Mechanism Design for Generative Engines: From Exploitation toward Win-Win Outcomes

arXiv cs.LG Papers

Summary

This paper models the strategic interaction between content providers and generative search engines as a repeated Stackelberg game, showing how GEO can escalate into citation wars, and proposes a verifiable-content reward mechanism (VCR) to align incentives and achieve win-win outcomes.

arXiv:2608.11390v1 Announce Type: new Abstract: Generative engines are reshaping the web ecosystem by making citations a key mechanism for allocating attention, attribution, and downstream value. This creates a strategic tension: content providers are incentivized to optimize for model citation, while platforms must preserve answer quality and trustworthy attribution. We show that this tension can escalate into citation wars. In repeated simulations, state-of-the-art generative engine optimization (GEO) attacks adapt to conventional defenses by producing citation-seeking rewrites that degrade document quality and introduce unsupported claims. To study this problem, we formulate the supplier--platform interaction as a repeated Stackelberg game with partial monitoring. A local best-response analysis identifies when citation competition approaches an inert stationary outcome. Motivated by this finding, we propose a platform--creator mechanism called VCR based on verifiable-content rewards. Rather than only penalizing suspicious rewrites, the platform also credits rewrites that surface checkable factual substance, aligning creator incentives with answer trustworthiness. Experiments on three benchmarks show that VCR consistently achieves the largest Net defense-utility score, outperforming the strongest baseline by an average of 12.1 percentage points, and produces a win--win outcome under our empirical equivalence criterion.
Original Article
View Cached Full Text

Cached at: 08/13/26, 03:35 PM

# Mechanism Design for Generative Engine: From Exploitation to Win-Win Equilibrium
Source: [https://arxiv.org/html/2608.11390](https://arxiv.org/html/2608.11390)
\\paperurl

=https://github\.com/cxcscmu/GameTheory\-GEO

Zitian GuoAffiliation:University of California, San DiegoChenyan XiongCorresponding author:\{chenxu2,cx\}@andrew\.cmu\.edu,ztguo@ucsd\.eduAffiliation:Carnegie Mellon University

###### Abstract

Generative engines are reshaping the web ecosystem by making citations a key mechanism for allocating attention, attribution, and downstream value\. This creates a strategic tension: content providers are incentivized to optimize for model citation, while platforms must preserve answer quality and trustworthy attribution\. We show that this tension can escalate into citation wars\. In repeated simulations, state\-of\-the\-art generative engine optimization \(GEO\) attacks adapt to conventional defenses by producing citation\-seeking rewrites that degrade document quality and introduce unsupported claims\. To study this problem, we formulate the supplier–platform interaction as a repeated Stackelberg game with partial monitoring\. A local best\-response analysis identifies when citation competition approaches an inert stationary outcome\. Motivated by this finding, we propose a platform–creator mechanism called VCR based on verifiable\-content rewards\. Rather than only penalizing suspicious rewrites, the platform also credits rewrites that surface checkable factual substance, aligning creator incentives with answer trustworthiness\. Experiments on three benchmarks show that VCR consistently achieves the largest Net defense–utility score, outperforming the strongest baseline by an average of12\.112\.1percentage points, and produces a win–win outcome under our empirical equivalence criterion\. GitHub:[https://github\.com/cxcscmu/GameTheory\-GEO](https://github.com/cxcscmu/GameTheory-GEO)\.

## 1Introduction

Generative search is reshaping information access into a citation\-mediated generative engine ecosystem, where LLM platforms allocate attention and attribution by deciding which sources to summarize and cite\[[26](https://arxiv.org/html/2608.11390#bib.bib26)\]\. In this ecosystem, citations become the new unit of visibility: they determine not only what users trust, but also which content suppliers receive traffic, reputation, and downstream value\. As a result, content providers are increasingly incentivized to optimize for model citation\[[1](https://arxiv.org/html/2608.11390#bib.bib1),[24](https://arxiv.org/html/2608.11390#bib.bib24)\], while platforms must preserve answer quality and trustworthy attribution\[[44](https://arxiv.org/html/2608.11390#bib.bib44),[12](https://arxiv.org/html/2608.11390#bib.bib12)\]\. This creates a strategic tension between supplier\-side visibility seeking and platform\-side quality control\. How to model and improve welfare in this generative engine ecosystem before it escalates into citation wars has become an urgent problem\.

Generative Engine Optimization \(GEO\)\[[1](https://arxiv.org/html/2608.11390#bib.bib1),[43](https://arxiv.org/html/2608.11390#bib.bib43),[47](https://arxiv.org/html/2608.11390#bib.bib47)\]operationalizes this tension: content providers rewrite documents to increase their probability of being cited by generative search engines\. Existing studies, however, mostly treat GEO as a one\-shot supplier\-side optimization problem\. This misses a key feature of the generative engine ecosystem: supplier optimization and platform defense interact repeatedly\. Once citations mediate visibility and downstream value, GEO may shift from improving content quality to strategically adapting to platform defense rules\. Over time, such adaptation can push suppliers toward citation\-seeking behaviors that distort attribution, reduce answer trustworthiness, and harm ecosystem welfare\. We next use simulation experiments to demonstrate this risk\.

![Refer to caption](https://arxiv.org/html/2608.11390v1/intro.png)Figure 1:Repeated GEO exploitation degrades both creator\-side document quality and user\-side answer utility, even under a standard defense\. Panel \(a\): five\-round trajectories onE\-commerce, where rewrite quality and answer utility both fall below the no\-exploitation reference\. Panel \(b\): a representative document before and after five rounds, with unsupported claims highlighted in red\.Fig\.[1](https://arxiv.org/html/2608.11390#S1.F1)illustrates this risk in a five\-round supplier–platform interaction onE\-commerce\. The supplier runsAutoGEO\[[43](https://arxiv.org/html/2608.11390#bib.bib43)\], while the platform applies a standard prompt\-warning defense against GEO manipulation\. Panel \(a\) shows that the system gradually drifts away from the no\-attack reference: rewrite quality becomes negative after the early rounds, defense recovery quickly decays, and platform/user utility remains below the clean baseline\. Panel \(b\) explains this degradation: repeated GEO adaptation accumulates unsupported claims and fabricated details, turning initially mild edits into citation\-seeking rewrites\. These results suggest that repeated GEO adaptation can drive the supplier–platform ecosystem toward an undesirable stationary outcome, where neither robust defense nor honest content improvement is sustained\.

To formalize this problem, we model the platform\-supplier interaction as a repeated Stackelberg game\[[40](https://arxiv.org/html/2608.11390#bib.bib40)\]with partial monitoring\. In each round, the supplier observes the platform’s current defense rule and commits to a GEO strategy for rewriting its target documents\. The platform then observes only document\-level before/after pairs and updates its answer\-time defense policy accordingly\. This game captures the key asymmetry of the generative engine ecosystem: suppliers can adapt directly to platform rules, while platforms must infer whether a rewrite reflects genuine quality improvement or strategic manipulation\.

Under this setting, we derive two structural results in a local quadratic model \(Sec\.[3\.3](https://arxiv.org/html/2608.11390#S3.SS3)\)\. First, holding source\-model moments fixed, the platform’s best\-response defense weakens as latent content quality becomes more correlated with manipulation intensity\. Second, when supplier utility is based on citation level rather than marginal citation gain, high\-quality targets can be preferred at a stationary response\. Together, these results expose a failure mode of the default game: the dynamics can approach an inert stationary outcome in which content\-improvement and manipulation gradients are exhausted and additional interaction produces little joint utility\.

Motivated by this analysis, we propose a platform\-supplier mechanism called VCR \(based on verifiable\-content rewards\) that aligns supplier incentives with platform trustworthiness\. The key idea is to make defense incentive\-compatible rather than purely punitive\. In addition to penalizing suspicious manipulation, the platform credits rewrites that make source\-supported factual content more salient, offsetting this credit against the suspicion score before applying the defense\. Thus, cosmetic or self\-promotional GEO edits are still demoted, while substantive rewrites that surface checkable information are rewarded\. In the local model, this gives a rational supplier a welfare\-aligned optimization direction and improves the joint defense–utility outcome\.

We evaluate the proposed mechanism on three benchmarks\[[43](https://arxiv.org/html/2608.11390#bib.bib43),[1](https://arxiv.org/html/2608.11390#bib.bib1)\]: commercial search \(E\-commerce\), open\-domain factual queries \(GEO\-Bench\), and research\-oriented queries \(Researchy\-GEO\)\. Across datasets and answer engines, VCR produces a win–win outcome under our empirical equivalence criterion: it protects platform/user utility while preserving creator exposure\. It achieves the largest Net defense–utility score in every setting, outperforming the strongest baseline by an average of12\.112\.1percentage points, and also has the strongest direct document\- and answer\-quality point estimates\. The code is shared at[https://github\.com/cxcscmu/GameTheory\-GEO](https://github.com/cxcscmu/GameTheory-GEO)\.

Our key contributions are three\-fold:

- •We formulate the GEO–platform interaction as a repeated Stackelberg game with partial monitoring, and provide a local best\-response analysis of stationary citation competition\.
- •We propose a supplier\-platform mechanism based on verifiable\-content rewards, which transforms platform defense from a purely punitive filter into a two\-sided incentive mechanism that rewards substantive content while penalizing manipulation\.
- •We validate the proposed mechanism on three benchmarks, three answer engines, and five GEO attackers, where it consistently achieves the largest Net score\.

## 2Related Work

#### Supplier\-side visibility attacks\.

Content providers have long tried to manipulate search visibility, from classical link spam, content spam, and robust ranking under document manipulation\[[19](https://arxiv.org/html/2608.11390#bib.bib19),[18](https://arxiv.org/html/2608.11390#bib.bib18),[34](https://arxiv.org/html/2608.11390#bib.bib34),[4](https://arxiv.org/html/2608.11390#bib.bib4),[7](https://arxiv.org/html/2608.11390#bib.bib7),[16](https://arxiv.org/html/2608.11390#bib.bib16)\]to newer LLM\-era attacks such as prompt injection, RAG poisoning, and product\-visibility manipulation\[[37](https://arxiv.org/html/2608.11390#bib.bib37),[17](https://arxiv.org/html/2608.11390#bib.bib17),[27](https://arxiv.org/html/2608.11390#bib.bib27),[48](https://arxiv.org/html/2608.11390#bib.bib48),[50](https://arxiv.org/html/2608.11390#bib.bib50),[45](https://arxiv.org/html/2608.11390#bib.bib45),[11](https://arxiv.org/html/2608.11390#bib.bib11),[35](https://arxiv.org/html/2608.11390#bib.bib35),[24](https://arxiv.org/html/2608.11390#bib.bib24)\]\. Generative engine optimization \(GEO\) is a recent and increasingly important form of this supplier\-side problem, where creators rewrite content to increase citation or attribution by generative search engines\. PriorGEOwork defines visibility metrics and studies manual or automatic rewriting strategies\[[1](https://arxiv.org/html/2608.11390#bib.bib1),[43](https://arxiv.org/html/2608.11390#bib.bib43)\]\. Subsequent work extendsGEOto role\-augmented intent modeling\[[10](https://arxiv.org/html/2608.11390#bib.bib10)\], latent\-query instruction fusion\[[49](https://arxiv.org/html/2608.11390#bib.bib49)\], e\-commerce benchmarks\[[3](https://arxiv.org/html/2608.11390#bib.bib3)\], and fuller search\-pipeline evaluation\[[22](https://arxiv.org/html/2608.11390#bib.bib22)\]\. Other extensions study multimodal content such as captions\[[9](https://arxiv.org/html/2608.11390#bib.bib9)\], structural features\[[46](https://arxiv.org/html/2608.11390#bib.bib46)\], agentic optimization settings\[[47](https://arxiv.org/html/2608.11390#bib.bib47)\], feature\-level objectives\[[28](https://arxiv.org/html/2608.11390#bib.bib28)\], reusable optimization strategies\[[42](https://arxiv.org/html/2608.11390#bib.bib42),[38](https://arxiv.org/html/2608.11390#bib.bib38)\], and source\-influence benchmarks\[[8](https://arxiv.org/html/2608.11390#bib.bib8)\]\. These works motivate our supplier\-side threat model; our focus is howGEO\-style optimization behaves when repeated against an adapting platform\.

#### Platform\-side defenses\.

Platforms can defend at different points in the pipeline\. Traditional search systems use spam detection, link analysis, demotion, and robust ranking\[[18](https://arxiv.org/html/2608.11390#bib.bib18),[7](https://arxiv.org/html/2608.11390#bib.bib7),[16](https://arxiv.org/html/2608.11390#bib.bib16)\]\. LLM systems also use prompt\-level and retrieval\-level defenses\. Citation\-grounded generation and RAG evaluation study attribution, factual support, and faithfulness\[[25](https://arxiv.org/html/2608.11390#bib.bib25),[31](https://arxiv.org/html/2608.11390#bib.bib31),[15](https://arxiv.org/html/2608.11390#bib.bib15),[6](https://arxiv.org/html/2608.11390#bib.bib6),[30](https://arxiv.org/html/2608.11390#bib.bib30),[13](https://arxiv.org/html/2608.11390#bib.bib13),[2](https://arxiv.org/html/2608.11390#bib.bib2)\]\. The instruction hierarchy asks models to prioritize trusted instructions over untrusted retrieved text\[[41](https://arxiv.org/html/2608.11390#bib.bib41)\]\. Robust RAG work studies defenses against adversarial or corrupted passages, including skeptical prompting, robust aggregation, and filtering\[[39](https://arxiv.org/html/2608.11390#bib.bib39),[44](https://arxiv.org/html/2608.11390#bib.bib44),[12](https://arxiv.org/html/2608.11390#bib.bib12)\]\. These defenses target malicious instructions or poisoned evidence\. While our method rewards source\-supported factual substance rather than only penalizing suspicious form\.

#### Strategic games and mechanisms\.

Our framework belongs to strategic machine learning\. Strategic classification studies agents that change features after seeing a classifier\[[20](https://arxiv.org/html/2608.11390#bib.bib20)\]\. Later work separates manipulative gaming from costly effort that can improve true outcomes\[[23](https://arxiv.org/html/2608.11390#bib.bib23)\]\. Performative prediction studies models whose deployment changes the future data distribution\[[36](https://arxiv.org/html/2608.11390#bib.bib36)\]\. Recommendation work has also modeled strategic content providers, platform mechanisms, and supply\-side equilibria\[[5](https://arxiv.org/html/2608.11390#bib.bib5),[21](https://arxiv.org/html/2608.11390#bib.bib21)\]\. We use a repeated Stackelberg game because suppliers observe platform defenses before choosing rewrites, while the platform only observes before/after document pairs\[[40](https://arxiv.org/html/2608.11390#bib.bib40),[29](https://arxiv.org/html/2608.11390#bib.bib29)\]\. The mechanism in Sec\.[4](https://arxiv.org/html/2608.11390#S4)follows this logic: the platform does not only punish suspicious rewrites; it also rewards source\-supported factual content so that supplier effort is more useful to users\. Unlike classical algorithmic mechanism design, which primarily intervenes through payments or allocation rules\[[32](https://arxiv.org/html/2608.11390#bib.bib32)\], VCR uses an LLM\-verifiable content channel native to generative\-engine citation\.

## 3Framework: A Repeated Game of Supplier and Platform

We model the problem as a repeated Stackelberg game with supplier leadership and partial monitoring\.

### 3\.1Notation

For queryq∈𝒬q\\in\\mathcal\{Q\}, letD⁡\(q\)=\{d1,…,dK\}D\(q\)=\\\{d\_\{1\},\\ldots,d\_\{K\}\\\}be the retrieved candidates andT⁡\(q\)⊆D⁡\(q\)T\(q\)\\subseteq D\(q\)the supplier’s target documents\. Each documentdid\_\{i\}has latent qualityqi∈ℝq\_\{i\}\\in\\mathbb\{R\}, capturing user\-useful content, and manipulation intensitymi∈ℝm\_\{i\}\\in\\mathbb\{R\}, capturing citation\-seeking surface patterns\. Letρ=corr⁡\(qi,mi\)\\rho=\\mathrm\{corr\}\(q\_\{i\},m\_\{i\}\)\. The engine assigns citation probability by

vi​\(α\)=βq​qi−α​mi\+bi,ci​\(α\)=softmax​\{vj​\(α\)\}i,v\_\{i\}\(\\alpha\)=\\beta\_\{q\}q\_\{i\}\-\\alpha m\_\{i\}\+b\_\{i\},\\qquad c\_\{i\}\(\\alpha\)=\\mathrm\{softmax\}\\\{v\_\{j\}\(\\alpha\)\\\}\_\{i\},\(1\)whereβq\>0\\beta\_\{q\}\>0is the quality weight,α≥0\\alpha\\geq 0the platform defense strength, andbib\_\{i\}independent residual noise\. Supplier exposure is scoregT=∑i∈T⁡\(q\)wi​\(q\)​ci,g\_\{T\}=\\sum\_\{i\\in T\(q\)\}w\_\{i\}\(q\)c\_\{i\},with position\-aware citation weightwi​\(q\)w\_\{i\}\(q\)\.

### 3\.2Repeated Game

At roundtt, the supplier observes the previous defenseπP,t−1\\pi\_\{P,t\-1\}and rewrites its targets, yieldingDta=πA,t​\(Dt\)D\_\{t\}^\{a\}=\\pi\_\{A,t\}\(D\_\{t\}\)\. The platform only observes before/after pairs𝒪t=\{\(di,dia\):i∈Tt\(q\),q∈𝒬\},\\mathcal\{O\}\_\{t\}=\\\{\(d\_\{i\},d\_\{i\}^\{a\}\):i\\in T\_\{t\}\(q\),q\\in\\mathcal\{Q\}\\\},estimates the rewrite strategy, and updates its answer\-time defenseπP,t\\pi\_\{P,t\}\. The supplier maximizes citation exposure net of rewrite cost:

uA​\(πA,πP\)=gT​\(πA,πP\)−κA​\(πA\),u\_\{A\}\(\\pi\_\{A\},\\pi\_\{P\}\)=g\_\{T\}\(\\pi\_\{A\},\\pi\_\{P\}\)\-\\kappa\_\{A\}\(\\pi\_\{A\}\),\(2\)whereκA\\kappa\_\{A\}captures editing cost, factual drift, and detectability\. The platform suppresses manipulated citations while avoiding false positives:

uP​\(πA,πP\)=−gT​\(πA,πP\)−μ​f​\(πP\)−γ2​r​\(πP\)\.u\_\{P\}\(\\pi\_\{A\},\\pi\_\{P\}\)=\-g\_\{T\}\(\\pi\_\{A\},\\pi\_\{P\}\)\-\\mu f\(\\pi\_\{P\}\)\-\\frac\{\\gamma\}\{2\}r\(\\pi\_\{P\}\)\.\(3\)Under Eq\. \([1](https://arxiv.org/html/2608.11390#S3.E1)\), the leading false\-positive cost is proportional toα​βq​cov​\(q,m\)\\alpha\\beta\_\{q\}\\mathrm\{cov\}\(q,m\): penalizing manipulation also suppresses quality whenqqandmmare correlated\. Since the platform never observes the true rewrite rulertr\_\{t\}, it estimatesr^t\\hat\{r\}\_\{t\}from𝒪t\\mathcal\{O\}\_\{t\}\.

###### Definition 1\(Local stationary response\)\.

Fix a target set and a neighborhood in feature space\. A pair\(δ∗,α∗\)\(\\delta^\{\\ast\},\\alpha^\{\\ast\}\)is a local stationary response ifδ∗\\delta^\{\\ast\}maximizes the supplier’s local quadratic utility givenα∗\\alpha^\{\\ast\}, andα∗\\alpha^\{\\ast\}minimizes the platform’s local quadratic loss given the induced document distribution\. This is the fixed point of the local best\-response map; it is not asserted to be a global equilibrium of the unrestricted text\-generation game\.

### 3\.3Theoretical Analysis

We characterize the platform best response and the induced fixed point\. Proofs are in Appendix[F](https://arxiv.org/html/2608.11390#A6)\.

###### Lemma 1\(Local response of target GEO\)\.

Under Eq\. \([1](https://arxiv.org/html/2608.11390#S3.E1)\),gT​\(α\)=gT​\(0\)−α​B\+12​α2​Q\+O⁡\(α3\),g\_\{T\}\(\\alpha\)=g\_\{T\}\(0\)\-\\alpha B\+\\frac\{1\}\{2\}\\alpha^\{2\}Q\+O\(\\alpha^\{3\}\),whereBBis the first\-order sensitivity to the manipulation penalty andQQis the second\-order term\.

###### Theorem 1\(Local platform best response\)\.

Under Eq\. \([1](https://arxiv.org/html/2608.11390#S3.E1)\) and Eq\. \([3](https://arxiv.org/html/2608.11390#S3.E3)\), suppose the Taylor remainder is negligible in a neighborhood of zero andQ\+γ\>0Q\+\\gamma\>0\. The unique minimizer of the platform’s quadratic local loss is

α∗=max⁡\{0,B−μ​βq​ρ​σq​σmQ\+γ\},\\alpha^\{\\ast\}=\\max\\left\\\{0,\\,\\frac\{B\-\\mu\\beta\_\{q\}\\rho\\sigma\_\{q\}\\sigma\_\{m\}\}\{Q\+\\gamma\}\\right\\\},\(4\)whereσq\\sigma\_\{q\}andσm\\sigma\_\{m\}are the standard deviations ofqqandmm\. Holding all other local moments and coefficients fixed,α∗\\alpha^\{\\ast\}is weakly decreasing inρ\\rho\.

###### Corollary 1\(Phase transition\)\.

Ifμ​βq​σq​σm\>0\\mu\\beta\_\{q\}\\sigma\_\{q\}\\sigma\_\{m\}\>0andρ∗=B/\(μ​βq​σq​σm\)\\rho^\{\\ast\}=B/\(\\mu\\beta\_\{q\}\\sigma\_\{q\}\\sigma\_\{m\}\), thenα∗\>0\\alpha^\{\\ast\}\>0iffρ<ρ∗\\rho<\\rho^\{\\ast\}\. Above this threshold, the local best response stops penalizing manipulation\.

Thus, when manipulation cues are entangled with quality, defense also suppresses useful evidence, so the platform weakens its penalty\.

###### Proposition 1\(Target\-selection structure\)\.

Suppose the supplier can choose target setTT, has level utility in Eq\. \([2](https://arxiv.org/html/2608.11390#S3.E2)\), and faces comparable rewrite costs across equal\-size target sets\. Its defended target choice satisfies

T∗∈arg​maxT⊆D⁡𝔼​\[gT​\(πA,πP∞\)∣T\]\.T^\{\\ast\}\\in\\argmax\_\{T\\subseteq D\}\\mathbb\{E\}\\\!\\left\[g\_\{T\}\(\\pi\_\{A\},\\pi\_\{P\}^\{\\infty\}\)\\mid T\\right\]\.\(5\)For two equal\-size target setsTH,TLT\_\{H\},T\_\{L\}, if rewrite costs are equal and𝔼⁡\[gTH​\(πA,πP∞\)\]\>𝔼⁡\[gTL​\(πA,πP∞\)\]\\mathbb\{E\}\[g\_\{T\_\{H\}\}\(\\pi\_\{A\},\\pi\_\{P\}^\{\\infty\}\)\]\>\\mathbb\{E\}\[g\_\{T\_\{L\}\}\(\\pi\_\{A\},\\pi\_\{P\}^\{\\infty\}\)\], thenTLT\_\{L\}is not optimal\. In particular, high\-quality targets are preferred whenever their higher baseline citation level and quality–manipulation correlation produce this strict ordering\.

###### Proposition 2\(Local defense\-effectiveness decomposition\)\.

Letst=𝔼⁡\[mi∣i∈Tt\]s\_\{t\}=\\mathbb\{E\}\[m\_\{i\}\\mid i\\in T\_\{t\}\]be target manipulation magnitude andet=12​‖rt−r^t‖22∈\[0,1\]e\_\{t\}=\\frac\{1\}\{2\}\\\|r\_\{t\}\-\\hat\{r\}\_\{t\}\\\|\_\{2\}^\{2\}\\in\[0,1\]the rule\-estimation error\. Assumertr\_\{t\}andr^t\\hat\{r\}\_\{t\}are unit vectors in a common rule basis and unit\-direction sensitivity is linear insts\_\{t\}\. To leading order,

gT​\(Dta,πP,t−1\)−gT​\(Dta,πP,t\)=c⁡\(1−et\)​st​αt,g\_\{T\}\(D\_\{t\}^\{a\};\\pi\_\{P,t\-1\}\)\-g\_\{T\}\(D\_\{t\}^\{a\};\\pi\_\{P,t\}\)=c\(1\-e\_\{t\}\)s\_\{t\}\\alpha\_\{t\},\(6\)wherec≥0c\\geq 0depends only on source\-model moments\.

Eq\. \([6](https://arxiv.org/html/2608.11390#S3.E6)\) shows that defense effectiveness is the product of rule\-estimation accuracy, edit magnitude, and defense strength, all of which may decay as the supplier adapts\.

#### Inert stationary outcome\.

A supplier moveδ=\(δq,δm\)\\delta=\(\\delta\_\{q\},\\delta\_\{m\}\)changes the shared platform/user utility by

Δ​U​\(δ\)=η​δq\+ξ​δm,\\Delta U\(\\delta\)=\\eta\\delta\_\{q\}\+\\xi\\delta\_\{m\},\(7\)whereη\>0\\eta\>0is utility gain from real content improvement andξ=ξ\+−ξ−\\xi=\\xi\_\{\+\}\-\\xi\_\{\-\}is the net effect of manipulation\. With isotropic rewrite costκA​\(δ\)=12​‖δ‖2\\kappa\_\{A\}\(\\delta\)=\\frac\{1\}\{2\}\\\|\\delta\\\|^\{2\}, the supplier best response satisfiesδ∝\(βq,−α∗\)\\delta\\propto\(\\beta\_\{q\},\-\\alpha^\{\\ast\}\), henceΔ​U∗∝η​βq−ξ​α∗\\Delta U^\{\\ast\}\\propto\\eta\\beta\_\{q\}\-\\xi\\alpha^\{\\ast\}\.

###### Corollary 2\(Locally inert stationary outcome\)\.

At a local stationary response in the high\-ρ\\rhoregime, suppose platform defense is weak, the supplier’s content\-improvement gradient is exhausted, and residual formatting benefit is offset by hallucination harm\. Then the first\-order utility change satisfiesΔ​U∗≈0\\Delta U^\{\\ast\}\\approx 0\.

#### Implication\.

The default game is one\-sided: it penalizes manipulation but rewards no feature directly aligned with platform/user utility\. High quality–manipulation correlation weakens defense, and partial monitoring further erodes it\. The resulting local stationary outcome can be inert: useful content is not induced, suspicious content is weakly penalized, and further platform updates have little effect\.

## 4Welfare\-Incentivizing Mechanism

![Refer to caption](https://arxiv.org/html/2608.11390v1/method_V3.png)Figure 2:Overview of VCR\. The platform extracts GEO rules from before/after pairs, rewards verifiable content, and applies a soft re\-ranking for answer\-time defense\.Based on Sec\.[3](https://arxiv.org/html/2608.11390#S3), we proposeVCR, a platform\-side mechanism that turns defense from a one\-sided penalty into a two\-sided incentive\. In one sentence: the platform*credits*rewrites that add pair\-verifiable factual substance \(Sec\.[4\.1](https://arxiv.org/html/2608.11390#S4.SS1)\),*calibrates*this credit with a suspicion penalty distilled from the supplier’s observed GEO behavior \(Sec\.[4\.2](https://arxiv.org/html/2608.11390#S4.SS2)\), and uses the combined score to softly re\-rank sources at answer time\. Algorithm[1](https://arxiv.org/html/2608.11390#alg1)summarizes the policy\.

### 4\.1Verifiable\-Content Reward

Corollary[2](https://arxiv.org/html/2608.11390#Thmcorollary2)explains why penalty\-only defenses stall: they can suppress manipulation but give the supplier no profitable direction to improve, so the repeated game settles at a welfare\-neutral fixed point\. The core of our mechanism is therefore a reward channel that makes verifiable substance the supplier’s most profitable strategy\.

###### Definition 2\(Verifiable supported content\)\.

For pair\(di,dia\)\(d\_\{i\},d\_\{i\}^\{a\}\), letnin\_\{i\}be the number of factual claims, numerical details, or named citations present in the rewrite and supported by the original document and surfaced more saliently in the rewrite\. We estimatenin\_\{i\}using a pair\-level LLM oracle\.

In the running example of Fig\.[2](https://arxiv.org/html/2608.11390#S4.F2), the rewrite surfaces three facts that are checkable against the original, namely the 8\-hour battery life, sweat resistance, and per\-bud weight, soni=3n\_\{i\}=3\. Additions with no support in the original, such as “expert\-recommended” and “industry\-leading,” earn no credit and instead feed the manipulation signalmim\_\{i\}of Eq\. \([1](https://arxiv.org/html/2608.11390#S3.E1)\), which the platform estimates by rule matching in Sec\.[4\.2](https://arxiv.org/html/2608.11390#S4.SS2)\. Each rewrite earns the credit

ri=λ⋅min⁡\(cmax,cn​ni\),r\_\{i\}=\\lambda\\cdot\\min\(c\_\{\\max\},c\_\{n\}n\_\{i\}\),\(8\)whereλ\\lambdais reward strength,cnc\_\{n\}the per\-claim credit, andcmaxc\_\{\\max\}the credit cap that bounds how much reward any single rewrite can farm\. The reward alone, however, cannot tell substantive rewrites from manipulative ones; the platform still needs a penalty side that tracks the supplier’s current GEO strategy, which we extract next\.

### 4\.2GEO Rule Extraction

To build this penalty side, the platform turns the supplier’s own rewrite history into evidence of its strategy\. At roundtt, the platform observes before/after pairs𝒪t=\{\(di,dia\)\}\\mathcal\{O\}\_\{t\}=\\\{\(d\_\{i\},d\_\{i\}^\{a\}\)\\\}and infers a rule setSP\(t\)S\_\{P\}^\{\(t\)\}describing the supplier’s current GEO strategy\. We follow the Explainer–Extractor–Merger–Filter pipeline ofAutoGEO\[[43](https://arxiv.org/html/2608.11390#bib.bib43)\], but reverse its use: instead of comparing preferred and less\-used documents to infer engine preferences, the platform compares original and rewritten documents to infer suspicious rewrite patterns\.

For each pair\(di,dia\)\(d\_\{i\},d\_\{i\}^\{a\}\), the platform computes edit magnitudeΔi\\Delta\_\{i\}and skips trivial rewrites withΔi<θ\\Delta\_\{i\}<\\theta\. The output isSP\(t\)S\_\{P\}^\{\(t\)\}and each retrieved document receives a baseline suspicion score

sjbase=Match​\(dj,SP\(t\)\)⋅Δj,s\_\{j\}^\{\\mathrm\{base\}\}=\\textsc\{Match\}\(d\_\{j\},S\_\{P\}^\{\(t\)\}\)\\cdot\\Delta\_\{j\},\(9\)whereMatch​\(⋅\)∈\[0,1\]\\textsc\{Match\}\(\\cdot\)\\in\[0,1\]measures rule match strength andΔj\\Delta\_\{j\}is recent edit magnitude\. The suspicion penalty then calibrates the reward of Eq\. \([8](https://arxiv.org/html/2608.11390#S4.E8)\) into a single score,

sinew=sibase−ri,s\_\{i\}^\{\\mathrm\{new\}\}=s\_\{i\}^\{\\mathrm\{base\}\}\-r\_\{i\},\(10\)so that cosmetic or self\-promotional rewrites remain suspicious, while checkable factual additions receive credit\.

### 4\.3Soft Re\-rank

The platform converts the combined scoresinews\_\{i\}^\{\\mathrm\{new\}\}into a soft defense signal\. It reorders documents, placing less suspicious and more verification\-friendly sources earlier in the context\. Finally, the platform adds a system\-level warning fromSP\(t\)S\_\{P\}^\{\(t\)\}that instructs the engine to treat these labels as auxiliary evidence, prioritize verifiable claims, and avoid over\-crediting sources whose citation value mainly comes from manipulative rewriting\. No document is removed: high\-suspicion documents may still be cited when they provide uniquely necessary evidence\.

Algorithm 1Mechanism\-augmented platform policyπPλ\\pi\_\{P\}^\{\\lambda\}1:Before/after pairs

𝒪t=\{\(di,dia\)\}\\mathcal\{O\}\_\{t\}=\\\{\(d\_\{i\},d\_\{i\}^\{a\}\)\\\}, threshold

θ\\theta, reward parameters

\(λ,cn,cmax\)\(\\lambda,c\_\{n\},c\_\{\\max\}\)\.

2:

ℛ←∅\\mathcal\{R\}\\leftarrow\\emptyset
3:foreach

\(di,dia\)∈𝒪t\(d\_\{i\},d\_\{i\}^\{a\}\)\\in\\mathcal\{O\}\_\{t\}do

4:Compute edit magnitude

Δi\\Delta\_\{i\}; continue if

Δi<θ\\Delta\_\{i\}<\\theta\.

5:

ei←Explainer​\(di,dia\)e\_\{i\}\\leftarrow\\textsc\{Explainer\}\(d\_\{i\},d\_\{i\}^\{a\}\);

ri←Extractor​\(ei\)r\_\{i\}\\leftarrow\\textsc\{Extractor\}\(e\_\{i\}\)\.

6:

ℛ←ℛ∪ri\\mathcal\{R\}\\leftarrow\\mathcal\{R\}\\cup r\_\{i\}\.

7:

SP←Filter​\(Merger​\(ℛ\)\)S\_\{P\}\\leftarrow\\textsc\{Filter\}\(\\textsc\{Merger\}\(\\mathcal\{R\}\)\)\.

8:foreach retrieved document

djd\_\{j\}do

9:Set

Δj\\Delta\_\{j\}to recent edit magnitude, or

00if unobserved\.

10:

sjbase←Match​\(dj,SP\)⋅Δjs\_\{j\}^\{\\mathrm\{base\}\}\\leftarrow\\textsc\{Match\}\(d\_\{j\},S\_\{P\}\)\\cdot\\Delta\_\{j\}\.

11:If pair

\(dj0,dj\)\(d\_\{j\}^\{0\},d\_\{j\}\)exists,

nj←Oracle​\(dj0,dj\)n\_\{j\}\\leftarrow\\textsc\{Oracle\}\(d\_\{j\}^\{0\},d\_\{j\}\); else

nj←0n\_\{j\}\\leftarrow 0\.

12:

sjnew←sjbase−λ​min⁡\(cmax,cn​nj\)s\_\{j\}^\{\\mathrm\{new\}\}\\leftarrow s\_\{j\}^\{\\mathrm\{base\}\}\-\\lambda\\min\(c\_\{\\max\},c\_\{n\}n\_\{j\}\)\.

13:

W←Warning​\(SP\)W\\leftarrow\\textsc\{Warning\}\(S\_\{P\}\); soft\-rerank by ascending

sjnews\_\{j\}^\{\\mathrm\{new\}\}\.

14:return

\(W,\{sjnew\},order\)\(W,\\\{s\_\{j\}^\{\\mathrm\{new\}\}\\\},\\mathrm\{order\}\)\.

### 4\.4Analysis

#### Theoretical analysis\.

We analyze how VCR changes utility at a local stationary response\. In Eq\. \([1](https://arxiv.org/html/2608.11390#S3.E1)\), the term−α​mi\-\\alpha m\_\{i\}is the linearized effect of the platform’s suspicion channel on the engine’s pre\-softmax citation logit\. Likewise, the VCR credit in Eq\. \([8](https://arxiv.org/html/2608.11390#S4.E8)\) induces a positive\+λ​ni\+\\lambda n\_\{i\}shift, absorbingcnc\_\{n\}intoλ\\lambdaand ignoring the cap locally\. The augmented logit is

vi​\(α,λ\)=βq​qi−α​mi\+λ​ni\+bi\.v\_\{i\}\(\\alpha,\\lambda\)=\\beta\_\{q\}q\_\{i\}\-\\alpha m\_\{i\}\+\\lambda n\_\{i\}\+b\_\{i\}\.\(11\)The key assumption is that source\-supported content is locally separable from manipulation and positively aligned with the shared platform/user utility\.

###### Assumption 1\.

The signalnin\_\{i\}is measurable from the before/after pair, satisfies𝔼⁡\[\(n−n¯\)​\(m−m¯\)\]=0\\mathbb\{E\}\[\(n\-\\bar\{n\}\)\(m\-\\bar\{m\}\)\]=0, and has positive marginal platform/user utilityηn=∂∂n​𝔼​\[U∣n\]\>0\\eta\_\{n\}=\\frac\{\\partial\}\{\\partial n\}\\mathbb\{E\}\[U\\mid n\]\>0\. The supplier’s local rewrite cost is12​δ⊤​H​δ\\frac\{1\}\{2\}\\delta^\{\\top\}H\\delta, whereH≻0H\\succ 0and thenncoordinate is block\-separable from\(q,m\)\(q,m\)\. The platform uses the local quadratic loss of Thm\.[1](https://arxiv.org/html/2608.11390#Thmtheorem1), whose reward–defense mixed partial vanishes atλ=0\\lambda=0:∂2LP/\(∂α​∂λ\)=0\\partial^\{2\}L\_\{P\}/\(\\partial\\alpha\\partial\\lambda\)=0\.

Note that our empirical experiments on three datasets show that the correlationρ^m,n∈\[−0\.05,0\.1\]\\widehat\{\\rho\}\_\{m,n\}\\in\[\-0\.05,0\.1\], which is a reasonable assumption\.

###### Theorem 2\(Local two\-sided utility improvement\)\.

Under Asm\.[1](https://arxiv.org/html/2608.11390#Thmassumption1), let\(δ∗​\(λ\),α∗​\(λ\)\)\(\\delta^\{\\ast\}\(\\lambda\),\\alpha^\{\\ast\}\(\\lambda\)\)be the local stationary response of Def\.[1](https://arxiv.org/html/2608.11390#Thmdefinition1)\. Thenα∗​\(λ\)=α∗​\(0\)\+O⁡\(λ2\)\\alpha^\{\\ast\}\(\\lambda\)=\\alpha^\{\\ast\}\(0\)\+O\(\\lambda^\{2\}\)and the shared platform/user utility satisfies

Δ​U∗​\(λ\)=Δ​U∗​\(0\)\+ηn​λ​Θ,\\Delta U^\{\\ast\}\(\\lambda\)=\\Delta U^\{\\ast\}\(0\)\+\\eta\_\{n\}\\lambda\\Theta,\(12\)whereΘ=\(H−1\)n​n\>0\\Theta=\(H^\{\-1\}\)\_\{nn\}\>0\. Hence, for sufficiently smallλ\>0\\lambda\>0,Δ​U∗​\(λ\)\>Δ​U∗​\(0\)\\Delta U^\{\\ast\}\(\\lambda\)\>\\Delta U^\{\\ast\}\(0\)\. If the default equilibrium is locally inert, VCR strictly improves the platform/user side to first order\. The creator’s optimized local objective changes only at second order\. Thus, to first order, VCR improves the platform/user side while preserving creator utility—the theoretical counterpart of the empirical equivalence test\.

Full proof is in Appendix[F](https://arxiv.org/html/2608.11390#A6)\. Intuitively, VCR adds a third strategic direction: verifiable substance\. Without the reward, suppliers gain visibility through latent quality or manipulation signals; with VCR, they can gain citation value by surfacing checkable factual content\. The platform still demotes manipulation, but also rewards substantive rewrites, making defense an incentive mechanism rather than only a filter\.

#### Discussion on practical deployment\.

VCR targets versioned content, which covers a substantial practical scope: a previous study found that about 40% of pages change within a week, whereas about 8% are newly created\[[14](https://arxiv.org/html/2608.11390#bib.bib14),[33](https://arxiv.org/html/2608.11390#bib.bib33)\]\. For a new page without a prior version,n=0n=0, so VCR degrades gracefully to itsλ=0\\lambda=0suspicion\-only special case\. On the reward side, the conservative pair\-verifiable scope limits adjudication ambiguity and gaming; we analyze this choice, together with the verification anchor and rule disclosure, in Sec\.[5\.4](https://arxiv.org/html/2608.11390#S5.SS4)\.

## 5Experiments

We evaluate whether the proposed verifiable\-content reward \(VCR\) improves the joint defense–utility outcome in repeated simulations\. Additional analyses, including direct quality measures, judge robustness, adaptive suppliers, and case studies, are deferred to App\.[E](https://arxiv.org/html/2608.11390#A5)\.

### 5\.1Experimental Setup

#### Datasets\.

We use three retrieval\-augmented benchmarks with different task regimes:E\-commerce\[[43](https://arxiv.org/html/2608.11390#bib.bib43)\],GEO\-Bench\[[1](https://arxiv.org/html/2608.11390#bib.bib1)\], andResearchy\-GEO\[[43](https://arxiv.org/html/2608.11390#bib.bib43)\]\. Following the evaluation construction of AutoGEO\[[43](https://arxiv.org/html/2608.11390#bib.bib43)\], each query is paired withK=5K=5candidate documents; the held\-out test splits contain up to1,0001\{,\}000queries\.

Table 1:Repeated\-game results across three benchmarks and three answer engines\. Def\. is the shared platform/user\-side utility, Welf\. is creator exposure utility, and Net is their sum; all values are percentage points\. Creator utility within±5\\pm 5points of zero is treated as empirically equivalent to the no\-exploitation reference\.DefenseE\-commerceGEO\-BenchResearchy\-GEODef\.Welf\.NetDef\.Welf\.NetDef\.Welf\.NetGemini\-flash\-2\.5\-litePrompt2\.72\.7−2\.0\-2\.00\.70\.73\.43\.4−3\.5\-3\.5−0\.1\-0\.10\.80\.8−0\.7\-0\.70\.10\.1Hard reject50\.250\.2−50\.8\-50\.8−0\.6\-0\.633\.833\.8−33\.1\-33\.10\.70\.763\.863\.8−63\.3\-63\.30\.50\.5Keyword scrub−1\.0\-1\.00\.00\.0−1\.0\-1\.0−0\.1\-0\.10\.30\.30\.10\.10\.20\.20\.20\.20\.40\.4VCR \(ours\)14\.4\\mathbf\{14\.4\}2\.2\\mathbf\{2\.2\}16\.6\\mathbf\{16\.6\}11\.4\\mathbf\{11\.4\}−3\.3\\mathbf\{\-3\.3\}8\.1\\mathbf\{8\.1\}8\.0\\mathbf\{8\.0\}−1\.7\\mathbf\{\-1\.7\}6\.3\\mathbf\{6\.3\}GPT\-4o\-miniPrompt−0\.7\-0\.7−3\.2\-3\.2−3\.9\-3\.9−0\.5\-0\.5−1\.9\-1\.9−2\.5\-2\.5−0\.4\-0\.40\.40\.40\.00\.0Hard reject22\.622\.6−21\.6\-21\.61\.01\.067\.367\.3−67\.5\-67\.5−0\.2\-0\.2−18\.9\-18\.920\.020\.01\.11\.1Keyword scrub−0\.8\-0\.81\.11\.10\.30\.31\.71\.7−2\.0\-2\.0−0\.2\-0\.2−2\.5\-2\.52\.62\.60\.10\.1VCR \(ours\)10\.9\\mathbf\{10\.9\}−1\.2\\mathbf\{\-1\.2\}9\.7\\mathbf\{9\.7\}9\.7\\mathbf\{9\.7\}−4\.7\\mathbf\{\-4\.7\}5\.0\\mathbf\{5\.0\}5\.0\\mathbf\{5\.0\}−1\.7\\mathbf\{\-1\.7\}3\.3\\mathbf\{3\.3\}Claude\-Haiku\-4\.5Prompt20\.020\.0−22\.9\-22\.9−2\.9\-2\.9−3\.4\-3\.43\.53\.50\.10\.1−0\.9\-0\.90\.20\.2−0\.7\-0\.7Hard reject5\.55\.5−5\.6\-5\.6−0\.1\-0\.116\.616\.6−19\.8\-19\.8−3\.1\-3\.185\.785\.7−85\.7\-85\.70\.00\.0Keyword scrub0\.40\.41\.11\.11\.51\.5−2\.7\-2\.76\.46\.43\.73\.72\.12\.1−1\.2\-1\.20\.90\.9VCR \(ours\)29\.1\\mathbf\{29\.1\}−3\.5\\mathbf\{\-3\.5\}25\.6\\mathbf\{25\.6\}29\.1\\mathbf\{29\.1\}−4\.8\\mathbf\{\-4\.8\}24\.3\\mathbf\{24\.3\}22\.0\\mathbf\{22\.0\}−1\.7\\mathbf\{\-1\.7\}20\.3\\mathbf\{20\.3\}
#### Metrics\.

We measure creator visibility using the target GEO scoregg\. Following AutoGEO\[[43](https://arxiv.org/html/2608.11390#bib.bib43)\]and the GEO visibility metric\[[1](https://arxiv.org/html/2608.11390#bib.bib1)\],ggaggregates how much, where, and how prominently the creator’s target documents are cited in the generated answer\. Full details are given in App\.[D](https://arxiv.org/html/2608.11390#A4)\.

For each defense, we computeggunder three states:g0g\_\{0\}is the no\-attack score on the original corpus,gag\_\{a\}is the score after GEO rewriting with no defense, andgdg\_\{d\}is the score after GEO rewriting with the platform defense applied\. We report two stakeholder sides\. Because the platform’s objective here is to protect the quality and trustworthiness of the answer shown to the user, platform and user interests are represented jointly by Def\.; Welf\. represents the creator side\. We compute

Def\.=\(ga−gd\)/ga,Welf\.=\(gd−g0\)/g0,Net=Def\+Welf\.\\mathrm\{Def\.\}=\(g\_\{a\}\-g\_\{d\}\)/g\_\{a\},\\qquad\\mathrm\{Welf\.\}=\(g\_\{d\}\-g\_\{0\}\)/g\_\{0\},\\qquad\\mathrm\{Net\}=\\mathrm\{Def\}\+\\mathrm\{Welf\}\.\(13\)Platform/user utility \(Def\.\) measures the fraction of manipulation\-induced visibility rolled back by the platform\. Creator utility \(Welf\.\) measures target\-source exposure relative to the no\-attack baseline; negative values indicate that the defense suppresses source exposure below its natural level\.Net\\mathrm\{Net\}is an equal\-weight summary of these two normalized stakeholder utilities\. Prior repeated runs showed approximately55percentage\-point standard deviation, so we use a pre\-specified±5\\pm 5\-point empirical equivalence band: creator utility in this interval is interpreted as exposure preserved within run variability, rather than as a meaningful loss or gain\. We nevertheless report the signed point estimates; per\-query bootstrap confidence intervals for the default\-engine main results are in Table[4](https://arxiv.org/html/2608.11390#A5.T4)\(App\.[E\.2](https://arxiv.org/html/2608.11390#A5.SS2)\), where VCR’s Net interval is separated from those of all baselines on every dataset\. Direct document and answer quality measures check the platform/user interpretation independently\.

#### Baselines and implementation\.

We compare VCR with three classical defenses spanning prompt\-level soft signals, source\-level exclusion, and content\-level filtering\.Prompt defenseattaches suspicion labels, softly reorders documents, and adds a system\-prompt warning\.Hard rejectremoves suspicious documents\.Keyword scrubfilters GEO\-style phrases\. Unless stated otherwise, the attacker isAutoGEO, the answer engine isgemini\-2\.5\-flash\-lite, andλ=1\\lambda=1\. Full details are in Apps\.[B](https://arxiv.org/html/2608.11390#A2)and[C](https://arxiv.org/html/2608.11390#A3)\.

### 5\.2Main Results

We report three main results: VCR achieves the best defense–utility \(Net\) outcome across datasets and engines, this outcome is backed by genuinely better documents and answers, and it generalizes across GEO attack strategies\.

#### Net outcome across datasets and engines\.

Table[1](https://arxiv.org/html/2608.11390#S5.T1)shows that VCR achieves the largest Net on every dataset and engine, with a12\.112\.1percentage\-point average advantage over the strongest baseline in each setting\. Classical defenses fail differently: Prompt defense and Keyword scrub approach inert outcomes, while Hard reject buys defense by suppressing creator exposure almost one\-for\-one\. VCR sustains defense while keeping creator exposure within the equivalence band in all nine settings, and it remains the only defense with strictly positive Net when the engine is replaced bygpt\-4o\-miniorclaude\-haiku\-4\-5, indicating that it operates on platform\-side source selection rather than idiosyncrasies of one generator\. We also sweep alternative weightings of the two stakeholder utilities in the Net definition\. VCR is preferred when both sides materially enter the objective; Hard reject overtakes only under a short\-sighted regime that heavily prioritizes immediate suppression over creator exposure, while Keyword scrub wins only when defense is nearly ignored \(App\.[E\.1](https://arxiv.org/html/2608.11390#A5.SS1)\)\.

#### Direct document and answer quality\.

Table[2](https://arxiv.org/html/2608.11390#S5.T2)complements citation exposure with direct LLM\-rubric evaluation\. VCR has the highest point estimate on all five document dimensions and on answer\-quality average\. Thus, its Net advantage is accompanied by more substantive rewrites and answers, rather than only better source placement\. Per\-round answer\-quality trajectories are in App\.[E\.7](https://arxiv.org/html/2608.11390#A5.SS7)\.

#### Generalization across GEO attack strategies\.

Figure[3](https://arxiv.org/html/2608.11390#S5.F3)\(a\) evaluates whether VCR depends on a specific GEO attacker\. We replace the defaultAutoGEOwith four additional attackers onE\-commerce:RAID\[[10](https://arxiv.org/html/2608.11390#bib.bib10)\],IF\-GEO\[[49](https://arxiv.org/html/2608.11390#bib.bib49)\],SAGEO\[[22](https://arxiv.org/html/2608.11390#bib.bib22)\], and Statistics Addition\[[1](https://arxiv.org/html/2608.11390#bib.bib1)\]\. Across all five attackers, VCR maintains positive Net atR5R\_\{5\}and consistently exceeds the three classical defenses, mirroring theAutoGEOpattern\.

Table 2:Direct quality onE\-commerce\. All metric names and averages are reported explicitly\.Rewritten documentGenerated answerDefenseClarityDepthInsightFactualityUsefulnessAverageClarityDepthInsightAveragePrompt\.820\.696\.605\.778\.718\.724\.549\.512\.457\.506Hard reject\.810\.727\.641\.788\.740\.741\.554\.526\.464\.515Keyword scrub\.813\.701\.608\.785\.724\.726\.554\.524\.465\.515VCR\.821\.741\.660\.820\.757\.760\.564\.526\.471\.520\(a\)R5R\_\{5\}Net \(%\) across five GEO attackers\.

\(b\) Per\-round Net \(%\)\.

Figure 3:VCRacross GEO attackers and interaction rounds onE\-commerce\. \(a\) Across five GEO attackers,VCRstays positive and consistently exceeds the three classical defenses by a large margin\. \(b\) Over five rounds underAutoGEO,VCRis the only defense that consistently maintains positive Net\.

### 5\.3Robustness Analysis

#### Round\-by\-round performance\.

Figure[3](https://arxiv.org/html/2608.11390#S5.F3)\(b\) shows the five\-round Net trajectory onE\-commerceunderAutoGEO\.VCRis the only method that stays in the positive Net region across rounds\. In contrast, Prompt defense gradually decays toward an inert outcome, Keyword scrub remains close to zero, and Hard reject stays slightly negative because its defense gains are offset by source\-exposure losses\. Trajectories on the other two datasets are reported in App\.[E\.6](https://arxiv.org/html/2608.11390#A5.SS6)\.

Figure 4:Robustness and ablation checks ofVCRonE\-commerce\.\(a\)Net when GEO rewrites target the lowest\-, middle\-, or highest\-quality candidate documents\.\(b\)Reward\-strength sweep overλ\\lambda\.\(c\)Ablation of the suspicion penalty, the verifiable\-content reward, and the soft re\-rank, with Net shown above each pair of bars\.
#### GEO on different target documents\.

Figure[4](https://arxiv.org/html/2608.11390#S5.F4)\(a\) reports Net under three target\-quality regimes\. Low, Mid, and High denote applying GEO strategies on the lowest\-, middle\-, and highest\-quality documents among the five retrieved candidates\.VCRachieves the highest Net in all regimes, showing that it remains effective even when applying GEO on target high\-quality documents, where manipulation signals are more correlated with genuine quality\.

#### Ablation on reward strengthλ\\lambda\.

Figure[4](https://arxiv.org/html/2608.11390#S5.F4)\(b\) sweeps the reward strengthλ\\lambda\. Asλ\\lambdaincreases, Def\. rises and then plateaus, while source\-exposure utility \(Welf\.\) moves from negative to positive\. This matches the predicted utility improvement, bounded by the credit cap\.

#### Ablation on the penalty and reward channels\.

Figure[4](https://arxiv.org/html/2608.11390#S5.F4)\(c\) removes each component of VCR in turn\.*No suspicion*keeps the verifiable\-content credit but drops the penalty: Net turns negative, as the supplier farms the reward without being defended against\.*No reward*is the penalty\-only Prompt defense, which stays near the inert outcome\.*No re\-rank*calls the same pair oracle as VCR but only hands its output to the engine as text in the prompt, so it matches VCR’s LLM budget and information; the outcome stays at the No\-reward level, showing that the extra oracle call contributes nothing unless the verification signal is enforced through the soft re\-rank\. Only the full combination converts the signal into a joint gain, so VCR’s advantage comes from the two\-sided incentive rather than from additional LLM budget\.

#### Additional robustness checks\.

As a supplement, the VCR–Prompt reward ordering is unchanged under GPT\-4o\-mini, Claude Haiku 4\.5, and Gemini 2\.5 Flash\-Lite judges \(App\.[E\.3](https://arxiv.org/html/2608.11390#A5.SS3)\)\. VCR also gives the best answer utility and precision in multi\-turn search \(App\.[E\.4](https://arxiv.org/html/2608.11390#A5.SS4)\), while the extended run is stable atR5R\_\{5\}before terminating atR8R\_\{8\}\(Fig\.[7](https://arxiv.org/html/2608.11390#A5.F7)\)\. Full deployment details, prompt and oracle specifications, and the roughly 400\-ms latency check are in Apps\.[B](https://arxiv.org/html/2608.11390#A2)and[G](https://arxiv.org/html/2608.11390#A7)\.

Table 3:Platform\-extracted GEO rules from supplier rewrites at rounds 1, 3, and 5 onE\-commerce, comparing the standard exploit baseline with our VCR mechanism\.RoundExploits \(baseline\)VCR \(ours\)R1R\_\{1\}Formatting:Hierarchical structure, bullets, bolding, concise wording; avoid jargon\.Quality:Hierarchical structure, scannable formatting, nuances, and distinctions\.R3R\_\{3\}Manipulation:Authentic\-source framing, Non\-GEO style, front\-loaded claims, strategic format\.Explanation:Mechanisms, rationales, causal links, accurate context, and explicit attribution\.R5R\_\{5\}Manipulation:Novel or authoritative information aligned with GEO principles; hidden GEO intent with AI\-friendly form\.Verifiability:Core findings separated from secondary information; verifiable, attributed, recent, and accurate information\.

### 5\.4Understanding the Effect of VCR

VCR’s advantage rests on three design questions that Figure[5](https://arxiv.org/html/2608.11390#S5.F5)answers in turn:RQ1:*What content should the reward credit?*\(a\);RQ2:*What evidence should verification trust?*\(b\); andRQ3:*Does the mechanism survive disclosure of its rule?*\(c\)\. Together, the answers show that the two\-sided improvement comes from the incentive structure itself, not from a lucky choice of reward scope, a trusting verifier, or secrecy\.

Figure 5:Probing the three design choices of the VCR reward channel onE\-commerce\.\(a\)Verifiable versus unverifiable content units added per rewrite under five candidate reward scopes\.\(b\)Reward earned and fabrications detected when verification uses the original pair versus an attacker\-created external “support page\.”\(c\)Net over rounds when the supplier is told the VCR rule and optimizes against it\.#### RQ1: what content should the reward credit?

Fig\.[5](https://arxiv.org/html/2608.11390#S5.F5)\(a\) re\-scores the same rewrites under five candidate reward scopes, separating content units that are grounded in the original from those that cannot be verified\. Fact\-style units are predominantly verifiable, whereas rewarding attribution or authority signals would credit a content type dominated by unverifiable claims, directly inviting fabricated sourcing\. Broadening the scope to explanatory or structural content preserves a positive Net while trading defense against exposure, so the conservative fact\-level scope is a robust rather than knife\-edge choice\.

#### RQ2: what evidence should verification trust?

Given fact\-level units, the next question is what evidence may vouch for them\. After each rewrite, the attacker additionally creates an external “support page” that justifies its fabricated claims\. As shown in Fig\.[5](https://arxiv.org/html/2608.11390#S5.F5)\(b\), verifying against the attacker\-created page nearly eliminates the earned reward, yet simultaneously weakens the fabrication penalty, letting a substantial share of unsupported claims go undetected\. External verification therefore opens a circular, gameable channel, whereas verification anchored on the original document pair stays outside the attacker’s control; trusted external verifiers remain future work\.

#### RQ3: does the mechanism survive disclosure?

With the reward unit and verification anchor fixed, the remaining concern is that disclosing the resulting rule invites reward hacking\. In Fig\.[5](https://arxiv.org/html/2608.11390#S5.F5)\(c\), the supplier is explicitly told the VCR rule and keeps optimizing against it over rounds\. Its Net drops relative to the standard supplier but remains far above Prompt throughout\. Because the reward only credits verifiable factual substance, the most profitable way to “game” VCR is to actually add checkable content, so strategic awareness weakens but cannot invert the joint gain\.

#### Case study: GEO rules\.

Table[3](https://arxiv.org/html/2608.11390#S5.T3)illustrates these incentives qualitatively by showing how platform\-inferred GEO rules evolve onE\-commerce\. AtR1R\_\{1\}, both settings mainly capture formatting signals\. ByR3R\_\{3\}andR5R\_\{5\}, the baseline shifts toward manipulation cues, such as authority framing and hidden GEO intent, while VCR shifts toward quality cues, such as explanation, attribution, and verifiability\. Since the extractor is unchanged, the divergence comes from the supplier’s response to the VCR reward\. More examples are provided in Apps\.[E\.8](https://arxiv.org/html/2608.11390#A5.SS8),[E\.10](https://arxiv.org/html/2608.11390#A5.SS10), and[E\.11](https://arxiv.org/html/2608.11390#A5.SS11)\.

## 6Conclusion

We studied citation competition as a repeated platform–creator game and showed how conventional defenses can approach an inert outcome\. VCR instead rewards source\-supported factual substance while penalizing suspicious manipulation\. Across the evaluated simulations, this incentive yields higher Net defense–utility, more substantive rewrites, and better generated answers; creator exposure remains within the55\-point empirical equivalence band in all nine settings\. To our knowledge, this is the first mechanism\-design treatment of generative engine optimization that turns platform defense from a filter into a two\-sided incentive; extending the model beyond a single platform and creator pool is a promising next step\.

## References

- Aggarwal et al\. \[2024\]Pranjal Aggarwal, Vishvak Murahari, Tanmay Rajpurohit, Ashwin Kalyan, Karthik Narasimhan, and Ameet Deshpande\.Geo: Generative engine optimization\.In*Proceedings of the 30th ACM SIGKDD conference on knowledge discovery and data mining*, pages 5–16, 2024\.
- Asai et al\. \[2024\]Akari Asai, Zeqiu Wu, Yizhong Wang, Avirup Sil, and Hannaneh Hajishirzi\.Self\-rag: Learning to retrieve, generate, and critique through self\-reflection\.In*The Twelfth International Conference on Learning Representations \(ICLR\)*, 2024\.
- Bagga et al\. \[2025\]Puneet S Bagga, Vivek F Farias, Tamar Korkotashvili, Tianyi Peng, and Yuhang Wu\.E\-geo: A testbed for generative engine optimization in e\-commerce\.*arXiv preprint arXiv:2511\.20867*, 2025\.
- Becchetti et al\. \[2006\]Luca Becchetti, Carlos Castillo, Debora Donato, Stefano Leonardi, and Ricardo A\. Baeza\-Yates\.Link\-based characterization and detection of web spam\.In*AIRWeb 2006, Proceedings of the Second International Workshop on Adversarial Information Retrieval on the Web, Seattle, Washington, USA, 10 August 2006, co\-located with SIGIR 2006*, pages 1–8, 2006\.
- Ben\-Porat and Tennenholtz \[2018\]Omer Ben\-Porat and Moshe Tennenholtz\.A game\-theoretic approach to recommendation systems with strategic content providers\.In*Advances in Neural Information Processing Systems 31 \(NeurIPS\)*, 2018\.
- Bohnet et al\. \[2023\]Bernd Bohnet, Vinh Q\. Tran, Pat Verga, Roee Aharoni, Daniel Andor, Livio Baldini Soares, Massimiliano Ciaramita, Jacob Eisenstein, Kuzman Ganchev, Jonathan Herzig, Kai Hui, Tom Kwiatkowski, Ji Ma, Jianmo Ni, Lierni Sestorain Saralegui, Tal Schuster, William W\. Cohen, Michael Collins, Dipanjan Das, Donald Metzler, Slav Petrov, and Kellie Webster\.Attributed question answering: Evaluation and modeling for attributed large language models\.*arXiv preprint arXiv:2212\.08037*, 2023\.
- Castillo and Davison \[2011\]Carlos Castillo and Brian D Davison\.Adversarial web search\.*Foundations and trends in Information Retrieval*, 4\(5\):377–486, 2011\.
- Chen et al\. \[2025a\]Qiyuan Chen, Jiahe Chen, Hongsen Huang, Qian Shao, Jintai Chen, Renjie Hua, Hongxia Xu, Ruijia Wu, Ren Chuan, and Jian Wu\.Cc\-gseo\-bench: A content\-centric benchmark for measuring source influence in generative search engines\.*arXiv preprint arXiv:2509\.05607*, 2025a\.
- Chen et al\. \[2025b\]Xiaolu Chen, Jie Bao, Haojie Wu, Zhen Chen, and Yong Liao\.Caption injection for optimization in generative search engine\.*arXiv preprint arXiv:2511\.04080*, 2025b\.
- Chen et al\. \[2025c\]Xiaolu Chen, Haojie Wu, Jie Bao, Zhen Chen, Yong Liao, and Hu Huang\.Role\-augmented intent\-driven generative search engine optimization\.*arXiv preprint arXiv:2508\.11158*, 2025c\.
- Chen et al\. \[2024\]Zhaorun Chen, Zhen Xiang, Chaowei Xiao, Dawn Song, and Bo Li\.Agentpoison: Red\-teaming llm agents via poisoning memory or knowledge bases\.In*Advances in Neural Information Processing Systems 37 \(NeurIPS\)*, 2024\.
- Edemacu et al\. \[2025\]Kennedy Edemacu, Vinay M\. Shashidhar, Micheal Tuape, Dan Abudu, Beakcheol Jang, and Jong Wook Kim\.Defending against knowledge poisoning attacks during retrieval\-augmented generation\.*arXiv preprint arXiv:2508\.02835*, 2025\.
- Es et al\. \[2024\]Shahul Es, Jithin James, Luis Espinosa\-Anke, and Steven Schockaert\.Ragas: Automated evaluation of retrieval augmented generation\.In*Proceedings of the 18th Conference of the European Chapter of the Association for Computational Linguistics: System Demonstrations*, 2024\.
- Fetterly et al\. \[2003\]Dennis Fetterly, Mark Manasse, Marc Najork, and Janet L\. Wiener\.A large\-scale study of the evolution of web pages\.In*Proceedings of the 12th International Conference on World Wide Web*, 2003\.
- Gao et al\. \[2023\]Tianyu Gao, Howard Yen, Jiatong Yu, and Danqi Chen\.Enabling large language models to generate text with citations\.In*Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing \(EMNLP\)*, 2023\.
- Goren et al\. \[2018\]Gregory Goren, Oren Kurland, Moshe Tennenholtz, and Fiana Raiber\.Ranking robustness under adversarial document manipulations\.In*The 41st International ACM SIGIR Conference on Research & Development in Information Retrieval*, pages 395–404, 2018\.
- Greshake et al\. \[2023\]Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz\.Not what you’ve signed up for: Compromising real\-world llm\-integrated applications with indirect prompt injection\.In*Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security \(AISec\)*, 2023\.
- Gyöngyi and Garcia\-Molina \[2005\]Zoltán Gyöngyi and Hector Garcia\-Molina\.Link spam alliances\.In*VLDB*, volume 5, pages 517–528, 2005\.
- Gyöngyi and Garcia\-Molina \[2005\]Zoltán Gyöngyi and Hector Garcia\-Molina\.Web spam taxonomy\.In*AIRWeb 2005, First International Workshop on Adversarial Information Retrieval on the Web, co\-located with the WWW conference, Chiba, Japan, May 2005*, pages 39–47, 2005\.
- Hardt et al\. \[2016\]Moritz Hardt, Nimrod Megiddo, Christos Papadimitriou, and Mary Wootters\.Strategic classification\.In*Proceedings of the 2016 ACM Conference on Innovations in Theoretical Computer Science \(ITCS\)*, pages 111–122, 2016\.
- Jagadeesan et al\. \[2023\]Meena Jagadeesan, Nikhil Garg, and Jacob Steinhardt\.Supply\-side equilibria in recommender systems\.In*Advances in Neural Information Processing Systems 36 \(NeurIPS\)*, 2023\.
- Kim et al\. \[2026\]Sunghwan Kim, Wooseok Jeong, Serin Kim, Sangam Lee, and Dongha Lee\.Sageo arena: A realistic environment for evaluating search\-augmented generative engine optimization\.*arXiv preprint arXiv:2602\.12187*, 2026\.
- Kleinberg and Raghavan \[2019\]Jon Kleinberg and Manish Raghavan\.How do classifiers induce agents to invest effort strategically?In*Proceedings of the 2019 ACM Conference on Economics and Computation \(EC\)*, 2019\.
- Kumar and Lakkaraju \[2024\]Aounon Kumar and Himabindu Lakkaraju\.Manipulating large language models to increase product visibility\.*arXiv preprint arXiv:2404\.07981*, 2024\.
- Lewis et al\. \[2020\]Patrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni, Vladimir Karpukhin, Naman Goyal, Heinrich Küttler, Mike Lewis, Wen tau Yih, Tim Rocktäschel, Sebastian Riedel, and Douwe Kiela\.Retrieval\-augmented generation for knowledge\-intensive nlp tasks\.In*Advances in Neural Information Processing Systems 33 \(NeurIPS\)*, 2020\.
- Liu et al\. \[2023a\]Nelson F\. Liu, Tianyi Zhang, and Percy Liang\.Evaluating verifiability in generative search engines\.In*Findings of the Association for Computational Linguistics: EMNLP 2023*, 2023a\.
- Liu et al\. \[2023b\]Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Zihao Wang, Xiaofeng Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, Leo Yu Zhang, and Yang Liu\.Prompt injection attack against llm\-integrated applications\.*arXiv preprint arXiv:2306\.05499*, 2023b\.
- Liu and Xu \[2026\]Zikang Liu and Peilan Xu\.Think before writing: Feature\-level multi\-objective optimization for generative citation visibility\.*arXiv preprint arXiv:2604\.19113*, 2026\.
- Marecki et al\. \[2012\]Janusz Marecki, Gerry Tesauro, and Richard Segal\.Playing repeated stackelberg games with unknown opponents\.In*Proceedings of the 11th International Conference on Autonomous Agents and Multiagent Systems \- Volume 2*, AAMAS ’12, Richland, SC, 2012\. International Foundation for Autonomous Agents and Multiagent Systems\.
- Min et al\. \[2023\]Sewon Min, Kalpesh Krishna, Xinxi Lyu, Mike Lewis, Wen tau Yih, Pang Wei Koh, Mohit Iyyer, Luke Zettlemoyer, and Hannaneh Hajishirzi\.Factscore: Fine\-grained atomic evaluation of factual precision in long form text generation\.In*Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing \(EMNLP\)*, 2023\.
- Nakano et al\. \[2021\]Reiichiro Nakano, Jacob Hilton, Suchir Balaji, Jeff Wu, Long Ouyang, Christina Kim, Christopher Hesse, Shantanu Jain, Vineet Kosaraju, William Saunders, Xu Jiang, Karl Cobbe, Tyna Eloundou, Gretchen Krueger, Kevin Button, Matthew Knight, Benjamin Chess, and John Schulman\.Webgpt: Browser\-assisted question\-answering with human feedback\.*arXiv preprint arXiv:2112\.09332*, 2021\.
- Nisan and Ronen \[2001\]Noam Nisan and Amir Ronen\.Algorithmic mechanism design\.*Games and Economic Behavior*, 35\(1–2\):166–196, 2001\.
- Ntoulas et al\. \[2004\]Alexandros Ntoulas, Junghoo Cho, and Christopher Olston\.What’s new on the web? the evolution of the web from a search engine perspective\.In*Proceedings of the 13th International Conference on World Wide Web*, 2004\.
- Ntoulas et al\. \[2006\]Alexandros Ntoulas, Marc Najork, Mark Manasse, and Dennis Fetterly\.Detecting spam web pages through content analysis\.In*Proceedings of the 15th International Conference on World Wide Web*, WWW ’06, page 83–92, 2006\.
- Oh et al\. \[2024\]Sejoon Oh, Gaurav Verma, and Srijan Kumar\.Adversarial text rewriting for text\-aware recommender systems\.In*Proceedings of the 33rd ACM International Conference on Information and Knowledge Management*\. ACM, 2024\.
- Perdomo et al\. \[2020\]Juan C\. Perdomo, Tijana Zrnic, Celestine Mendler\-Dünner, and Moritz Hardt\.Performative prediction\.In*Proceedings of the 37th International Conference on Machine Learning \(ICML\)*, 2020\.
- Perez and Ribeiro \[2022\]Fábio Perez and Ian Ribeiro\.Ignore previous prompt: Attack techniques for language models\.*arXiv preprint arXiv:2211\.09527*, 2022\.
- Puerto et al\. \[2025\]Haritz Puerto, Martin Gubri, Tommaso Green, Seong Joon Oh, and Sangdoo Yun\.C\-seo bench: Does conversational seo work?*arXiv preprint arXiv:2506\.11097*, 2025\.
- Su et al\. \[2024\]Jinyan Su, Jin Peng Zhou, Zhengxin Zhang, Preslav Nakov, and Claire Cardie\.Towards more robust retrieval\-augmented generation: Evaluating rag under adversarial poisoning attacks\.*arXiv preprint arXiv:2412\.16708*, 2024\.
- Von Stackelberg \[2010\]Heinrich Von Stackelberg\.*Market structure and equilibrium*\.Springer Science & Business Media, 2010\.
- Wallace et al\. \[2024\]Eric Wallace, Kai Xiao, Reimar Leike, Lilian Weng, Johannes Heidecke, and Alex Beutel\.The instruction hierarchy: Training llms to prioritize privileged instructions\.*arXiv preprint arXiv:2404\.13208*, 2024\.
- Wu et al\. \[2026\]Beining Wu, Fuyou Mao, Jiong Lin, Cheng Yang, Jiaxuan Lu, Yifu Guo, Siyu Zhang, Yifan Wu, Ying Huang, and Fu Li\.From experience to skill: Multi\-agent generative engine optimization via reusable strategy learning\.*arXiv preprint arXiv:2604\.19516*, 2026\.
- Wu et al\. \[2025\]Yujiang Wu, Shanshan Zhong, Yubin Kim, and Chenyan Xiong\.What generative search engines like and how to optimize web content cooperatively\.*arXiv preprint arXiv:2510\.11438*, 2025\.
- Xiang et al\. \[2024\]Chong Xiang, Tong Wu, Zexuan Zhong, David Wagner, Danqi Chen, and Prateek Mittal\.Certifiably robust rag against retrieval corruption\.*arXiv preprint arXiv:2405\.15556*, 2024\.
- Xue et al\. \[2024\]Jiaqi Xue, Mengxin Zheng, Yebowen Hu, Fei Liu, Xun Chen, and Qian Lou\.Badrag: Identifying vulnerabilities in retrieval augmented generation of large language models\.*arXiv preprint arXiv:2406\.00083*, 2024\.
- Yu et al\. \[2026\]Junwei Yu, Mufeng Yang, Yepeng Ding, and Hiroyuki Sato\.Structural feature engineering for generative engine optimization: How content structure shapes citation behavior\.*arXiv preprint arXiv:2603\.29979*, 2026\.
- Yuan et al\. \[2026\]Jiaqi Yuan, Jialu Wang, Zihan Wang, Qingyun Sun, Ruijie Wang, and Jianxin Li\.Agenticgeo: A self\-evolving agentic system for generative engine optimization\.*arXiv preprint arXiv:2603\.20213*, 2026\.
- Zhong et al\. \[2023\]Zexuan Zhong, Ziqing Huang, Alexander Wettig, and Danqi Chen\.Poisoning retrieval corpora by injecting adversarial passages\.In*Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing \(EMNLP\)*, 2023\.
- Zhou et al\. \[2026\]Heyang Zhou, JiaJia Chen, Xiaolu Chen, Jie Bao, Zhen Chen, and Yong Liao\.If\-geo: Conflict\-aware instruction fusion for multi\-query generative engine optimization\.*arXiv preprint arXiv:2601\.13938*, 2026\.
- Zou et al\. \[2025\]Wei Zou, Runpeng Geng, Binghui Wang, and Jinyuan Jia\.\{\\\{PoisonedRAG\}\\\}: Knowledge corruption attacks to\{\\\{Retrieval\-Augmented\}\\\}generation of large language models\.In*34th USENIX Security Symposium \(USENIX Security 25\)*, pages 3827–3844, 2025\.

## Appendix ALimitations and Open Directions

VCRmakes several simplifying assumptions\. First, the theory analyzes a local quadratic surrogate and the experiments use a finite interaction horizon; neither establishes a global equilibrium for unrestricted rewriting strategies\. The model also considers one platform and one creator population, leaving multi\-platform competition and paid placement to future work\.

Second, the reward checks a rewrite against its earlier version\. It measures source support and factual salience, not independent truth: an inaccurate statement already present in the earlier version may still receive credit\. Moreover, LLM\-based claim counting and rule matching can err, and suppliers may repeat or split supported claims to approach the reward cap\. The cap and manipulation penalty reduce, but do not eliminate, these risks\.

Finally, the reported utilities represent creator exposure and a joint platform/user objective, with equal weight in Net\. The±5\\pm 5\-point creator equivalence band is an operational tolerance motivated by prior repeated\-run variation, not a formal equivalence test for each current estimate\. We report paired query\-level bootstrap intervals for the default\-engine results; additional independent pipeline runs would quantify model\- and trajectory\-level variability beyond this query\-sampling uncertainty\.

## Appendix BImplementation Details

#### Hardware and runtime\.

All experiments are run on a SLURM cluster\. Each job uses88CPU cores and6464GB RAM; no GPU is used\. A single five\-round game on the full1,0001\{,\}000\-query test split takes1818–2424wall\-clock hours onGEO\-BenchandResearchy\-GEO, and1212–1515hours onE\-commerce\. Smaller diagnostic runs and ablations typically take44–66hours\. VCR adds one cached, JSON\-only oracle call per changed pair to the rule extraction shared with Prompt defense\. In an online latency test, all four defenses complete answer\-time processing in approximately400400ms; the pair\-level oracle runs off the answer\-time path\.

#### Models\.

The answer\-generation engineGGisgemini\-2\.5\-flash\-lite\. The platform\-side rule extractor \(Explainer/Extractor/Merger/Filter\), the change\-magnitude judge, and the verifiable\-content oracle all usegpt\-4o\-miniwith temperature00and JSON\-only decoding when applicable\. We pre\-compute and cache quality\-judge scores for each dataset so that target selection is deterministic across runs\.

#### Game configuration\.

Each repeated game runs forT=5T=5rounds\. To make trajectories comparable across defenses, we disable early stopping in all reported experiments; the supplier and platform always interact for all five rounds\. The change\-magnitude thresholdθ\\thetais set so that the median edited document contributes to the rule set in roundR1R\_\{1\}\. Unless otherwise stated, the reward strength isλ=1\\lambda=1\. The per\-claim creditcnc\_\{n\}and credit capcmaxc\_\{\\max\}are calibrated to be on the same scale as the weakest and strongest single suspicion penalties in the rule pipeline\. Theλ\\lambdasweep in Fig\.[4](https://arxiv.org/html/2608.11390#S5.F4)\(b\) covers the same effective range as multiplying the per\-claim credit by an equivalent factor\.

## Appendix CDefense and Attacker Baselines

#### Defense baselines\.

We compare against three classical platform\-side defenses\.Prompt defenseattaches a per\-document suspicion label, softly reorders sources by ascending suspicion, and inserts the warning template in App\.[G\.2](https://arxiv.org/html/2608.11390#A7.SS2)into the engine’s system prompt\. No document is removed\.Hard rejectdrops any document whose suspicion score exceedsτ=0\.45\\tau=0\.45before generation; the threshold is tuned on a5050\-query development split\.Keyword scrubdisables all prompt\-defense channels and instead applies a regex filter over2424GEO\-style phrases, such as “optimized for GEO”, “expert\-curated”, and “machine\-readable listing”, to every incoming document\. The full phrase list is released with our code\.

#### GEO attacker baselines\.

In Sec\.[5\.3](https://arxiv.org/html/2608.11390#S5.SS3), we evaluate robustness against four non\-AutoGEOattackers\.RAID\[[10](https://arxiv.org/html/2608.11390#bib.bib10)\]extracts engine\-preference rules from contrastive role\-conditioned answers; we use the authors’ released codebase with the engine replaced by ours\.IF\-GEO\[[49](https://arxiv.org/html/2608.11390#bib.bib49)\]performs influence\-based GEO; we re\-implement its influence proxy on top of our engine\.SAGEO\[[22](https://arxiv.org/html/2608.11390#bib.bib22)\]performs structure\-aware GEO via prompt programming; we use the authors’ prompts with the top\-55candidate set from our retriever\. Statistics Addition\[[1](https://arxiv.org/html/2608.11390#bib.bib1)\]adds quantitative claims following the original paper\.

## Appendix DEvaluation Metrics

We adopt the AutoGEO framework of[Wu et al\. 2025](https://arxiv.org/html/2608.11390#bib.bib43)and the visibility metric of[Aggarwal et al\. 2024](https://arxiv.org/html/2608.11390#bib.bib1)\. For a queryqq, the engine retrieves a candidate setDqD\_\{q\}, and an LLMGGproduces an answera=G⁡\(q,Dq\)a=G\(q,D\_\{q\}\)\. Each candidate documentd∈Dqd\\in D\_\{q\}receives a citation visibility score

Vis⁡\(d,a\)=Word⁡\(d,a\)\+Pos⁡\(d,a\)\+Overall⁡\(d,a\),\\mathrm\{Vis\}\(d,a\)=\\mathrm\{Word\}\(d,a\)\+\\mathrm\{Pos\}\(d,a\)\+\\mathrm\{Overall\}\(d,a\),\(14\)whereWord⁡\(d,a\)\\mathrm\{Word\}\(d,a\)is the normalized word count of sentences inaacitingdd,Pos⁡\(d,a\)\\mathrm\{Pos\}\(d,a\)is the location\-based weight of the source\-linked text, andOverall⁡\(d,a\)\\mathrm\{Overall\}\(d,a\)integrates the two signals\. We follow[Aggarwal et al\. 2024](https://arxiv.org/html/2608.11390#bib.bib1)for the exact implementation\.

Given the supplier’s target setT⁡\(q\)⊆DqT\(q\)\\subseteq D\_\{q\}, the target GEO score for queryqqis

g⁡\(q\)=∑d∈T⁡\(q\)Vis⁡\(d,a\),g=𝔼q​\[g⁡\(q\)\]\.g\(q\)=\\sum\_\{d\\in T\(q\)\}\\mathrm\{Vis\}\(d,a\),\\qquad g=\\mathbb\{E\}\_\{q\}\[g\(q\)\]\.\(15\)A higherggmeans the target documents are cited more prominently in the engine’s answer\.

## Appendix EAdditional Experiments and Case Studies

### E\.1Sensitivity to the Net Weighting

Net weights the two stakeholder utilities equally\. To check that the defense ranking does not depend on this choice, define

Netω=ω​Def\+\(1−ω\)​Welf,ω∈\[0,1\],\\mathrm\{Net\}\_\{\\omega\}=\\omega\\,\\mathrm\{Def\}\+\(1\-\\omega\)\\,\\mathrm\{Welf\},\\qquad\\omega\\in\[0,1\],\(16\)so thatω=0\.5\\omega=0\.5recovers the main metric up to scale\. Figure[6](https://arxiv.org/html/2608.11390#A5.F6)\(a\) shows the Pareto view of the four defenses across the three datasets: Hard reject lies on theNet=0\\mathrm\{Net\}=0diagonal, meaning it buys defense one\-for\-one with creator exposure; Prompt and Keyword scrub cluster at the origin; and VCR is the only defense inside the win\-win region on every dataset\. Figure[6](https://arxiv.org/html/2608.11390#A5.F6)\(b\) sweepsω\\omegaonE\-commerce\. VCR is the optimal defense for allω<0\.60\\omega<0\.60onE\-commerce, forω∈\(0\.24,0\.57\)\\omega\\in\(0\.24,0\.57\)onGEO\-Bench, and forω∈\(0\.20,0\.53\)\\omega\\in\(0\.20,0\.53\)onResearchy\-GEO\. Hard reject overtakes only when creator utility is nearly ignored \(ω≳0\.6\\omega\\gtrsim 0\.6\), and the near\-inert Keyword scrub wins only when defense is nearly ignored\.

In practice,ω\>0\.6\\omega\>0\.6describes a short\-sighted platform objective that values one point of immediate suppression more than1\.51\.5points of creator exposure\. At the Hard\-reject operating point this removes roughly half of creators’ natural exposure \(Welf\.≈−50\\approx\-50onE\-commerce\): the current answer is protected, but the citation traffic that motivates future content supply is lost\. At the opposite extreme, Keyword scrub wins only when the platform nearly ignores defense\. Thus, the alternatives overtake VCR in one\-sided regimes that omit one of the two ecosystem objectives, rather than under the two\-sided mechanism\-design setting studied here\.

Figure 6:Sensitivity of the defense ranking to the Net weighting\.\(a\)Pareto view of \(Def\., Welf\.\) for all defenses and datasets; the shaded band is the win\-win region \(positive Def\. with creator utility within the±5\\pm 5\-point equivalence band or better\)\.\(b\)Netω\\mathrm\{Net\}\_\{\\omega\}onE\-commerce: VCR is optimal for every platform weightω\\omegabelow≈0\.60\{\\approx\}0\.60\.
### E\.2Statistical Uncertainty

To quantify the statistical uncertainty of the reported utilities, we compute paired per\-query bootstrap confidence intervals at round55\. For each run we pair the three per\-query target GEO scores that enter the metrics \(no\-attack, attacked, and defended\), resample queries with replacement \(10410^\{4\}replicates\), and recompute Def\., Welf\., and Net on each replicate; Table[4](https://arxiv.org/html/2608.11390#A5.T4)reports95%95\\%percentile intervals for the full\-scale main runs behind the Gemini block of Table[1](https://arxiv.org/html/2608.11390#S5.T1)\.

The default\-engine conclusions are well separated from query\-sampling uncertainty\. On every dataset, VCR’s Net interval lies entirely above the intervals of all three classical defenses, which all straddle or hug zero\. For creator utility, theGEO\-BenchandResearchy\-GEOintervals are fully contained in the±5\\pm 5\-point band, while theE\-commerceinterval closely tracks it and reaches5\.45\.4at its upper endpoint\. We therefore treat the band as an empirical operational criterion rather than claim a formal equivalence test\.

Table 4:Paired per\-query bootstrap95%95\\%confidence intervals at round55for the full\-scale main runs \(percentage points\)\.DatasetDefenseDef\. \[CI\]Welf\. \[CI\]Net \[CI\]E\-commercePrompt2\.72\.7\[0\.2,5\.1\]\[0\.2,5\.1\]−2\.0\-2\.0\[−4\.6,0\.6\]\[\-4\.6,0\.6\]0\.70\.7\[−1\.5,2\.8\]\[\-1\.5,2\.8\]Hard reject50\.350\.3\[40\.0,59\.8\]\[40\.0,59\.8\]−50\.8\-50\.8\[−60\.3,−40\.9\]\[\-60\.3,\-40\.9\]−0\.6\-0\.6\[−2\.0,0\.7\]\[\-2\.0,0\.7\]Keyword scrub−1\.0\-1\.0\[−2\.7,0\.6\]\[\-2\.7,0\.6\]0\.00\.0\[−1\.9,1\.9\]\[\-1\.9,1\.9\]−1\.0\-1\.0\[−2\.9,0\.9\]\[\-2\.9,0\.9\]VCR14\.414\.4\[12\.0,16\.8\]\[12\.0,16\.8\]2\.22\.2\[−0\.9,5\.4\]\[\-0\.9,5\.4\]16\.6\\mathbf\{16\.6\}\[13\.7,19\.6\]\[13\.7,19\.6\]GEO\-BenchPrompt3\.43\.4\[2\.2,4\.6\]\[2\.2,4\.6\]−3\.5\-3\.5\[−4\.7,−2\.2\]\[\-4\.7,\-2\.2\]−0\.1\-0\.1\[−1\.1,1\.0\]\[\-1\.1,1\.0\]Hard reject33\.833\.8\[26\.7,40\.7\]\[26\.7,40\.7\]−33\.2\-33\.2\[−40\.1,−25\.9\]\[\-40\.1,\-25\.9\]0\.60\.6\[−0\.1,1\.4\]\[\-0\.1,1\.4\]Keyword scrub−0\.1\-0\.1\[−1\.0,0\.7\]\[\-1\.0,0\.7\]0\.30\.3\[−0\.7,1\.2\]\[\-0\.7,1\.2\]0\.10\.1\[−0\.8,1\.1\]\[\-0\.8,1\.1\]VCR11\.411\.4\[10\.1,12\.7\]\[10\.1,12\.7\]−3\.3\-3\.3\[−4\.7,−2\.1\]\[\-4\.7,\-2\.1\]8\.0\\mathbf\{8\.0\}\[6\.8,9\.3\]\[6\.8,9\.3\]Researchy\-GEOPrompt0\.80\.8\[−0\.2,1\.9\]\[\-0\.2,1\.9\]−0\.7\-0\.7\[−1\.8,0\.3\]\[\-1\.8,0\.3\]0\.10\.1\[−0\.8,1\.1\]\[\-0\.8,1\.1\]Hard reject63\.963\.9\[58\.3,69\.2\]\[58\.3,69\.2\]−63\.3\-63\.3\[−68\.8,−57\.8\]\[\-68\.8,\-57\.8\]0\.50\.5\[0\.2,0\.9\]\[0\.2,0\.9\]Keyword scrub0\.20\.2\[−0\.6,0\.9\]\[\-0\.6,0\.9\]0\.20\.2\[−0\.6,1\.0\]\[\-0\.6,1\.0\]0\.30\.3\[−0\.5,1\.2\]\[\-0\.5,1\.2\]VCR8\.08\.0\[6\.9,9\.0\]\[6\.9,9\.0\]−1\.7\-1\.7\[−2\.8,−0\.5\]\[\-2\.8,\-0\.5\]6\.3\\mathbf\{6\.3\}\[5\.3,7\.3\]\[5\.3,7\.3\]
### E\.3Judge Robustness

To study whether the verifiable\-content reward depends on the specific pair\-level LLM oracle, we take the same two pools of round\-5 rewrites, one produced under Prompt defense and one under VCR, and re\-score every pair with three independent judge models from three different providers \(Table[5](https://arxiv.org/html/2608.11390#A5.T5)\)\. If the reward reflected the idiosyncrasies of one judge rather than the substance of the rewrites, gaming the judge would amount to gaming the mechanism; what the mechanism actually requires is only that the ordering be stable across judges\.

From the results, we can see that the reward signal is robust to the choice of judge\. The three judges differ in how conservatively they score, so the absolute reward levels shift from judge to judge, but every judge assigns clearly more verifiable\-content reward to the VCR\-arm rewrites than to the Prompt\-arm rewrites\. The signal that drives the mechanism is therefore a property of the rewrites themselves rather than of one particular oracle, and the residual disagreement between judges is in line with the moderate cross\-judge agreement reported in prior GEO evaluations\[[1](https://arxiv.org/html/2608.11390#bib.bib1),[43](https://arxiv.org/html/2608.11390#bib.bib43)\]\.

Table 5:Verifiable\-content reward assigned by three independent judges\.Rewrites fromGPT\-4o\-miniClaude\-Haiku\-4\.5Gemini\-2\.5\-Flash\-LitePrompt defense0\.2130\.1800\.244VCR0\.2430\.1940\.273
### E\.4Multi\-Turn Search

To study whether VCR’s advantage survives beyond the single retrieval\-generation pass of the main experiments, we extend the environment to a multi\-turn search session: the engine issues several search steps for one user question, accumulates evidence across steps, and only then composes the answer, with the defense applied at every retrieval step\. This setting changes the exposure economics, since a manipulated document has several chances to enter the context and an over\-aggressive defense has several chances to drop useful evidence\. We compare an undefended attacked session, Prompt defense, and VCR \(Table[6](https://arxiv.org/html/2608.11390#A5.T6)\)\.

From the results, we can see that the single\-pass advantage carries over\. VCR attains the best citation precision and the best user\-side answer utility of the three conditions, while its recall stays essentially perfect, so the added filtering does not cost the session useful evidence\. The undefended attacked session reaches higher raw visibility for the target documents but pays for it with lower precision and weaker answers, which is the multi\-turn analogue of the exploitation pattern in the single\-pass game\.

Table 6:Results in the multi\-turn search setting\.ConditionGEO scorePrecisionRecallSupportGEU averagePrompt defense0\.14260\.69680\.99000\.56200\.5777AutoGEO0\.19900\.69200\.98500\.52600\.5836VCR0\.19240\.72070\.98940\.56000\.5998
### E\.5Extended Convergence Check

To study whether the fixed five\-round horizon of the main experiments truncates the interaction too early, we rerun the full game without the fixed horizon and let it continue until its built\-in stopping check terminates it, several rounds past the main evaluation point \(Fig\.[7](https://arxiv.org/html/2608.11390#A5.F7)\)\. If the supplier\-platform dynamics were still moving at round five, endpoint comparisons could be artifacts of where we stop rather than properties of the defenses\.

From the results, we can see that the five\-round endpoint is a representative snapshot of the stabilized interaction\. Both the attacked and the defended target GEO scores flatten before the main horizon and remain essentially unchanged through the additional rounds, with no late drift or reversal\. The endpoints used in the main tables therefore reflect stabilized behavior of the repeated game, although we do not claim that any five\-round simulation constitutes a general real\-world equilibrium\.

![Refer to caption](https://arxiv.org/html/2608.11390v1/extended_convergence.png)Figure 7:Eight\-round convergence check\. The dashed line marks the main evaluation horizon; attacked and defended target GEO scores remain stable thereafter\.
### E\.6Round\-by\-Round Dynamics across all datasets

Figure[8](https://arxiv.org/html/2608.11390#A5.F8)extends the main\-text trajectory onE\-commerceto all three benchmarks\.VCRconsistently maintains positive Net across rounds and datasets\. Prompt defense decays by the second round as the attacker adapts\. Keyword scrub stays near zero throughout, while Hard reject oscillates around zero because its defense gains are offset by welfare losses\. These dynamics match the theory: classical defenses depend on manipulation signals that can be eroded through repeated adaptation, whereasVCRrewards a verifiable\-content direction that is welfare\-aligned and harder to neutralize by surface rewriting\.

Figure 8:Round\-by\-round Net performance over five GEO–platform interaction rounds across all three benchmarks\.VCRconsistently maintains positive Net across datasets\.
### E\.7User\-Side Utility \(GEU\)

We complement these metrics with the user\-side GEU score \(Generative\-Engine Utility\), following the answer\-quality evaluation protocol of[Aggarwal et al\. 2024](https://arxiv.org/html/2608.11390#bib.bib1)\. GEU is computed bygpt\-4o\-minion the engine’s final answer and directly measures whether the defense improves the end user’s experience\. Tab\.[7](https://arxiv.org/html/2608.11390#A5.T7)reports two aggregate summaries\.

Tab\.[7](https://arxiv.org/html/2608.11390#A5.T7)further reports per\-round GEU on three substance dimensions: Clarity, Depth, and Insightfulness, comparingVCRwith the standard baseline pipeline\. The results show three clear trends\. First, the two defenses perform similarly in the first round, suggesting that the later gap is unlikely to be caused by initial\-condition artifacts\. Second, as the interaction proceeds,VCRconsistently improves over the baseline across all three dimensions, indicating that the multi\-round mechanism gradually translates verifiable\-content incentives into better user\-facing answers\. Third, the improvements are stable across different substance dimensions rather than concentrated in a single metric\. Overall, these results suggest thatVCRnot only improves platform\-side outcomes, as shown in Tab\.[1](https://arxiv.org/html/2608.11390#S5.T1), but also produces more informative and useful answers for end users\.

Table 7:Per\-round GEU substance dimensions onE\-commerce\.VCRconsistently improves Clarity, Depth, and Insightfulness after the first round\.DimDefenseR1R\_\{1\}R2R\_\{2\}R3R\_\{3\}R4R\_\{4\}R5R\_\{5\}Avg \(R1→R5R\_\{1\}\\\!\\to\\\!R\_\{5\}\)ClarityBaseline0\.5510\.5510\.5510\.5510\.5480\.5480\.5490\.5490\.5490\.5490\.5500\.550VCR\(ours\)0\.5480\.5480\.568\\mathbf\{0\.568\}0\.563\\mathbf\{0\.563\}0\.564\\mathbf\{0\.564\}0\.564\\mathbf\{0\.564\}0\.562\\mathbf\{0\.562\}DepthBaseline0\.5030\.5030\.5140\.5140\.5160\.5160\.5170\.5170\.5130\.5130\.5130\.513VCR\(ours\)0\.5000\.5000\.526\\mathbf\{0\.526\}0\.522\\mathbf\{0\.522\}0\.520\\mathbf\{0\.520\}0\.525\\mathbf\{0\.525\}0\.518\\mathbf\{0\.518\}InsightfulnessBaseline0\.4500\.4500\.4570\.4570\.4600\.4600\.4560\.4560\.4570\.4570\.4560\.456VCR\(ours\)0\.4500\.4500\.474\\mathbf\{0\.474\}0\.470\\mathbf\{0\.470\}0\.467\\mathbf\{0\.467\}0\.471\\mathbf\{0\.471\}0\.466\\mathbf\{0\.466\}
### E\.8Full Rule\-Alignment Trajectories

Figure[9](https://arxiv.org/html/2608.11390#A5.F9)tracks the alignment between the platform’s inferred rules and the attacker’s actual rewriting strategy over rounds\. With the full VCR pipeline, the inferred rules stay aligned with attacker behavior as the attacker adapts; removing the VCR stage causes the extractor to drift toward generic quality patterns, showing that the reward\-based filtering is what keeps the defense locked onto manipulation\-specific signals\.

Table[8](https://arxiv.org/html/2608.11390#A5.T8)reports the per\-round rule\-alignment score⟨rt,r^t⟩\\langle r\_\{t\},\\hat\{r\}\_\{t\}\\ranglebetween the attacker’s actual rule set and the platform’s extracted suspicion rules\. We comparehigh3andlow3target\-quality buckets, with and without theVCRFilterstage\. Across both buckets, alignment improves whenFilteris used and degrades when it is removed\. This supports the role ofFilter: it removes generic quality clauses that would match honest content and concentrates the platform rule set on attacker\-specific GEO axes\. Figure[9](https://arxiv.org/html/2608.11390#A5.F9)plots thehigh3trajectory\.

Figure 9:Alignment between platform\-inferred rules and attacker strategy over rounds, with and without VCR filtering \(high3bucket\)\.high3low3Roundw/o FilterVCRfullw/o FilterVCRfullR1R\_\{1\}0\.9450\.9450\.8580\.8580\.9580\.9580\.8920\.892R2R\_\{2\}0\.9070\.9070\.8940\.8940\.9000\.9000\.9030\.903R3R\_\{3\}0\.8940\.8940\.9120\.9120\.9550\.9550\.9260\.926R4R\_\{4\}0\.8680\.8680\.9310\.9310\.8350\.8350\.8080\.808R5R\_\{5\}0\.8650\.8650\.934\\mathbf\{0\.934\}0\.8550\.8550\.943\\mathbf\{0\.943\}Table 8:Round\-by\-round rule alignment⟨rt,r^t⟩\\langle r\_\{t\},\\hat\{r\}\_\{t\}\\ranglebetween attacker rules and platform suspicion rules\. With theFilterstage, alignment increases over rounds; without it, alignment drifts downward\.
### E\.9Case Study: Platform Rule Refinement underVCR

We inspect how the platform’s suspicion rules evolve across rounds\. Table[9](https://arxiv.org/html/2608.11390#A5.T9)compares the top rules extracted atR1R\_\{1\}andR5R\_\{5\}under the fullVCRpipeline\. AtR1R\_\{1\}, the extracted rules mostly reflect generic writing principles, such as relevance, concision, and structure\. These rules can also match honest content and therefore risk false positives\. ByR5R\_\{5\}, the rules become more attacker\-specific: they emphasize negative\-constraint coverage, atomic quotability, explicit GEO signaling, and provenance attribution\. This refinement is consistent with the increasing rule alignment in Fig\.[9](https://arxiv.org/html/2608.11390#A5.F9)\.

Table 9:Platform\-side suspicion rules under fullVCRatR1R\_\{1\}andR5R\_\{5\}\. Early rules are often generic writing\-quality heuristics, while later rules become more specific to attacker behavior\. Rules are truncated for display\.DatasetRoundTop\-33platform suspicion rulesr^t\\hat\{r\}\_\{t\}under fullVCRE\-commerceR1R\_\{1\}Content must be highly relevant and directly address the user’s query, avoiding extraneous, promotional, or conversational filler\.Content should be exceptionally well\-structured for AI consumption, using clear headings, lists, and highlighted key terms\.Documents demonstrating explicit optimization for AI consumption and GEO principles for structured extraction are preferred\.R5R\_\{5\}Directly address all explicit and implicit aspects of the query, including constraints and negative constraints\.Ensure core query components are explicitly identified and prominently featured\.Prioritize factual, specific, quantifiable details over narrative descriptions or extraneous meta\-commentary\.GEO\-BenchR1R\_\{1\}Content must be highly relevant and directly address the user’s query, minimizing extraneous or tangential information\.Content should be concise and efficient, without unnecessary verbosity, jargon, or conversational filler\.Content should be optimized for machine readability and AI consumption, adhering to GEO principles\.R5R\_\{5\}Clearly differentiate and compare related concepts, address potential misconceptions, and offer disambiguating information\.Ensure content is atomic and segmentable, optimized for direct quotation and synthesis by generative AI systems\.Explicitly signal document optimization for AI consumption and GEO principles through structure, phrasing, and relevance\.ResearchyR1R\_\{1\}Content must be accurate, credible, and verifiable, supported by data, examples, and citations to reputable sources\.Content must be highly relevant to the query, with key information presented early and prominently\.Content must be presented in a structured, scannable format with descriptive headings and hierarchical organization\.R5R\_\{5\}Content should be presented in an atomic, easily isolatable format, with direct, assertive, and quotable statements for streamlined AI synthesis\.Provide specific, actionable details, concrete examples, and clear “how/why” explanations rather than general statements\.Information must be factual, accurate, specific, and verifiable, including precise data points, dates, names, and figures\.
### E\.10Case Study: Cross\-Attacker Rule Convergence underVCR

AutoGEOis already analyzed in Tab\.[3](https://arxiv.org/html/2608.11390#S5.T3); here we show the remaining four attackers\. We inspect whyVCRmaintains positive Net across the four non\-AutoGEOattackers in Fig\.[3](https://arxiv.org/html/2608.11390#S5.F3)\(a\)\. For each attacker, we take the top platform rule extracted atR5R\_\{5\}onE\-commerce, under Prompt defense and underVCR\. TheR1R\_\{1\}rules are generic writing\-quality clauses for all attackers \(cf\. Tab\.[9](https://arxiv.org/html/2608.11390#A5.T9),R1R\_\{1\}rows\) and are omitted\.

Table 10:Top platform rule atR5R\_\{5\}onE\-commercefor the four non\-AutoGEOattackers\. Under Prompt defense, the rule tracks each attacker’s specific manipulation pattern\. UnderVCR, the rule of all four attackers converges onto a common verifiability axis\. Rules are taken fromplatform/merged\_rules\.jsonand lightly truncated\.AttackerTop platform rule underPrompt defense\(R5R\_\{5\}\)Top platform rule underVCR\(R5R\_\{5\}\)RAIDContent must directly address the user’s query, prioritizingactionable advice, clear recommendations, and specific value propositionsover meta\-analysis or tangential details\.The document should demonstrateauthority and trustworthiness through accurate, up\-to\-date, specific, and quantifiable information, potentially including sourcing, comparative data, and concrete examples,framed with confident and definitive language\.SAGEOContent should be organized intoself\-contained, logically segmented blocks or sectionsthat are easily parsable and directly usable by language models\.The document should beself\-contained, offering sufficient core information without immediate reliance on external linksfor basic details\.Statistics AdditionThe document must presentaccurate, verifiable, and up\-to\-date factual information and statistics, supported by credible sourcesand specific evidence\.The document must befactually accurate, verifiable, and up\-to\-date,avoiding generalizations, vague statements, or outdated content\.IF\-GEOThe document shouldanticipate user needs and concerns, providing proactive advice, warnings, context, and practical guidancefor decision\-making and implementation\.Information must beaccurate, verifiable, and up\-to\-date, providing specific evidence, citations, disclaimers, and clearly stating temporal relevanceor limitations\.Under Prompt defense, the four rules diverge and each captures a different manipulation pattern: recommendation framing forRAID, segmented blocks forSAGEO, sourced statistics for Statistics Addition, and proactive guidance forIF\-GEO\. The platform locates each attacker, but Prompt defense gives the supplier no reward for honest content, so all four runs end with near\-zero or negative Net\. UnderVCR, the four rules collapse onto the same verifiability axis \(accurate, verifiable, sourced, specific evidence\)\. The verifiable\-content reward then pays the supplier for the same kind of content regardless of attacker, which matches the uniform positive Net in Fig\.[3](https://arxiv.org/html/2608.11390#S5.F3)\(a\) and the gradient\-redirection result of Thm\.[2](https://arxiv.org/html/2608.11390#Thmtheorem2)\.

### E\.11Case Study: Escalating Fabrications

We measure hallucination harm with a pair\-level LLM judge \(gpt\-4o\-mini, temperature00\) that compares each original and rewritten document\. The judge returns the number of unsupported claimsuiu\_\{i\}and their severitysi∈\{1,…,5\}s\_\{i\}\\in\\\{1,\\ldots,5\\\}, where larger severity indicates more central fabrications\. We aggregate these judgments as

ξ−=f⋅max\(0,s¯u\>0−14\),f=Pri\[ui\>0\],s¯u\>0=𝔼\[si∣ui\>0\],\\xi^\{\-\}=f\\cdot\\max\\\!\\left\(0,\\frac\{\\bar\{s\}\_\{u\>0\}\-1\}\{4\}\\right\),\\qquad f=\\Pr\_\{i\}\[u\_\{i\}\>0\],\\qquad\\bar\{s\}\_\{u\>0\}=\\mathbb\{E\}\[s\_\{i\}\\mid u\_\{i\}\>0\],\(17\)whereffis the fraction of rewrites containing unsupported claims, and the second term normalizes conditional severity to\[0,1\]\[0,1\]\. Thus,ξ−\\xi^\{\-\}is a frequency\-weighted hallucination cost per rewritten document\. It enters the welfare decompositionξ=ξ\+−ξ−\\xi=\\xi^\{\+\}\-\\xi^\{\-\}in Eq\. \([7](https://arxiv.org/html/2608.11390#S3.E7)\), whereξ\+\\xi^\{\+\}captures formatting or readability gains andξ−\\xi^\{\-\}captures hallucination harm\. Full prompts are in App\.[G\.3](https://arxiv.org/html/2608.11390#A7.SS3)\.

Figure[1](https://arxiv.org/html/2608.11390#S1.F1)shows aE\-commerceexample underPrompt defense\. Table[11](https://arxiv.org/html/2608.11390#A5.T11)repeats the same query–document pair underVCR\. UnderPrompt defense, the rewrite accumulates unsupported specifics over rounds\. UnderVCR, the rewrite instead foregrounds source\-supported details, such as platform information and qualitative descriptions of cooperative play\. This matches the gradient\-redirection effect predicted by Thm\.[2](https://arxiv.org/html/2608.11390#Thmtheorem2)\.

Table 11:Case study of the same query–document pair\. We show rewritten content across rounds, together with hallucination harmξ−\\xi^\{\-\}and the number of unsupported claims\.RoundPrompt defenseVCRR1R\_\{1\}ARK is “highly rated” with “intricate building systems”; Roblox hosts “millions of user\-created games\.”ARK is a sandbox\-survival game praised for building systems; Roblox is a user\-generated\-content platform\.R3R\_\{3\}GEO\-optimized rewrite adds “high\-fidelity 3D graphics,” “higher polygon counts,” and “advanced textures\.”Source\-grounded rewrite highlights ARK multiplayer building and Roblox as a PC/mobile/console UGC platform\.R5R\_\{5\}Rewrite escalates to “over 100 unique dinosaurs” and “deep multiplayer tribal systems for cooperative base building\.”Rewrite keeps to source\-supported claims: ARK tribe\-based building and Roblox user\-generated worlds\.Hallucination harmξ−\\xi^\{\-\}0\.420\.420\.210\.21Unsupported claims4–61

## Appendix FProofs

This appendix proves the results in the main text\. We use the notation from Sec\.[3](https://arxiv.org/html/2608.11390#S3): document features\(qi,mi\)\(q\_\{i\},m\_\{i\}\), correlationρ=corr⁡\(qi,mi\)\\rho=\\mathrm\{corr\}\(q\_\{i\},m\_\{i\}\), source\-model logitvi​\(α\)=βq​qi−α​mi\+biv\_\{i\}\(\\alpha\)=\\beta\_\{q\}q\_\{i\}\-\\alpha m\_\{i\}\+b\_\{i\}, citation massci​\(α\)=softmax​\{vj​\(α\)\}ic\_\{i\}\(\\alpha\)=\\mathrm\{softmax\}\\\{v\_\{j\}\(\\alpha\)\\\}\_\{i\}, target weightwiw\_\{i\}, and target GEO scoregT​\(α\)=∑i∈Twi​ci​\(α\)g\_\{T\}\(\\alpha\)=\\sum\_\{i\\in T\}w\_\{i\}c\_\{i\}\(\\alpha\)\.

### F\.1Proof of Lemma[1](https://arxiv.org/html/2608.11390#Thmlemma1)

###### Proof\.

Letci\(0\)=softmax​\{βq​qj\+bj\}ic\_\{i\}^\{\(0\)\}=\\mathrm\{softmax\}\\\{\\beta\_\{q\}q\_\{j\}\+b\_\{j\}\\\}\_\{i\}andm¯\(0\)=∑jcj\(0\)​mj\\bar\{m\}^\{\(0\)\}=\\sum\_\{j\}c\_\{j\}^\{\(0\)\}m\_\{j\}\. We use a local Taylor expansion ofgT​\(α\)g\_\{T\}\(\\alpha\)aroundα=0\\alpha=0\. The coefficients in Eq\. \([1](https://arxiv.org/html/2608.11390#Thmlemma1)\) are

B=𝔼⁡\[∑i∈Twi​ci\(0\)​\(mi−m¯\(0\)\)\],B=\\mathbb\{E\}\\\!\\left\[\\sum\_\{i\\in T\}w\_\{i\}c\_\{i\}^\{\(0\)\}\(m\_\{i\}\-\\bar\{m\}^\{\(0\)\}\)\\right\],and

Q=𝔼⁡\[∑i∈Twi​ci\(0\)​\(\(mi−m¯\(0\)\)2−Varc\(0\)​\(m\)\)\]\.Q=\\mathbb\{E\}\\\!\\left\[\\sum\_\{i\\in T\}w\_\{i\}c\_\{i\}^\{\(0\)\}\\left\(\(m\_\{i\}\-\\bar\{m\}^\{\(0\)\}\)^\{2\}\-\\mathrm\{Var\}\_\{c^\{\(0\)\}\}\(m\)\\right\)\\right\]\.To derive them, differentiatelog⁡ci=vi−log⁡Z\\log c\_\{i\}=v\_\{i\}\-\\log Z:

∂αlog⁡ci=−\(mi−∑jcj​mj\)\.\\partial\_\{\\alpha\}\\log c\_\{i\}=\-\(m\_\{i\}\-\\sum\_\{j\}c\_\{j\}m\_\{j\}\)\.Therefore,

∂αci\|0=−ci\(0\)​\(mi−m¯\(0\)\)\.\\partial\_\{\\alpha\}c\_\{i\}\\big\|\_\{0\}=\-c\_\{i\}^\{\(0\)\}\(m\_\{i\}\-\\bar\{m\}^\{\(0\)\}\)\.A second differentiation uses∂αm¯\|0=−Varc\(0\)​\(m\)\\partial\_\{\\alpha\}\\bar\{m\}\\big\|\_\{0\}=\-\\mathrm\{Var\}\_\{c^\{\(0\)\}\}\(m\)and gives

∂α2ci\|0=ci\(0\)​\(\(mi−m¯\(0\)\)2−Varc\(0\)​\(m\)\)\.\\partial^\{2\}\_\{\\alpha\}c\_\{i\}\\big\|\_\{0\}=c\_\{i\}^\{\(0\)\}\\left\(\(m\_\{i\}\-\\bar\{m\}^\{\(0\)\}\)^\{2\}\-\\mathrm\{Var\}\_\{c^\{\(0\)\}\}\(m\)\\right\)\.Taking theww\-weighted target sum and then expectation yields Eq\. \([1](https://arxiv.org/html/2608.11390#Thmlemma1)\)\. The remainder is local inα\\alphaunder the standard smoothness conditions of the softmax source model\. ∎

### F\.2Proof of Theorem[1](https://arxiv.org/html/2608.11390#Thmtheorem1)

###### Proof\.

Maximizing platform utility is equivalent to minimizing the local loss

L⁡\(α\)=gT​\(α\)\+μ​α​βq​cov​\(q,m\)\+γ2​α2,L\(\\alpha\)=g\_\{T\}\(\\alpha\)\+\\mu\\alpha\\beta\_\{q\}\\mathrm\{cov\}\(q,m\)\+\\frac\{\\gamma\}\{2\}\\alpha^\{2\},where the second term is the leading false\-positive cost from Sec\.[3\.2](https://arxiv.org/html/2608.11390#S3.SS2)\. Substituting Lem\.[1](https://arxiv.org/html/2608.11390#Thmlemma1)and usingcov⁡\(q,m\)=ρ​σq​σm\\mathrm\{cov\}\(q,m\)=\\rho\\sigma\_\{q\}\\sigma\_\{m\}gives

L⁡\(α\)=gT​\(0\)\+α⁡\(−B\+μ​βq​ρ​σq​σm\)\+12​α2​\(Q\+γ\)\+O⁡\(α3\)\.L\(\\alpha\)=g\_\{T\}\(0\)\+\\alpha\(\-B\+\\mu\\beta\_\{q\}\\rho\\sigma\_\{q\}\\sigma\_\{m\}\)\+\\frac\{1\}\{2\}\\alpha^\{2\}\(Q\+\\gamma\)\+O\(\\alpha^\{3\}\)\.Ignoring higher\-order terms in the local regime, the first\-order condition yields

\(Q\+γ\)​α=B−μ​βq​ρ​σq​σm\.\(Q\+\\gamma\)\\alpha=B\-\\mu\\beta\_\{q\}\\rho\\sigma\_\{q\}\\sigma\_\{m\}\.Projecting onto the feasible setα≥0\\alpha\\geq 0gives Eq\. \([4](https://arxiv.org/html/2608.11390#S3.E4)\)\. The phase threshold and monotonicity inρ\\rhofollow directly from the numerator\. ∎

### F\.3Proof of Theorem[2](https://arxiv.org/html/2608.11390#Thmproposition2)

###### Proof\.

Embed the true rewrite rulertr\_\{t\}and the platform estimater^t\\hat\{r\}\_\{t\}as unit vectors in a shared manipulation\-rule basis\. Since the platform appliesr^t\\hat\{r\}\_\{t\}while the supplier moves alongrtr\_\{t\}, the effective directional alignment is

⟨rt,r^t⟩=1−12​‖rt−r^t‖22=1−et\.\\langle r\_\{t\},\\hat\{r\}\_\{t\}\\rangle=1\-\\frac\{1\}\{2\}\\\|r\_\{t\}\-\\hat\{r\}\_\{t\}\\\|\_\{2\}^\{2\}=1\-e\_\{t\}\.LetBtB\_\{t\}denote the first\-order sensitivity of the target GEO score to a unit defense applied in the true manipulation direction at roundtt\. By the same local expansion as Lem\.[1](https://arxiv.org/html/2608.11390#Thmlemma1), applying a defense of strengthαt\\alpha\_\{t\}along the inferred direction gives

gT​\(Dta,πP,t−1\)−gT​\(Dta,πP,t\)=αt​\(1−et\)​Bt\+O⁡\(αt2\)\.g\_\{T\}\(D\_\{t\}^\{a\};\\pi\_\{P,t\-1\}\)\-g\_\{T\}\(D\_\{t\}^\{a\};\\pi\_\{P,t\}\)=\\alpha\_\{t\}\(1\-e\_\{t\}\)B\_\{t\}\+O\(\\alpha\_\{t\}^\{2\}\)\.The realized sensitivityBtB\_\{t\}scales with the average manipulation magnitude of the target documents\. Writingst=𝔼⁡\[mi∣i∈Tt\]s\_\{t\}=\\mathbb\{E\}\[m\_\{i\}\\mid i\\in T\_\{t\}\], we absorb the remaining local source\-model moments into a nonnegative constantccand writeBt=c​stB\_\{t\}=cs\_\{t\}to leading order\. This yields

gT​\(Dta,πP,t−1\)−gT​\(Dta,πP,t\)=c⁡\(1−et\)​st​αt\+O⁡\(αt2\)\.g\_\{T\}\(D\_\{t\}^\{a\};\\pi\_\{P,t\-1\}\)\-g\_\{T\}\(D\_\{t\}^\{a\};\\pi\_\{P,t\}\)=c\(1\-e\_\{t\}\)s\_\{t\}\\alpha\_\{t\}\+O\(\\alpha\_\{t\}^\{2\}\)\.Dropping higher\-order terms gives Eq\. \([6](https://arxiv.org/html/2608.11390#S3.E6)\)\. ∎

### F\.4Proof of Theorem[2](https://arxiv.org/html/2608.11390#Thmtheorem2)

###### Proof\.

The mechanism augments the source model with source\-supported content:

vi​\(α,λ\)=βq​qi−α​mi\+λ​ni\+bi\.v\_\{i\}\(\\alpha,\\lambda\)=\\beta\_\{q\}q\_\{i\}\-\\alpha m\_\{i\}\+\\lambda n\_\{i\}\+b\_\{i\}\.Write the platform’s quadratic local loss asLP​\(α,λ\)L\_\{P\}\(\\alpha,\\lambda\)\. Orthogonality ofnnandmmremoves the mixed first\-order response of the manipulation penalty to the reward, so∂2LP/\(∂α​∂λ\)\|\(α∗,0\)=0\\partial^\{2\}L\_\{P\}/\(\\partial\\alpha\\partial\\lambda\)\|\_\{\(\\alpha^\{\\ast\},0\)\}=0\. Since∂2LP/∂α2=Q\+γ\>0\\partial^\{2\}L\_\{P\}/\\partial\\alpha^\{2\}=Q\+\\gamma\>0, the implicit\-function theorem gives

α∗​\(λ\)=α∗​\(0\)\+O⁡\(λ2\)\.\\alpha^\{\\ast\}\(\\lambda\)=\\alpha^\{\\ast\}\(0\)\+O\(\\lambda^\{2\}\)\.Thus the platform response does not offset the reward at first order\.

Now letδ=\(δq,δm,δn\)\\delta=\(\\delta\_\{q\},\\delta\_\{m\},\\delta\_\{n\}\)and definea⁡\(α,λ\)=\(βq,−α,λ\)⊤a\(\\alpha,\\lambda\)=\(\\beta\_\{q\},\-\\alpha,\\lambda\)^\{\\top\}\. The supplier’s local objective is the strictly concave quadratic

JA​\(δ,α,λ\)=a​\(α,λ\)⊤​δ−12​δ⊤​H​δ,H≻0\.J\_\{A\}\(\\delta;\\alpha,\\lambda\)=a\(\\alpha,\\lambda\)^\{\\top\}\\delta\-\\tfrac\{1\}\{2\}\\delta^\{\\top\}H\\delta,\\qquad H\\succ 0\.Its first\-order condition is necessary and sufficient, hence the unique best response is

δ∗​\(λ\)=H−1​a​\(α∗​\(λ\),λ\)\.\\delta^\{\\ast\}\(\\lambda\)=H^\{\-1\}a\(\\alpha^\{\\ast\}\(\\lambda\),\\lambda\)\.Because thenncoordinate is block\-separable from\(q,m\)\(q,m\),

δn∗​\(λ\)=λ​\(H−1\)n​n,\(δq∗,δm∗\)​\(λ\)=\(δq∗,δm∗\)​\(0\)\+O⁡\(λ2\)\.\\delta\_\{n\}^\{\\ast\}\(\\lambda\)=\\lambda\(H^\{\-1\}\)\_\{nn\},\\qquad\(\\delta\_\{q\}^\{\\ast\},\\delta\_\{m\}^\{\\ast\}\)\(\\lambda\)=\(\\delta\_\{q\}^\{\\ast\},\\delta\_\{m\}^\{\\ast\}\)\(0\)\+O\(\\lambda^\{2\}\)\.LetΘ=\(H−1\)n​n\>0\\Theta=\(H^\{\-1\}\)\_\{nn\}\>0\. Extending the platform/user utility decomposition by the termηn​δn\\eta\_\{n\}\\delta\_\{n\}therefore yields

Δ​U∗​\(λ\)=Δ​U∗​\(0\)\+ηn​λ​Θ\+O⁡\(λ2\)\.\\Delta U^\{\\ast\}\(\\lambda\)=\\Delta U^\{\\ast\}\(0\)\+\\eta\_\{n\}\\lambda\\Theta\+O\(\\lambda^\{2\}\)\.The linear coefficient is strictly positive, so the platform/user side strictly improves for all sufficiently smallλ\>0\\lambda\>0\.

Finally, substituting the supplier best response into its objective givesJA∗​\(λ\)=12​a⊤​H−1​aJ\_\{A\}^\{\\ast\}\(\\lambda\)=\\frac\{1\}\{2\}a^\{\\top\}H^\{\-1\}a\. Block separability and theO⁡\(λ2\)O\(\\lambda^\{2\}\)change inα∗\\alpha^\{\\ast\}imply

JA∗​\(λ\)−JA∗​\(0\)=O⁡\(λ2\)\.J\_\{A\}^\{\\ast\}\(\\lambda\)\-J\_\{A\}^\{\\ast\}\(0\)=O\(\\lambda^\{2\}\)\.Thus creator utility is preserved to first order while platform/user utility increases at first order\. This establishes the stated local two\-sided result; it makes no claim about the sign of the creator’s second\-order change or about a global equilibrium outside the quadratic neighborhood\. ∎

## Appendix GPrompt Templates

This appendix lists the LLM prompts used by the supplier and the platform\. Variables in braces, such as\{q\}and\{d\_i\}, are substituted at call time\. Unless otherwise specified, prompts use temperature00and JSON\-only output when a JSON schema is requested\.

### G\.1Supplier Prompts

Query:\{q\}

Generatedanswer:

\{a\}

DocumentA\(citedmore\):

\{d\_i\}

DocumentB\(citedless\):

\{d\_j\}

IdentifyconcretepropertiesofDocumentAthatmakeitmorevisible

tothegenerativeenginethanDocumentB\.Returnabulletlistof

candidateexplanationsandcitespecificevidencefromDocumentA

wheneverpossible\.

Listing 1:Supplier Explainer prompt\.Explanation:

\{expl\}

Extractaconciselistofactionablerewritingrulesthatacontent

suppliercouldapplytoanotherdocumenttoimproveitscitation

frequencyonthisengine\.Eachruleshouldbeasingleimperative

sentenceandshouldgeneralizeacrossqueries\.

Listing 2:Supplier Extractor prompt\.Candidaterules:

\{rules\}

Consolidatethecandidaterulesintoacompactlistofgeneral

rewritingrules\.Removeduplicatesandoverlyspecificclauses\.Keep

onlyrulesthatgeneralizeacrossdocumentsandqueries\.

Listing 3:Supplier Merger prompt\.Candidaterules:

\{rules\}

Retainonlyrulesthatdescribeverifiablepreferencesofa

generativeengine,suchasstructure,comparativeframing,orexplicit

answerability\.Dropgenericwriting\-qualityadvicethatdoesnot

specificallyraisecitationprobability\.

Listing 4:Supplier Filter prompt\.Rules:

\{S\_A\}

Originaldocument:

\{d\_i\}

Rewritethedocumentsothatitfollowsallrulesabovewhile

preservingfactualcontent\.Returnonlytherewrittendocument\.

Listing 5:Supplier rewrite prompt\.
### G\.2Platform Defense Prompts

Originaldocument:

\{d\_i\}

Rewrittendocument:

\{d\_i^a\}

Therewrittenversionmayhavebeenmodifiedtoattractcitationsin

agenerativeenginewithoutchangingfactualcontent\.Identify

concretepropertiesthatdistinguishtherewrittenversionfromthe

original,suchasstructuralchanges,formattingcues,comparative

framing,orkeyworddensity\.Returnabulletlistofcandidate

patterns\.

Listing 6:Platform Explainer prompt\.Explanation:

\{expl\}

Extractsuspicionrulesfromtheexplanationabove\.Eachruleshould

describeafeatureindicatingthatadocumentmayhavebeen

GEO\-optimized\.Eachruleshouldgeneralizeacrossqueries\.

Listing 7:Platform Extractor prompt\.Candidatesuspicionrules:

\{rules\}

Consolidatetherulesintoacompactlistofgeneralsuspicion

patterns\.Removeduplicatesandoverlyspecificclauses\.

Listing 8:Platform Merger prompt\.Candidaterules:

\{rules\}

RetainonlyGEO\-specificpatterns,suchasaggressivestructure,

explicitanswer\-prioritycues,andkeywordstuffing\.Dropgeneric

evidence\-qualityclausessuchas"berelevant"or"befactually

correct"\.

Listing 9:Platform Filter prompt\.SomeretrievedpagesmaybeGEO\-optimizedtoattractcitationsthrough

formattingorpackagingratherthansubstance\.Treatthefollowing

patternsassuspiciousunlesstheunderlyingevidencedirectlyanswers

thequery\.

Suspiciouspatterns:

\{rules\}

Per\-documentsuspicionlabels:

\{labels\}

Guidelines:

\-Preferlow\-suspiciondocumentswhentheyprovidesufficientevidence\.

\-Citeahigh\-suspiciondocumentonlyifitprovidesuniquelynecessary

evidencethatlower\-suspiciondocumentsdonotprovide\.

\-Donotmentionthesesuspicionlabelsinyouranswer\.

Listing 10:Answer\-time defense warning\.
### G\.3Pair\-Level Oracles

The following pair\-level oracles are used by the platform\. The change\-magnitude judge gates whether a pair contributes to the inferred rule set\. The verifiable\-content oracle computes the reward signalnin\_\{i\}\. The quality judge is used for deterministic target\-document selection\.

SYSTEM:

Youareasearch\-qualitychangejudge\.Compareanolderpageanda

newerpage\.Estimateonlythemagnitudeoftheupdate,notwhetherthe

newerpageisbetter\.ReturnJSONonly\.

USER:

Query:\{q\}

Scoretheupdatemagnitudeona0\-\-1scale:

0=trivialeditsorlocalwordingchanges\.

1=substantialrewriting,restructuring,orrepackaging\.

Returnexactly:

\{

"change\_magnitude":0\.0,

"reason":"shortexplanation"

\}

Olderpage:

\{d\_i\}

Newerpage:

\{d\_i^a\}

Listing 11:Change\-magnitude judge\. Returns a score in 0 to 1\.SYSTEM:

Youareacarefulfact\-checkercomparingtwoversionsofadocument\.

Counttwothings:\(i\)claimsintherewrittenversionthatarenot

supportedbytheoriginal,and\(ii\)newfactualcontentinthe

rewrittenversionthatissupportedbytheoriginalandaddsgenuine

informationalvalue\.ReturnJSONonly\.

USER:

Query:\{q\}

Originaldocument:

\{d\_i\}

Rewrittendocument:

\{d\_i^a\}

Identifyspecificfactualclaimsintherewrittendocument\.

Definitions:

\-unsupported\_claims:numberofconcretedetails,suchasnumbers,

names,prices,citations,orspecifications,thatappearinthe

rewrittendocumentbutcannotbeverifiedfromtheoriginal\.

\-verifiable\_new\_content:numberoffactsthataresupportedbythe

originalandmaketherewrittendocumenteasiertoextractfrom,for

examplebypromotingburiedprices,specifications,orcitationsinto

salientform\.

\-severity:severityofunsupportedclaims,from1to5\.

ReturnJSON:

\{

"unsupported\_claims":<int\>,

"verifiable\_new\_content":<int\>,

"severity":<int1\-5\>

\}

Listing 12:Verifiable\-content oracle\. Returns an integer reward signal\.SYSTEM:

Youareasearch\-qualityjudge\.Scoreeachcandidatedocumentforhow

usefulandtrustworthyitisforansweringthequery\.ReturnJSONonly\.

USER:

Query:\{q\}

Foreachdocument,assignscoresfrom0to1forquality,

credibility,query\_relevance,andoverall\.Useoverallasabalanced

summary\.Alsoincludeashortreason\.

Returnexactly:

\{

"documents":\[

\{

"doc\_id":0,

"quality":0\.0,

"credibility":0\.0,

"query\_relevance":0\.0,

"overall":0\.0,

"reason":"shortexplanation"

\}

\]

\}

Documents:

\[0\]\{d\_0\}

\[1\]\{d\_1\}

\.\.\.

Listing 13:Quality judge for target\-document selection\.

Similar Articles

Generative Optimization for Incentivized Advertising with Global Level Constraints

arXiv cs.LG

This paper proposes GOAL, a constraint-aware generative framework for incentivized advertising that formulates incentive allocation as conditional sequence generation, and introduces SCPO to learn a single generative policy that generalizes across ROI constraints. Experiments show improved long-term revenue and user retention with reduced ROI violations.

Self-Evolving Deep Research via Joint Generation and Evaluation

arXiv cs.CL

Researchers from HKUST, ByteDance, and UCL propose SCORE, a co-evolutionary training framework that jointly trains an LLM as both a deep research report generator and an evaluator, using a meta-harness to dynamically adjust evaluation difficulty and prevent reward saturation. Experiments show consistent improvement in open-ended research report quality.

Don't Gamble, GAMBLe: An Analytical Framework for AI-Driven Research Systems

arXiv cs.AI

The paper introduces GAMBLe, a framework that decomposes AI-Driven Research Systems into generator, assessor, discovery mechanism, and budget, revealing how component interactions shape optimization landscapes. Experiments on NP-hard problems show no universally best configuration, emphasizing the need for careful component selection.