IRAIJun 8

SafeGEO: Understanding Generative Engine Optimization Risks in Recommendation Agents

arXiv:2606.28356
Originality Incremental advance
AI Analysis

For developers of recommendation agents, this paper identifies and quantifies a new security risk from GEO, showing that existing systems are vulnerable and that simple defenses are insufficient.

The paper studies how Generative Engine Optimization (GEO) can be exploited by sellers to promote flawed products in recommendation agents, showing that GEO attacks increase the rate of flawed products entering the recommendation set by up to 83.2%, and that simple defenses reduce harmful promotion by up to 39.2% but do not fully restore baseline performance.

Generative Engine Optimization (GEO) lets content owners rewrite web content to increase their visibility in generative systems. In recommendation agents, this creates a risk that seller-controlled sources make flawed products appear better supported than they are. We study this risk by asking whether recommendation agents preserve utility-aligned decisions when seller-controlled sources are rewritten for GEO. To make this question measurable, we construct SafeGEO, an evaluation suite with 22 GEO attack variants across 600 recommendation cases. We empirically show that GEO attacks can promote flawed target products. On average, they increase the rate at which such flawed products enter the recommendation set by up to 83.2%. We further study whether agent-side design choices can mitigate this risk and show that simple defenses, including defensive prompting and structured evidence checks, reduce harmful target promotion by up to 39.2%. These gains are substantial but do not restore the no-GEO performance, showing that GEO remains a serious risk despite developer-side mitigation.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes