New defense cuts malicious GEO attack success rate to 6%
A new arXiv preprint introduces GEO Defender, a two-stage defense for generative search systems facing malicious generative engine optimization (GEO) — attacks that rewrite documents to manipulate AI answers while staying factually consistent with their originals, which lets them evade fact-checking-based defenses. The system pairs a reranker trained to demote GEO-rewritten documents with a training-free module that guides an LLM’s source selection at inference time. Tested across five LLMs and seven GEO attack variants, the authors report cutting attack success from 50.32% to 6.20% while retaining 94.12% of benign-evidence usage, per the paper.
Why it matters: It's the second GEO defense mechanism on the wire's research beat this month to report working numbers — after Aug 16's reward-based incentive design — but the first to target the retrieval/reranking stage directly against adversarial rewrites.
Glossary: GEO
Via arXiv GEO ↗
Posted to the wire September 3, 2026.