SMNS event
Can We Trust GenAI Recommendations? Unpacking Adversarial Vulnerabilities in LLM/VLM Ranking Systems
Large Language Models (LLMs) and Vision-Language Models (VLMs) are fundamentally reshaping information retrieval, transitioning us from traditional keyword matching to "Generative Search" engines that directly recommend and rank content. While these systems offer superior user experiences, they introduce a critical and largely unexplored attack surface: Adversarial Ranking Manipulation. In this talk, I will present a comprehensive analysis of vulnerabilities in modern generative rankers, ranging from atomic attacks to ecosystem-level dynamics. First, we introduce StealthRank and RAF, frameworks that utilize energy-based and gradient-guided optimization to craft fluent text triggers that covertly highjack LLM rankings. Second, we extend this to Vision-Language Models with MGEO, demonstrating how cross-modal perturbations can drastically alter search results. Finally, we model the search ecosystem as a game-theoretic dilemma, revealing a "Paradox of Defense" where standard countermeasures may inadvertently incentivize an arms race between attackers and search engines.