HuggingFace Daily Papers(社区热门论文)· HuggingFace Daily Papers(社区热门论文)·· 2026-08-24精选AI 评分72
单个污染页面即可影响LLM推荐:FORGE基准揭示检索增强推荐系统的脆弱性
AI 导读
检索增强型LLM在消费推荐中易受GEO内容污染影响,成为虚假产品的无意推广者。新基准FORGE在225个真实产品、15个类别和5个消费场景中测试12个商业及开源LLM,发现所有模型均易受攻击:单个污染页面即可造成最高27%的受骗率,替换全部前3个结果时升至73.8%。
推荐理由
实验量化了单页污染对 LLM 推荐器的影响,并发现推理会生成虚假社会证明,这提示搜索增强推荐系统的风险评估需覆盖推理环节。
正文
Abstract:Search-augmented LLMs increasingly mediate everyday consumer recommendations by retrieving live web content. This creates a new risk: LLM recommenders may consume web content that Generative Engine Optimization (GEO) operators have polluted to mislead them. We ask: to what extent do they become unwitting promoters of fake products? We introduce FORGE (Fake Online Recommendations in Generative Environments), which locally rewrites real products in a frozen set of retrieved web pages into fake ones and measures how often the LLM recommends the fake product, across 225 real products in 15 categories and 5 consumer scenarios. Across 12 commercial and open-weights LLMs, all models are vulnerable: a single polluted page yields fooled rates of up to 27%, while the full top-3 replacement raises this to 73.8%. Vulnerability varies across categories, increasing when models lack stable prior knowledge of the products. Reasoning does not mitigate this vulnerability; instead, it often generates spurious social proof to justify false recommendations. None of the four defenses is adequate: the skepticism prompt can exacerbate vulnerability much like reasoning, the two consensus filters risk suppressing legitimate products, and credibility re-ranking helps every model but removes only a sixth of the fakes. We release the FORGE benchmark and the evaluation code at this https URL.
| Comments: | EMNLP 2026 Findings |
| Subjects: | Computation and Language (cs.CL); Artificial Intelligence (cs.AI) |
| Cite as: | arXiv:2606.13610 [cs.CL] |
| (or arXiv:2606.13610v2 [cs.CL] for this version) | |
| https://doi.org/10.48550/arXiv.2606.13610 arXiv-issued DOI via DataCite |
Submission history
From: Minghao Luo [view email]
[v1]
Thu, 11 Jun 2026 17:24:14 UTC (4,018 KB)
[v2]
Mon, 24 Aug 2026 13:12:16 UTC (4,026 KB)
来源:HuggingFace Daily Papers(社区热门论文) · arxiv.org