Skip to content
Search
paperJune 2026Unreviewed

How Much Can We Trust LLM Search Agents? Measuring Endorsement Vulnerability to Web Content Manipulation

Yimeng Chen, Zhe Ren, Firas Laakom, Yu Li, Dandan Guo, Jürgen Schmidhuber

Abstract

Large language model (LLM)-based search agents synthesize open-web content into actionable recommendations on behalf of users, creating a risk that attacker-published pages are transformed into endorsed claims. We introduce SearchGEO, a controlled evaluation framework for measuring endorsement corruption in LLM-based web-search agents, combining a web-evidence manipulation pipeline, a five-mode attack taxonomy, and multiple output-level metrics. We evaluate 13 LLM backends on 308 cases each. Res

Categories

Cite

@misc{chen2026howb,
  title = {{How Much Can We Trust LLM Search Agents? Measuring Endorsement Vulnerability to Web Content Manipulation}},
  author = {Yimeng Chen and Zhe Ren and Firas Laakom and Yu Li and Dandan Guo and Jürgen Schmidhuber},
  year = {2026},
  month = jun,
  eprint = {2606.16821},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.16821}
}