← Latest papers
🤖 AI

GPE: Evaluating Robust Evidence Aggregation for Fact Verification under Controllable GEO-Style Poisoning

This paper introduces GPE, a multi-domain benchmark and evaluation framework designed to assess the robustness of fact-verification systems against Generative Engine Optimization (GEO) poisoning by controlling evidence sources and attack ratios, revealing critical vulnerabilities and trade-offs not detectable in clean environments.

Original authors: Zhaoqi Wang, Zijian Zhang, Xiaomei Yuan, Pengtao Kou, Jiamou Liu, Zhen Li, Liehuang Zhu

Published 2026-07-24
📖 4 min read☕ Coffee break read

Original authors: Zhaoqi Wang, Zijian Zhang, Xiaomei Yuan, Pengtao Kou, Jiamou Liu, Zhen Li, Liehuang Zhu

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a massive, bustling library where the books are constantly being rewritten by a chaotic crowd. In this library, Artificial Intelligence (AI) acts like a super-smart librarian who doesn't just memorize facts but goes out to fetch the latest books to answer your questions. This is how modern AI works: it uses "retrieval-augmented generation," meaning it searches the web for fresh information to back up its answers. But here's the catch: what if someone sneaks into the library and swaps the real books for fake ones that look and sound exactly like the real thing? This is the danger of "GEO poisoning." Just as a bad actor might try to trick a search engine into showing their fake news first, they can flood the library with convincing lies designed specifically to fool the AI librarian. The big question for scientists is: if the library is full of these clever forgeries, can the AI still tell the truth, or will it get tricked into believing the fake books are real?

This is exactly the problem tackled by a new study called GPE (Generative Engine Optimization Poisoning Evaluation). The researchers built a special "training gym" for fact-checking AI, designed to test how well these digital librarians can spot lies when the evidence they find is contaminated. Instead of just asking, "Can the AI find the right answer?" they asked, "Can the AI find the right answer when 33%, 67%, or even 100% of the evidence it finds has been secretly poisoned?" They created a massive dataset covering six different worlds: politics, celebrity gossip, science, medicine, history, and everyday life. For every claim, they gathered real evidence and then injected different types of "poison"—some were fluent fake articles, some were real news articles with key facts swapped out, and some were even instructions telling the AI to ignore the truth.

The results were a bit of a wake-up call. The study found that even the smartest AI models struggle significantly when the evidence is poisoned. In a clean environment with no lies, the best models got the answer right about 52% to 53% of the time. But as soon as the evidence was polluted, their performance dropped sharply. For instance, when the evidence was completely replaced with fake content, some models' accuracy plummeted to single digits. The researchers discovered that no single method was a superhero; a model that was good at spotting one type of fake news often failed miserably against another. They also found that trying to be more careful often cost the AI more "brain power" (in the form of computer tokens), making it slower and more expensive without necessarily making it safer.

One of the most interesting findings was about the type of poison. The study showed that "Adaptive Tampering Attacks" (ATA)—where bad actors take a real, trustworthy-looking article and just change a few numbers or names—were the most dangerous. These were harder for the AI to detect than obvious, made-up fake news because they looked so much like the real thing. The researchers also built a "knowledge graph," which is like a giant map connecting all the people, places, and documents in their dataset. This map helps researchers see how a single piece of poisoned evidence can spread and trick the AI about multiple different claims.

Ultimately, the paper suggests that we cannot rely on current AI fact-checking methods to be robust against these attacks. The study proves that an AI might look confident and smart when the evidence is clean, but that confidence can vanish the moment the evidence is manipulated. The authors conclude that we need new ways to evaluate these systems, not just on how well they work in a perfect world, but on how they survive in a messy, adversarial one where the truth is hidden behind a wall of convincing lies.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →