NOTAS DE CAMPO / LDM ZARAGOZA / CALATAYUD · 2026
RESEARCH IA/PAPER 01

RAG · SEGURIDAD

SIREN — PAIR-Driven Preference Manipulation in Web-RAG Recommenders

ImprescindibleLectura primaria completa

SIREN estudia algo directamente relacionado con el futuro del SEO: ¿puede una web modificar su contenido para conseguir que un asistente con búsqueda la coloque como recomendación nº1?

AUTHORS / LABEvan Caville, Siamak Layeghy, Billy Sung, Sara Dolnicar, Marius Portmann
FECHA24 JULIO 2026.
LECTURALectura primaria completa
LECTURA DE 60 SEGUNDOS

Lo esencial antes de invertir más tiempo.

HALLAZGO

SIREN estudia algo directamente relacionado con el futuro del SEO: ¿puede una web modificar su contenido para conseguir que un asistente con búsqueda la coloque como recomendación nº1? Manteniendo exactamente las mismas fuentes recuperadas y modificando solamente una página, consigue alcanzar el primer puesto en 62 de 124 intentos; los ataques exitosos se reproducen en sesiones nuevas con una tasa media de 80,5%. Curiosamente, afirmaciones declarativas de ranking y listas sembradas funcionaron mejor que instrucciones explícitas tipo prompt injection.

EVIDENCIA DISPONIBLE

The full sweeps evaluate the complete taxonomy, whereas the reduced sweeps test whether techniques selected on Q1 and Q2 remain effective on new queries and entities.

Resultado reportado con fuente enlazada · 5 localizadores disponibles.
LÍMITE

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 9. Results.

SIGUIENTE PRUEBA

Comparar la métrica principal de la fuente junto con calidad, coste, latencia y tasa de errores.

EN UNA FRASE

SIREN estudia algo directamente relacionado con el futuro del SEO: ¿puede una web modificar su contenido para conseguir que un asistente con búsqueda la coloque como recomendación nº1? Manteniendo exactamente las mismas fuentes recuperadas y modificando solamente una página, consigue alcanzar el primer puesto en 62 de 124 intentos; los ataques exitosos se reproducen en sesiones nuevas con una tasa media de 80,5%. Curiosamente, afirmaciones declarativas de ranking y listas sembradas funcionaron mejor que instrucciones explícitas tipo prompt injection.

SEÑALbúsqueda generativa, GEO/LLMO, seguridad. · e-commerce · turismo
EVIDENCIAResultado reportado con fuente enlazada
CONFIANZA EDITORIALMedia
RESULTADOS / PROCEDENCIA

Qué está reportado y qué conviene comprobar.

Hay resultado reportado con fuente enlazada.
RESULTADO REPORTADO

The full sweeps evaluate the complete taxonomy, whereas the reduced sweeps test whether techniques selected on Q1 and Q2 remain effective on new queries and entities.

contexto: 9. Results

RESULTADO REPORTADO

Because the reduced set was selected using R1–R4, its higher rate should not be interpreted as a direct improvement over the full-sweep rate or as an unbiased estimate over all 23 techniques.

contexto: 9. Results

RESULTADO REPORTADO

ASR ranges from 0.26 to 0.78 in the four full sweeps and from 0.38 to 1.00 in the four reduced sweeps (Appendix A ).

contexto: 9. Results

RESULTADO REPORTADO

The two payloads that never return to rank 1 are both Sonnet cases in which a rival regains the top position.

contexto: 9. Results

LECTURA DEL PAPER / SÍNTESIS EDITORIAL

Qué estudiaron y qué cambia.

La síntesis está separada de los resultados reportados y de las inferencias.

PROBLEMA / La señal entra en el radar porque los asistentes web ya son sistemas de ranking, pero sus resultados pueden manipularse a través del contenido que leen. Por qué puede ser importante: es una de las señales más claras que he visto de que GEO/Generative Engine Optimization tendrá una dimensión adversarial similar al SEO, aunque con mecanismos diferentes.

MÉTODO / La lectura de 3. Threat Model describe la intervención y su construcción: A user asks an assistant with web access for the top L entities in a category, where L is the requested list length. The assistant searches the live web, fetches candidate pages, and synthesises a ranked list from the retrieved text. The target entity is a real business or service the adversary wishes to promote. The rivals are the other real entities the model would otherwise rank. The adversary can edit the content of one retrievable page that already mentions the target entity. This models a business editing its own site or a party controlling a listicle or review page in which the target appears. The… [Fuente: https://arxiv.org/html/2607.21951#S3]

RESULTADO / La sección 9. Results informa: The full sweeps evaluate the complete taxonomy, whereas the reduced sweeps test whether techniques selected on Q1 and Q2 remain effective on new queries and entities. Because the reduced set was selected using R1–R4, its higher rate should not be interpreted as a direct improvement over the full-sweep rate or as an unbiased estimate over all 23 techniques. ASR ranges from 0.26 to 0.78 in the four full sweeps and from 0.38 to 1.00 in the four reduced sweeps (Appendix A ). [Fuente: https://arxiv.org/html/2607.21951#S9]

LÍMITE / El cierre de la fuente señala: Constraint enforcement and rank measurement. The harness mechanically enforces the edit operation, transformation, and reconstruction of the source page. Some semantic eligibility rules are enforced through the attacker prompt rather than by the harness. The deterministic parser confirms 62 of the judge’s 63 rank-1 decisions and rejects one case in which a rival occupies the first position. Under a stricter rule that credits only the 58 responses that… La transferencia a auditoría GEO requiere repetir la comparación con datos y criterios propios [Fuente: https://arxiv.org/html/2607.21951#S10].

DECISIÓN RÁPIDAProbar la propuesta en auditoría GEO reproduciendo primero la comparación y registrando calidad, coste, latencia y errores.
NO LO SOBREINTERPRETES

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 9. Results.

PROBLEMA
Los asistentes web ya son sistemas de ranking, pero sus resultados pueden manipularse a través del contenido que leen. Por qué puede ser importante: es una de las señales más claras que he visto de que GEO/Generative Engine Optimization tendrá una dimensión adversarial similar al SEO, aunque con mecanismos diferentes.
MÉTODO
La lectura de 3. Threat Model describe la intervención y su construcción: A user asks an assistant with web access for the top L entities in a category, where L is the requested list length. The assistant searches the live web, fetches candidate pages, and synthesises a ranked list from the retrieved text. The target entity is a real business or service the adversary wishes to promote. The rivals are the other real entities the model would otherwise rank. The adversary can edit the content of one retrievable page that already mentions the target entity. This models a business editing its own site or a party controlling a listicle or review page in which the target appears. The…
TIPO DE EVIDENCIA
La sección 9. Results informa 4 hallazgo(s) extraído(s) desde la fuente. El resultado principal se conserva con el localizador de sección https://arxiv.org/html/2607.21951#S9.
LÍMITE
La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 9. Results.
FIELD NOTES / ANOTACIONES

La lectura también deja rastro.

Guarda una observación junto a la evidencia. Tú escribes aquí; los agentes pueden añadir notas por MCP y aparecerán identificados.

MEMORIA PRIVADAEntra para anotar este paper y conectarlo con otros.
Entrar con ChatGPT
LECTURA AMPLIADAMetodología, implicaciones y preguntas para volver al paper.+
LECTURA EN 90 SEGUNDOSLo que conviene llevarse antes de abrir el PDF.
QUÉ HACE

La lectura de 3. Threat Model describe la intervención y su construcción: A user asks an assistant with web access for the top L entities in a category, where L is the requested list length. The assistant searches the live web, fetches candidate pages, and synthesises a ranked list from the retrieved text. The target entity is a real business or service the adversary wishes to promote. The rivals are the other real entities the model would otherwise rank. The adversary can edit the content of one retrievable page that already mentions the target entity. This models a business editing its own site or a party controlling a listicle or review page in which the target appears. The…

QUÉ APORTA

La relevancia práctica todavía necesita contraste editorial.

QUÉ NO PRUEBA

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 9. Results.

Cómo lo llevaría a un proyecto

Probar la propuesta en auditoría GEO reproduciendo primero la comparación y registrando calidad, coste, latencia y errores.

auditoría GEOrobustez de buscadores generativosanálisis de reputaciónsistemas de recomendación.

Preguntas que conviene probar

  • ¿La mejora se mantiene cuando auditoría GEO cambia de dominio o distribución?
  • ¿Qué componente del método explica la mayor parte del resultado y qué baseline lo pone realmente a prueba?
PLANTILLA DE PRUEBA / INFERENCIA EDITORIAL

Si tuviera que convertirlo en una prueba mañana.

ENTRADAauditoría GEO con un conjunto pequeño de casos representativos y la misma métrica o protocolo que la fuente cuando sea reproducible.
PREGUNTA¿La propuesta mejora auditoría GEO frente a la línea base actual?
MÉTRICAComparar la métrica principal de la fuente junto con calidad, coste, latencia y tasa de errores.
PARADAParar si no aparece una mejora reproducible o si aumenta el riesgo, la complejidad o el coste sin compensación.

Mi lectura

La pregunta operativa es si auditoría GEO puede medirse con una línea base y un criterio de parada claros.

Esta última frase es una inferencia editorial a partir del paper y de sus posibles implicaciones; no es una afirmación de los autores.