# New defense cuts malicious GEO attack success rate to 6%

Published: 2026-09-04T03:18:36.544Z · Source: arXiv GEO (https://arxiv.org/abs/2609.02964v1)
Source date: 2026-09-02

A new arXiv preprint introduces GEO Defender, a two-stage defense for generative search systems facing malicious generative engine optimization (GEO) — attacks that rewrite documents to manipulate AI answers while staying factually consistent with their originals, which lets them evade fact-checking-based defenses. The system pairs a reranker trained to demote GEO-rewritten documents with a training-free module that guides an LLM's source selection at inference time. Tested across five LLMs and seven GEO attack variants, the authors report cutting attack success from 50.32% to 6.20% while retaining 94.12% of benign-evidence usage, per the paper.

Why it matters: It's the second GEO defense mechanism on the wire's research beat this month to report working numbers — after Aug 16's reward-based incentive design — but the first to target the retrieval/reranking stage directly against adversarial rewrites.

## What this answers

**Can AI search defenses stop malicious GEO content manipulation?**

A new arXiv paper's two-stage 'GEO Defender' system — a reranker plus a training-free source-selection guide — cut attack success from 50.32% to 6.20% across five LLMs and seven attack variants, while keeping 94.12% of benign-source usage intact.

**What makes malicious GEO hard to detect?**

Per the paper, GEO-rewritten attack documents stay factually consistent with their originals, so fact-checking-based defenses miss them — the same features that make GEO content look high quality are what let it manipulate rankings.


Canonical: https://anythingengineoptimization.com/item/2026-09-04-new-defense-cuts-malicious-geo-attack-success-rate-to-6/
From Anything Engine Optimization (AEO Wire) — https://anythingengineoptimization.com/ · Standards: https://anythingengineoptimization.com/standards/
