arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

GPE:在可控的地理风格中毒情况下评估用于事实核查的稳健证据聚合

GPE: Evaluating Robust Evidence Aggregation for Fact Verification under Controllable GEO-Style Poisoning

Zhaoqi Wang, Zijian Zhang, Xiaomei Yuan, Pengtao Kou, Jiamou Liu, Zhen Li, Liehuang Zhu

arXiv 2607.20730首次发表:更新:

发表机构

School of Cyberspace Science and Technology, Beijing Institute of Technology; School of Computer Science, The University of Auckland(航天信息科学技术学院,北京理工大学; 计算机科学学院,奥克兰大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对大型语言模型利用搜索工具时文档可能被操纵的问题,提出GPE,包含多领域事实核查基准及评估框架,通过实验证明其能揭示仅干净评估无法发现的稳健性下降与效率权衡,凸显对抗性证据环境下评估事实核查的必要性。

AI 中文摘要

大型语言模型越来越多地使用搜索工具来检索最新信息,这引入了一个新的攻击面,即检索到的文档可能被操纵。生成引擎优化的发展加剧了这种风险,它会使选定内容更有可能被模型检索、引用和采用。现有的事实核查基准和评估框架没有提供评估针对地理风格中毒的稳健性所需的可控证据环境。因此,我们提出了GPE,它由一个多领域事实核查基准和一个用于控制证据来源和中毒率的评估框架组成。跨多种验证方法和中毒攻击的实验表明,GPE揭示了仅通过干净评估无法观察到的稳健性下降和效率权衡,证实了在对抗性证据环境下评估事实核查的必要性。

英文摘要

Large language models increasingly use search tools to retrieve up-to-date information, introducing a new attack surface in which retrieved documents can be manipulated. This risk is amplified by the development of generative engine optimization, which can make selected content more likely to be retrieved, cited, and adopted by models. Existing fact-verification benchmarks and evaluation frameworks do not provide the controlled evidence environments needed to assess robustness against GEO poisoning. We therefore propose GPE, which consists of a multi-domain fact-verification benchmark and an evaluation framework for controlling evidence sources and poisoning ratios. Experiments across multiple verification methods and poisoning attacks demonstrate that GPE exposes robustness degradation and efficiency trade-offs that cannot be observed through clean evaluation alone, confirming the need to evaluate fact verification under adversarial evidence environments.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑