PAPER
Can AI search overviews be manipulated?
If there is bias in what an AI search overview selects, can that bias be used to push a result in?
Exploring LLM biases to manipulate AI search overview
- Authors
- Roman Smirnov
- Affiliation
- Single author (no affiliation stated)
- Venue
- arXiv preprint (14 pages, no conference publication listed)
- Submitted
- 2026-03-30
- arXiv
- arXiv:2605.00012
- We verified
- 2026-08-24
WHAT THE PAPER SAYS
The author reports that it can. He trained a small language model with reinforcement learning to rewrite search snippets, and writes that the rewritten snippets drew the LLM overview's selection in most cases. He also shows that selection depends on **relative comparison between candidates** rather than absolute quality, and that context poisoning attacks can produce inaccurate or harmful results. No success rate is reported numerically.
Read the original on arXiv ↗METHOD
How it was measured
Read the conditions before the numbers. The same figure means something different under a different sample or environment.
- Approach
- Reinforcement learning on a small language model to rewrite search snippets and draw LLM preference
- Scope
- Deliberately limited to snippets only, which the author states reflects realistic constraints of a web search environment
- Length
- 14 pages · 7 charts
- ⚠️ What is not reported
- Success rate and sample size are not given as concrete figures. The claim is at the level of "succeeded in most cases"
FINDINGS
What came out
- Manipulability
- The author reports that rewritten snippets drew the LLM overview's selection in most cases
- The nature of selection
- Overview selection depends on relative comparison between candidates rather than absolute quality — meaning the result changes with whatever the competing documents are
- Safety
- Context poisoning attacks are shown to be able to produce inaccurate or harmful results
- ⚠️ Strength of evidence
- A single-author preprint with no conference publication and no success-rate figures. This is the weakest evidence in the library
LIMITATIONS
Limitations the authors state themselves
Not our criticism — this is what the authors wrote in the paper.
- The experiment is confined to snippet rewriting — it does not cover a full real-world web search pipeline.
- Success rate and sample size are not reported numerically.
- A single-author preprint with no conference publication or peer review on record.
- There is no dedicated Limitations section.
NAVIRANG'S READING — NOT THE PAPER'S CONCLUSION
What stayed with us after reading was not the headline claim but a line underneath it. The central claim — that manipulation works — rests on thin evidence: a single author, 14 pages, and only the statement that it "succeeded in most cases", with no success rate and no sample size given as numbers. There is not even a limitations section, so we cannot tell what the author himself thinks he failed to do. We therefore do not carry this paper's conclusion forward as fact. What did catch our eye was the observation that **selection depends on relative comparison between candidates rather than absolute quality**. That property holds whether or not anyone is manipulating anything, and it transfers straight into practice — your document can stay untouched, word for word, and still lose or gain a citation because a competing document changed. That is why finishing after one measurement is not an option. Measuring repeatedly under the same conditions is not diligence; it is that the value moves outside our hands. We will also record the part that was uncomfortable to read. If what this paper shows is right, rank manipulation is something one could do. That Navirang does not build automated repeat searching or self-result clicking is a choice rather than a limit, and the reason is that it is abuse. For the same reason we have not reproduced the manipulation procedure in this summary — a paper summary must not become a set of instructions.
IN COMPARISON
Where it diverges from other papers
The claims-table entries this paper appears in.
RELATED
Related reading
If you want your own brand's numbers rather than a paper's
Every figure here came from someone else's sample. Send us a URL and we ask all 7 answer engines directly and measure yours.
We reply within one business day.