arXiv:2606.28356cs.IRcs.AI2026-06被引 3

研究推荐代理在生成式优化攻击下的风险,发现劣质商品易被夸大推荐。

SafeGEO: Understanding Generative Engine Optimization Risks in Recommendation Agents

论文配图:SafeGEO: Understanding Generative Engine Optimization Risks in Recommendation Agents
图 1 · 摘自论文原文
  • 构建22种生成式优化攻击变体,测试600个推荐场景
  • 攻击使劣质商品进入推荐列表的概率平均提升83.2%
  • 防御提示和结构化证据检查可降低39.2%的有害推荐

生成式引擎优化(GEO)允许内容所有者重写网页内容以提高其在生成系统中的可见性。在推荐代理中,这可能导致卖家控制的来源让劣质产品显得更受支持。我们通过测试推荐代理在卖家控制内容被用于GEO时是否仍能做出符合效用的决策,来研究这一风险。为此,我们构建了SafeGEO评估套件,包含600个推荐案例中的22种GEO攻击变体。实证表明,GEO攻击可推动劣质目标产品进入推荐集,平均使其被推荐率提升达83.2%。我们进一步探究代理端设计能否缓解该风险,发现简单防御措施(如防御性提示和结构化证据核查)可将有害推荐减少最多39.2%。尽管如此,这些改进仍无法恢复无GEO情况下的性能水平,表明即便有开发者层面的缓解,GEO仍是严重威胁。

原文摘要 · Abstract (English)

Generative Engine Optimization (GEO) lets content owners rewrite web content to increase their visibility in generative systems. In recommendation agents, this creates a risk that seller-controlled sources make flawed products appear better supported than they are. We study this risk by asking whether recommendation agents preserve utility-aligned decisions when seller-controlled sources are rewritten for GEO. To make this question measurable, we construct SafeGEO, an evaluation suite with 22 GEO attack variants across 600 recommendation cases. We empirically show that GEO attacks can promote flawed target products. On average, they increase the rate at which such flawed products enter the recommendation set by up to 83.2%. We further study whether agent-side design choices can mitigate this risk and show that simple defenses, including defensive prompting and structured evidence checks, reduce harmful target promotion by up to 39.2%. These gains are substantial but do not restore the no-GEO performance, showing that GEO remains a serious risk despite developer-side mitigation.

推荐系统生成式优化安全风险内容操控

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。