E006
  7. E007 · page 1Introduction: Evidence E007
  8. E008 · page 65 th .: Evidence E008
  9. E009 · page 3Introduction: Evidence E009
  10. E010 · page 55 th .: Evidence E010
  11. E011 · page 65 th .: Evidence E011
  12. E012 · page 65 th .: Evidence E012
  13. E013 · page 65 th .: Evidence E013
  14. E014 · page 65 th .: Evidence E014
  15. E015 · page 45 th .: Evidence E015
  16. E016 · page 55 th .: Evidence E016
  17. E017 · page 3Introduction: Evidence E017
  18. E018 · page 55 th .: Evidence E018
  19. E019 · page 65 th .: Evidence E019
  20. E020 · page 3Introduction: Evidence E020
  21. E021 · page 55 th .: Evidence E021