AI Optimization Terminology

Generative Engine Optimization now names both a service and an attack.

A 2023 paper introduced Generative Engine Optimization as help for content creators. A 2026 defense paper tests that same method as an attack, and its word 'malicious' describes an intent its own detector never reads.

· 7 minute read

On September 2, 2026, a defense paper on arXiv listed the original Generative Engine Optimization method, under the name GEO, as one of seven attacks for its reranker to demote. The documents that method produces are not false and not badly written. What separates them from benign content, in that paper's design, is only the fact that they were rewritten.

The GEO Defender paper tests the original 2023 GEO method as an attack

The paper "When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization" (arXiv:2609.02964v1, submitted September 2, 2026) is by Haozhang Li and five coauthors. It describes malicious Generative Engine Optimization as rewriting "web documents to match engines' citation preferences" and thereby manipulating generated answers. It defines a GEO attack as "the malicious application of a GEO method to a web document, with the goal of increasing its likelihood of selection and citation by LLMs and influencing the generated answer."

The paper evaluates its defense, GEO Defender, against "seven GEO attacks." One is labeled GEO and cited to Aggarwal et al. (2024). It is one of four methods excluded from the construction of the defense and evaluated as unseen; three later methods, AgenticGEO, AutoGEO and MAGEO, were used to build it. Table 1 of the paper reports that GEO Defender cut the average attack success rate from 50.32% to 6.20% and retained 94.12% of benign evidence use.

Two statements in the abstract show what the paper is detecting. The attack documents "remain factually consistent with their originals," which is why fact verification and perplexity filtering fail against them, and "the features they amplify equally characterize high-quality benign content." The defense is not looking for falsehood or low quality. It is looking for a document rewritten toward what the engine prefers to cite.

The paper is a single preprint and does not settle usage for a field. It does establish, with a date, that the method Generative Engine Optimization was coined for is in print as an attack.

The 2023 GEO paper introduced the rewrite as help for content creators

Generative Engine Optimization entered the research record in "GEO: Generative Engine Optimization" by Pranjal Aggarwal and five coauthors (arXiv:2311.09735, v1 November 16, 2023; v3 June 28, 2024). The abstract presents GEO as help for the weaker party in generative search: "the first novel paradigm to aid content creators in improving their content visibility in generative engine responses." Its motivation is that creators "have little to no control over when and how their content is displayed," and it reports that GEO "can boost visibility by up to 40%".

The 2023 paper tested keyword stuffing alongside quotation addition, statistics addition and source citation, and in its Table 1 keyword stuffing trailed all three. The authors wrote that such methods, "while widely used for Search Engine Optimization," offer "little to no improvement" in generative engine responses. The methods the paper found effective were additions of substance.

The 2026 paper summarizes that method as rewriting a document, "for instance by adding citations and statistics," and evaluates it as an attack. In both papers the act is identical: rewrite a document so a generative engine is more likely to select and cite it. The 2023 paper scores that act as visibility gained. The 2026 paper scores it as attack success rate.

GEO Defender's 94.12% retention figure does not cover a truthful rewrite

The 94.12% figure in GEO Defender's Table 1 can read as proof that the defense separates attack documents from good content. The paper defines the metric more narrowly: benign evidence retention is "the aggregate use of benign documents relative to the clean-reference answer," where each clean reference answer comes from the undefended pipeline run on the clean candidate set. It measures how much untouched content survives.

Shield Reranker, the first stage of GEO Defender, is trained on construction instances that each contain "an original benign document d+, its GEO-rewritten attack variant da, and another query-relevant benign document db." The learned preference ranks both benign documents above the rewrite. At inference the reranker scores document content, not labels, so whether it demotes a careful rewrite made outside the benchmark is an empirical question. The paper does not test that case, and this entry does not claim the answer.

What the training design does fix is the lesson on offer. Every example the reranker learns from pairs an original with a rewrite, and in every pair the rewrite is the one to rank lower. A rewrite that a practitioner would call an improvement is not represented as a separate class anywhere in that data.

The strongest objection: the paper already qualifies GEO, and SEO lived with qualifiers

The strongest case against this thesis comes from the paper itself. Its title says "Malicious Generative Engine Optimization," so the attack side already carries a qualifier. Security writing about search did the same for decades with forms such as "SEO poisoning" and "black-hat SEO," and SEO survived as the name of a legitimate trade. On that view "white-hat GEO" and "malicious GEO" are an ordinary pair.

The objection is right that a qualifier can split a term, and right that one preprint does not decide what security researchers will call this attack.

It fails on where the qualifier sits. The paper's definition puts "malicious" on the application of a GEO method, not on the method, and one of the methods is the 2023 one, cited to its authors. The abstract then counts "seven GEO attacks" and the paper's method by method analysis names one of them plain GEO. Qualifiers about intent reconcile two meanings only where the enforcing system reads intent. Google's spam policies are written in terms of purpose: they describe scaled content abuse as pages generated "for the primary purpose of manipulating search rankings and not helping users" (Google Search Central, "Spam policies for Google web search," last updated August 28, 2026, accessed September 24, 2026). GEO Defender has no input for purpose. It scores a document.

The qualifier sits on the application. The detector scores the document. "Malicious" and "white-hat" are both claims about the author, and neither reaches a system of this design. Google's page now extends its policies to "attempting to manipulate generative AI responses in Google Search," so an intent based definition does exist in one engine's written policy. Whether research defenses adopt one is not settled.

Describing the edit changes the report, the invoice and the dispute, not the detector

Optimization work for AI answers is described durably by naming what it changed in the document. The 2023 paper's own method names show the difference: "added three statistics, each with its source" can be checked against the page, while "did GEO" cannot, and a reader from the defense literature can read the second as an attack.

Three documents change when the edit is named. A vendor report lists each edit with the text before and after, not a GEO score. A client invoice itemizes edits, so the client knows what was bought and can judge it. A site owner questioning a demotion with an engine operator can point to a specific addition of information rather than defend an acronym the operator may model as a threat.

Each of those records answers one question that a label cannot: did this edit add information, or only reshape existing information toward what gets cited? That question has an answer for a specific edit. It has no answer for "GEO", and no replacement acronym defined by optimizing for an engine will have one either.

A classifier trained on original and rewritten pairs demotes what it demotes whatever the work is called. Describing the edit does not change detection, and it should not be presented as if it did.

The qualifier sits on the application. The detector scores the document.

This entry does not cover whether production generative engines demote rewritten documents, which neither paper measures, or whether "GEO attack" becomes the standard name in security research. Both were open as of September 24, 2026.

Further reading

  1. Li et al., arXiv preprint defining malicious GEO as an attack and proposing the GEO Defender defense arxiv.org/abs/2609.02964
  2. Aggarwal et al., the 2023 paper that introduced Generative Engine Optimization as an aid to content creators arxiv.org/abs/2311.09735
  3. Google Search Central, spam policies defining manipulation by intent and extending it to generative AI responses developers.google.com/search/docs/essentials/spam-policies

Every source above was fetched and a verbatim phrase confirmed on the page before this essay published. Nothing here is paraphrased from memory.