跳到正文
原文
HuggingFace Daily Papers(社区热门论文)· HuggingFace Daily Papers(社区热门论文)·· 2026-08-24精选AI 评分72

单个污染页面即可影响LLM推荐:FORGE基准揭示检索增强推荐系统的脆弱性

AI 导读

检索增强型LLM在消费推荐中易受GEO内容污染影响,成为虚假产品的无意推广者。新基准FORGE在225个真实产品、15个类别和5个消费场景中测试12个商业及开源LLM,发现所有模型均易受攻击:单个污染页面即可造成最高27%的受骗率,替换全部前3个结果时升至73.8%。

推荐理由

实验量化了单页污染对 LLM 推荐器的影响,并发现推理会生成虚假社会证明,这提示搜索增强推荐系统的风险评估需覆盖推理环节。

正文

View PDF HTML (experimental)

Abstract:Search-augmented LLMs increasingly mediate everyday consumer recommendations by retrieving live web content. This creates a new risk: LLM recommenders may consume web content that Generative Engine Optimization (GEO) operators have polluted to mislead them. We ask: to what extent do they become unwitting promoters of fake products? We introduce FORGE (Fake Online Recommendations in Generative Environments), which locally rewrites real products in a frozen set of retrieved web pages into fake ones and measures how often the LLM recommends the fake product, across 225 real products in 15 categories and 5 consumer scenarios. Across 12 commercial and open-weights LLMs, all models are vulnerable: a single polluted page yields fooled rates of up to 27%, while the full top-3 replacement raises this to 73.8%. Vulnerability varies across categories, increasing when models lack stable prior knowledge of the products. Reasoning does not mitigate this vulnerability; instead, it often generates spurious social proof to justify false recommendations. None of the four defenses is adequate: the skepticism prompt can exacerbate vulnerability much like reasoning, the two consensus filters risk suppressing legitimate products, and credibility re-ranking helps every model but removes only a sixth of the fakes. We release the FORGE benchmark and the evaluation code at this https URL.
Comments: EMNLP 2026 Findings
Subjects: Computation and Language (cs.CL); Artificial Intelligence (cs.AI)
Cite as: arXiv:2606.13610 [cs.CL]
  (or arXiv:2606.13610v2 [cs.CL] for this version)
  https://doi.org/10.48550/arXiv.2606.13610

arXiv-issued DOI via DataCite

Submission history

From: Minghao Luo [view email]
[v1] Thu, 11 Jun 2026 17:24:14 UTC (4,018 KB)
[v2] Mon, 24 Aug 2026 13:12:16 UTC (4,026 KB)

来源:HuggingFace Daily Papers(社区热门论文) · arxiv.org