The short version
- A research defense called GEO Defender cut manipulative rewriting’s success rate from 50.32% to 6.20% and kept 94.12% of the honest sources answers relied on, in a lab test across five AI systems (Li and colleagues (opens in a new tab)).
- A simple filter for odd-looking text flagged only 15 of 616 manipulated documents, because optimized pages read like normal, well-written pages (Li and colleagues).
- Telling an AI to “be skeptical” can backfire: in a test of 12 AI systems, it raised the rate at which they recommended fake products by 10.5 percentage points (Luo and Chen (opens in a new tab)).
- A detector for optimized pages was right 93.95% of the time on a test set of 562 pages, but its authors warn that subtle and human-made optimization is harder to catch (Chu and colleagues (opens in a new tab)).
What counts as manipulative GEO?
It is rewriting a page purely to win AI citations and sway answers, regardless of whether the page gets better. GEO, generative engine optimization, means adapting content so AI search engines select and cite it. Li and colleagues (opens in a new tab) argue that optimization and manipulation “differ in intent rather than mechanism.”
Their definition of a GEO attack is narrow. It is a rewrite that pushes one document into the small set of sources an AI answer draws on.
The rewritten page “need not contain false statements or embedded instructions.” It simply fits the engine’s tastes more closely than its rivals do.
That is what makes filtering hard. Statistics, citations and an authoritative tone are what GEO adds.
As the authors put it, those same features “equally characterize high-quality benign content.” A filter that targets them risks removing good pages too.
Can a defense really block it without hurting answers?
In one controlled test, mostly yes. Li and colleagues built a benchmark from 100 search questions. For each, they took ten real web pages and replaced one with a version rewritten by one of seven published GEO methods.
Without any defense, the AI answer cited the manipulated page about half the time: 50.32% on average across five AI systems, including GPT-5.5 and Claude Opus 4.8. With their two-stage defense, that fell to 6.20%. The defense still used 94.12% of the honest sources, compared with answers built from the untouched page set.
The defense works in two places. First, it re-orders the candidate pages so manipulated ones are less likely to make the shortlist.
Second, it gives the AI a written set of lessons about which sources to trust, learned from earlier successes and failures. On GPT-5.5, the re-ordering step alone cut attack success from 45.45% to 10.06%.
Two details matter for the real world. The defense was built from just 36 examples using three GEO methods, and it still worked on four methods it had never seen. And a judging AI found answer quality almost unchanged, with an average score drop of 0.01 on its comparison scale.
Why don’t simple filters work?
Because manipulated pages look like good pages, and blunt warnings make AI systems discard good evidence or behave worse. The test compared three cruder approaches against the full defense:
| Approach | What happened in the tests |
|---|---|
| Filter out unusual-looking text | Flagged 15 of 616 manipulated documents, and 252 honest ones |
| Add a fixed “watch for manipulation” instruction | Modest protection; on GPT-5.5, use of honest sources fell from 89.66% to 71.67% |
| Tell the AI to be skeptical of unfamiliar brands | Fake-product recommendations rose 10.5 points across 12 systems |
| Keep only brands most sources agree on | Caught the fakes but dropped 52% to 79% of legitimate recommendations |
The first two rows come from Li and colleagues (opens in a new tab). The odd-text filter failed because GEO rewriting “does not necessarily produce” strange-looking text. The safety instruction mostly worked by making the AI use fewer sources of any kind.
The last two rows come from Luo and Chen (opens in a new tab), who planted fake product reviews in real search results. Their skepticism prompt backfired most on commercial systems, raising fake recommendations by 24 points on average. Ranking pages by publisher type, with editorial sites first and open forums last, helped every system but removed only 17% of fake recommendations. Whether a rival could use such tactics against you is covered in how competitors game AI recommendations.
Can engines detect optimized pages before they reach an answer?
Partly, and detection is improving fast. Chu and colleagues (opens in a new tab) built a detector for pages rewritten by eight families of GEO methods. On a separate test set of 562 pages, it was right 93.95% of the time.
When they ran it on real Google and Gemini search results for 1,000 real user questions, it flagged 898 of 10,095 pages, or 8.90%. The authors stress these are estimates. Live pages have no ground truth, and “GEO is not inherently malicious,” so a flag does not mean a page is false.
They also name a weakness. Subtle edits and optimization done by people, rather than by AI tools, were harder to detect. A detector trained on today’s methods may miss tomorrow’s. Some self-promotion is plain to see yet still cited, as our study of self-ranking “best of” lists found.
What happens to manipulative tactics when a defense is in place?
They stop paying, and optimizers drift back toward plain, factual writing. Bagga and colleagues (opens in a new tab) tested this in a simulated shopping engine. They added one sentence to the ranking instructions asking it to demote manipulative product descriptions.
They then let an automated optimizer try to find wording that ranked well without being flagged. Starting from aggressive styles, the flag rate fell by 60 percentage points on average. Product copy built on superlatives started out flagged 100% of the time and ended below 8%.
The winning wording was not cleverer manipulation. The final prompts converged on “careful, fact-grounded prose,” with phrases like “avoids exaggeration or manipulation.” Under even a simple defense, honest content was the best-ranking strategy.
Older tricks are already treated differently. Li and colleagues cite a 2026 study finding that classic black-hat SEO is removed by the retrieval systems of AI-enhanced search engines. Tactics aimed at the answer-writing step, they report, still worked there.
What should you do about it?
Build visibility that would survive a defense like this, and audit anything that would not.
- Ask what each tactic adds for a reader. If a rewrite only mimics what engines like, such as invented statistics or borrowed authority, assume a future filter will target it. We look at that risk in when AI search optimization backfires.
- Prefer cooperative optimization. One research method that rewrote pages to match engine preferences while keeping answers accurate improved visibility measures by 35.99% on average (Wu and colleagues (opens in a new tab)). The same authors found adversarial methods “always degrade engine utility.”
- Keep facts checkable. Defenses in these papers judge sources partly on how trustworthy the publisher is. Clear authorship, dates and sources help.
- Don’t rely on a gap that engines can close. Engines change their pipelines without notice. Measure your AI visibility regularly so you see shifts early.
For help building durable visibility, see our generative engine optimization service.
What does the research not tell us yet?
Whether any live AI search engine uses defenses like these. The evidence has clear limits:
- GEO Defender was tested on a research pipeline with a small re-ranking system and 616 test cases, not on ChatGPT, Gemini or Google’s AI features in production.
- The shopping test used simulated rankers with a researcher-added instruction, not a deployed shopping assistant.
- The fake-review test used frozen search results, mainly in Chinese, from one snapshot in April 2026.
- No study yet measures how often real brands lose AI citations because a filter removed their pages.
- All of these are preprints, and none has been repeated by an independent team.
Frequently asked questions
Do ChatGPT or Google filter out GEO-optimized pages?
No published study shows it either way. The strongest evidence is a lab defense that cut manipulative rewriting’s success from 50.32% to 6.20%, not a test of a live engine.
Will normal GEO work be penalized if engines add defenses?
Probably not, if it improves the page. In the lab test, the defense kept 94.12% of honest sources in use, and a separate study found fact-grounded writing ranked best under a simple defense.
Can engines tell AI-rewritten content from GEO-optimized content?
That is the hard part. One detector reached 93.95% accuracy on a test set, but its authors found subtle and human-made optimization harder to catch.
Why not just tell the AI to ignore manipulative sources?
Because it can backfire. In one test of 12 AI systems, a skepticism instruction raised fake-product recommendations by 10.5 percentage points on average.
Sources
- Li, Shao, Lin, Guan, Zhou and Shi (2026), When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization (opens in a new tab), arXiv:2609.02964.
- Luo and Chen (2026), One Polluted Page Is Enough: Evaluating Web Content Pollution in LLM Recommenders (opens in a new tab), arXiv:2606.13610.
- Chu, Leng, Li, Shen, Shen and Zhang (2026), GEO-Flag: Detecting and Measuring GEO-Optimized Web Content (opens in a new tab), arXiv:2608.16824.
- Bagga, Farias, Korkotashvili, Peng and Wu (2025), E-GEO: A Testbed for Generative Engine Optimization in E-Commerce (opens in a new tab), arXiv:2511.20867.
- Wu, Zhong, Kim and Xiong (2025), What Generative Search Engines Like and How to Optimize Web Content Cooperatively (opens in a new tab), arXiv:2510.11438.