June 2026Unreviewed
How Much Can We Trust LLM Search Agents? Measuring Endorsement Vulnerability to Web Content Manipulation
Yimeng Chen, Zhe Ren, Firas Laakom, Yu Li, Dandan Guo, Jürgen Schmidhuber
Abstract
Large language model (LLM)-based search agents synthesize open-web content into actionable recommendations on behalf of users, creating a risk that attacker-published pages are transformed into endorsed claims. We introduce SearchGEO, a controlled evaluation framework for measuring endorsement corruption in LLM-based web-search agents, combining a web-evidence manipulation pipeline, a five-mode attack taxonomy, and multiple output-level metrics. We evaluate 13 LLM backends on 308 cases each. Res
Categories
Cite
@misc{chen2026howb,
title = {{How Much Can We Trust LLM Search Agents? Measuring Endorsement Vulnerability to Web Content Manipulation}},
author = {Yimeng Chen and Zhe Ren and Firas Laakom and Yu Li and Dandan Guo and Jürgen Schmidhuber},
year = {2026},
month = jun,
eprint = {2606.16821},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.16821}
}