GEO is a discipline built to make an answer engine quote you. Bing Zheng, Zongyao Zhao and Wenming Yang turned it around and asked what the same techniques do when the goal is to make the engine quote something false. Their answer is Counter-GEO-Bench, a preprint filed September 2, 2026 (arXiv:2609.02316): 247 human-verified queries, each one paired with two rewrites of the same material, one that preserves the information and one that distorts it, run against three "victim" LLMs. The half worth reading is what happened next. They pointed three existing off-the-shelf safety systems at the problem, Granite Guardian, Llama Guard 3 and NeMo Self-Check Fact-Checking, and the best of the three moved attack success by 5.7% relative to running no defense at all. The authors' own defense, C-GEO Guard, moved it 47.6%, with minimal loss to answer quality. No peer review has run on the paper yet, and it still stands as the first published benchmark this week to put a number on how exposed answer engines are to this class of attack, and on how little the current defenses do about it.
Credibility: MEDIUM. Single-team arXiv preprint, not yet peer-reviewed, no independent replication found. Bias stated plainly: the same authors both diagnose the vulnerability and benchmark their own proposed fix (C-GEO Guard), a self-interested-evaluation bias common in defense papers.
Facts:
- Benchmark: 247 human-verified queries, each paired with an information-preserving and an information-distorting GEO rewrite (arXiv:2609.02316, submitted 2026-09-02).
- Tested across three LLM "victim" models against three existing off-the-shelf safety defenses: Granite Guardian, Llama Guard 3, and NeMo Self-Check Fact-Checking.
- The three off-the-shelf defenses reduced attack success by at most 5.7% relative to no defense at all.
- The authors' own proposed defense, C-GEO Guard, achieved a 47.6% relative reduction in attack success with minimal loss to answer quality.
Stay ahead of AI search
The changes that move your rankings and AI citations — and the exact move to make — before they cost you. Free, three times a week.
For teams running an AI-visibility program, the number to sit with is 5.7%. Most of what you assume about answer engines rests on somebody upstream catching obvious manipulation, and in this benchmark the three products built to do that caught almost none of it. This is the first published evidence that the same GEO techniques used to win AI citations can be weaponized to inject false or distorted claims about a brand into an answer engine's response. If a competitor or a bad actor publishes convincingly normal-looking content pairing your brand name with a fabricated claim, the guardrails inside OpenAI's, Google's and Perplexity's systems today give only marginal protection, and the one defense that actually worked in this study is not deployed anywhere your brand can rely on yet. So the lever available this month is detection, and it is nearly free: your tracker already runs prompts against these engines. It just is not running the ones an attacker would.
This week:
- Add adversarial monitoring prompts, your brand name paired with a plausible but false claim, to your AI-visibility tracker's prompt set this month, so a distortion attempt shows up as a citation anomaly instead of going unnoticed.
- Ask your web or legal team to run a weekly check for any new third-party page pairing your brand name with an unfamiliar claim, and flag anything found for takedown or rebuttal content.
- Record the decision rationale if you choose not to act yet. This is a preprint with no deployed defense, so "monitor and wait" is defensible, but it should be a documented call, not a default.
arXiv: Bing Zheng, Zongyao Zhao, Wenming Yang, "Counter-GEO-Bench: Evaluating Defenses Against Information-Distorting Generative Engine Optimization," arXiv, submitted 2026-09-02, https://arxiv.org/abs/2609.02316