A Lower Attack Rate Is Not Enough: Counter-GEO-Bench Tests Generative-Search Defenses Against Factual Distortion
TL;DR for operators A retrieved document does not need to look malicious to corrupt a generative-search answer. In Counter-GEO-Bench, carefully constructed documents remain fluent and topically relevant while inserting a targeted false claim; in the undefended pipeline, 55.7% of these attacks move the generated answer toward that claim across three tested models.1 ...