NVDA 223.67 ▼0.91%GOOGL 330.65 ▼2.28%MSFT 491.65 ▼0.47%AMD 521.10 ▲3.04%INTC 106.24 ▲1.69%TSMC 435.36 ▼0.83%AMZN 252.40 ▼1.78%META 653.69 ▲6.55%AAPL 315.34 ▼0.28%PLTR 169.53 ▼0.45%
Markets at last close

Anthropic · Research

SearchGEO tests how LLM search agents endorse manipulated web content

·1 min read

Researchers led by Yimeng Chen introduced SearchGEO, a controlled framework for testing endorsement corruption in LLM-based web-search agents. The work was submitted to arXiv on 15 Jun 2026 and focuses on whether manipulated web evidence can turn attacker-published pages into claims endorsed by an agent.

The evaluation covered 13 LLM backends on 308 cases each, with attack success rate varying sharply by model. Results ranged from 0.0% on Claude-Sonnet-4.6 to 31.4% on Gemini-3-Flash, showing that endorsement reliability can differ substantially across backends under adversarial search conditions.

SearchGEO combines a web-evidence manipulation pipeline, a five-mode attack taxonomy, multiple output-level metrics, and an auxiliary agent-skill probe that frames endorsement as an install command. The probe found a split between Claude systems that tended to “over-reject” and GPT systems that tended to “over-trust,” highlighting failure modes that may not appear in isolated model tests.

Originally reported by letsdatascience.comRead the source →
Related coverage
All Anthropic news →