Search papers, labs, and topics across Lattice.
This study investigates the vulnerability of generative search engines (GSEs) to poisoning attacks in the political domain by analyzing citation selection and personalization factors. A novel metric, the content-injection barrier, is introduced to quantify the ease of injecting misleading content based on publisher authority, revealing significant differences in attack surfaces across various GSE models. Key findings indicate that ruling parties present a broader attack surface compared to opposition parties, while user profiles have minimal impact on citation behavior.
Ruling parties are more susceptible to poisoning attacks in generative search engines, highlighting critical vulnerabilities in information access.
We characterize the attack surface of generative search engines (GSEs) against poisoning attacks in the political domain, from the perspectives of citation selection and personalization. GSEs integrate web search and answer generation with user preferences and backgrounds using large language models (LLMs). They play a crucial role in how users access information on the web. Because anyone can publish content on the web, GSEs are vulnerable to poisoning attacks that manipulate citations to undermine reliable information delivery. Existing studies on citation evaluation focus on how faithfully answers reflect cited content. However, they leave unexamined the two critical aspects to capture the attack surface of GSEs against poisoning attacks: which publishers GSEs prefer to cite, and how personalization affects citation behavior. To fill this gap, we introduce an evaluation framework that characterizes the attack surface of GSEs against poisoning attacks. Our contributions are twofold: (1) we propose a novel metric, \emph{content-injection barrier}, which quantifies the difficulty of injecting arbitrary content onto the web with a given level of publisher authority; and (2) we reveal how personalization affects citation behavior by embedding user profiles into GSEs. We conduct experiments on three major GSEs in the political domain of the United States and Japan. Our results show that (a) the attack surface differs across GSE models; (b) the web search functionality of GSEs shapes the attack surface; (c) ruling parties have a broader attack surface than opposition parties; and (d) user profiles have little influence on the attack surface.