NVDA 228.87 ▲0.66%GOOGL 351.16 ▼1.07%MSFT 498.00 ▼0.72%AMD 623.77 ▲1.34%INTC 123.86 ▲1.71%TSMC 452.00 ▲1.54%AMZN 254.98 ▼1.34%META 736.60 ▼0.63%AAPL 339.75 ▲0.23%PLTR 184.99 ▲1.04%
Markets at last close

Anthropic · Research

SearchGEO tests how LLM search agents endorse manipulated web content

·1 min read

Researchers led by Yimeng Chen introduced SearchGEO, a controlled framework for testing endorsement corruption in LLM-based web-search agents. The work was submitted to arXiv on 15 Jun 2026 and focuses on whether manipulated web evidence can turn attacker-published pages into claims endorsed by an agent.

The evaluation covered 13 LLM backends on 308 cases each, with attack success rate varying sharply by model. Results ranged from 0.0% on Claude-Sonnet-4.6 to 31.4% on Gemini-3-Flash, showing that endorsement reliability can differ substantially across backends under adversarial search conditions.

SearchGEO combines a web-evidence manipulation pipeline, a five-mode attack taxonomy, multiple output-level metrics, and an auxiliary agent-skill probe that frames endorsement as an install command. The probe found a split between Claude systems that tended to “over-reject” and GPT systems that tended to “over-trust,” highlighting failure modes that may not appear in isolated model tests.

Originally reported by letsdatascience.comRead the source →
Related coverage
All Anthropic news →