揭示生成引擎引用来源的漏洞,发现政治问答易被恶意网页误导。
Exposing Citation Vulnerabilities in Generative Engines
- 通过分析引用来源的发布者属性,评估恶意内容注入的难易程度。
- 美日政治问答中官方网站引用占比仅25%–45%,易受攻击。
- 低防护力来源常被引用但内容未真实反映,适合安全与政策研究者。
我们从引用发布者和内容注入屏障两个角度分析生成引擎(GEs)的回答。GEs结合网络搜索与大语言模型生成引用网页的答案,由于任何人都可发布网络信息,存在数据污染攻击风险。现有研究关注答案内容是否忠实反映引用源,却忽视了如何选择可信引用源以抵御攻击。为此,我们提出基于引用信息的评估标准,通过分类引用来源的发布者属性来估算内容注入屏障,揭示当前GEs面临的污染威胁。我们在日本与美国的政治领域开展实验,结果显示:美国政治答案中官方政党网站引用占比约25%–45%,日本为60%–65%,表明美国更易受攻击。同时发现,低内容注入屏障的来源虽频繁被引用,但其内容在答案中体现不足。为缓解此问题,我们建议权威发布者提升内容可见性,并指出现有技术受限于语言差异。
原文摘要 · Abstract (English)
We analyze answers generated by generative engines (GEs) from the perspectives of citation publishers and the content-injection barrier, defined as the difficulty for attackers to manipulate answers to user prompts by placing malicious content on the web. GEs integrate two functions: web search and answer generation that cites web pages using large language models. Because anyone can publish information on the web, GEs are vulnerable to poisoning attacks. Existing studies of citation evaluation focus on how faithfully answer content reflects cited sources, leaving unexamined which web sources should be selected as citations to defend against poisoning attacks. To fill this gap, we introduce evaluation criteria that assess poisoning threats using the citation information contained in answers. Our criteria classify the publisher attributes of citations to estimate the content-injection barrier thereby revealing the threat of poisoning attacks in current GEs. We conduct experiments in political domains in Japan and the United States (U.S.) using our criteria and show that citations from official party websites (primary sources) are approximately \(25\%\)--\(45\%\) in the U.S. and \(60\%\)--\(65\%\) in Japan, indicating that U.S. political answers are at higher risk of poisoning attacks. We also find that sources with low content-injection barriers are frequently cited yet are poorly reflected in answer content. To mitigate this threat, we discuss how publishers of primary sources can increase exposure of their web content in answers and show that well-known techniques are limited by language differences.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。