Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»SEO & Digital Marketing»A 13-word edit can steer what deep-research AI agents recommend
    SEO & Digital Marketing

    A 13-word edit can steer what deep-research AI agents recommend

    adminBy adminJune 24, 2026No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    A 13-word edit can steer what deep-research AI agents recommend
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cornell Tech researchers found that deep-research AI agents can be manipulated by short edits to public user-generated pages, allowing a single injected Reddit-style comment to become a cited recommendation for fake products, services, or entities.

    The paper called those altered pages “poisoned” because the added text was designed to steer what the AI system cited and repeated. It identified the weakness in systems that search the web, gather sources, and write cited reports. The researchers called the attack WARP, short for Web Agent Retrieval Poisoning.

    How injected text reaches reports. The attack doesn’t require access to the model, prompts, search engine or retrieval system. Instead, an attacker edits or appends text to a page the agent already tends to retrieve, such as a Reddit thread, Wikipedia page, or forum post.

    • When the agent later searches related topics, it may pull in that page, cite it, and repeat the attacker’s chosen message.
    • Deep-research tools often run many related searches for one user request, and the paper found the same user-generated pages surfaced across related queries.

    Reddit was the biggest opening. Across STORM, Co-STORM, and OmniThink, 17% to 23% of retrieved URLs came from user-generated platforms, including Reddit, YouTube, Facebook, and Wikipedia.

    • Reddit made up the largest share of those pages. It accounted for 54% to 71% of user-generated URLs retrieved by the three open-source systems.
    • The researchers didn’t alter live websites. They used a simulation framework called GeoStorm to insert manipulated text into retrieved content during testing.

    A few words worked. The researchers found the attack worked with snippets as short as about 13 words:

    • In one test, a 15-word sentence pushed a fake cryptocurrency, BananaCoin, into a Co-STORM report as an “emerging” long-term investment option. The report cited the altered source alongside legitimate crypto sources.
    • When the manipulated page was retrieved, the fake entity appeared in 38% to 51% of reports across systems. Targeting multiple pages raised that range to 42% to 62%.
    • The attack still worked when systems retrieved full Reddit threads, though mention rates were lower. When injected text was added to complete Reddit threads and made up less than 4% of the retrieved content, the fake entity still appeared in 30% to 53% of reports when the page was retrieved.

    Defenses struggled. Blocking user-generated domains stopped this attack path, but it also removed sources such as firsthand product experiences and local recommendations.

    • The tested text filters failed to reliably separate injected passages from normal user content. The manipulated passages were fluent because they were written by an AI model, so perplexity-based filters were more likely to flag normal user content than the injected text.
    • Report-level checks also missed the manipulation. Altered reports looked similar to clean reports because the agent itself folded the fake recommendation into an otherwise normal answer.

    Why we care. A small edit to a public page can become part of a cited AI answer, even when the underlying source is user-generated. Misinformation planted on sites like Reddit or in forums can move from discussion threads to cited recommendations in AI answers that look credible to users.

    About the research. The paper, Deep-Research Agents Can Be Poisoned via User-Generated Content, was written by Tingwei Zhang, Harold Triedman, and Vitaly Shmatikov of Cornell Tech and posted to arXiv on May 22. The researchers tested the full attack on three open-source systems: STORM, Co-STORM, and OmniThink. They analyzed OpenAI Deep Research and Gemini Deep Research for user-generated citations, but didn’t run live manipulation tests because that would require publishing altered content to the open web.


    Search Engine Land is owned by Semrush. We remain committed to providing high-quality coverage of marketing topics. Unless otherwise noted, this page’s content was written by either an employee or a paid contractor of Semrush Inc.


    Danny Goodwin
    Danny Goodwin is Editorial Director of Search Engine Land & Search Marketing Expo – SMX. He joined Search Engine Land in 2022 as Senior Editor. In addition to reporting on the latest search marketing news, he manages Search Engine Land’s SME (Subject Matter Expert) program. He also helps program U.S. SMX events.

    Goodwin has been editing and writing about the latest developments and trends in search and digital marketing since 2007. He previously was Executive Editor of Search Engine Journal (from 2017 to 2022), managing editor of Momentology (from 2014-2016) and editor of Search Engine Watch (from 2007 to 2014). He has spoken at many major search conferences and virtual events, and has been sourced for his expertise by a wide range of publications and podcasts.

    13word agents deepresearch Edit Recommend steer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWhy AI Visibility Does Not Only Depend On SEO
    Next Article How Brian Winum Uses WP Multi-Site Networks to Scale 700+ Subdomains
    admin
    • Website

    Related Posts

    Google Begins Rolling Out The June 2026 Spam Update

    June 24, 2026

    8 top Profound alternatives your marketing team can actually use

    June 24, 2026

    Why AI Visibility Does Not Only Depend On SEO

    June 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Begins Rolling Out The June 2026 Spam Update

    June 24, 2026

    A Practical Guide for Network Engineers

    June 24, 2026

    8 top Profound alternatives your marketing team can actually use

    June 24, 2026

    How Brian Winum Uses WP Multi-Site Networks to Scale 700+ Subdomains

    June 24, 2026
    Categories
    • Blogging (100)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (291)
    • SEO & Digital Marketing (1,585)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (374)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Begins Rolling Out The June 2026 Spam Update

    June 24, 2026

    A Practical Guide for Network Engineers

    June 24, 2026

    8 top Profound alternatives your marketing team can actually use

    June 24, 2026
    Most Popular
    • Google Begins Rolling Out The June 2026 Spam Update
    • A Practical Guide for Network Engineers
    • 8 top Profound alternatives your marketing team can actually use
    • How Brian Winum Uses WP Multi-Site Networks to Scale 700+ Subdomains
    • A 13-word edit can steer what deep-research AI agents recommend
    • Why AI Visibility Does Not Only Depend On SEO
    • What it is and how to nail It with your team & tech
    • Attackers exploit Cisco Unified CM flaw weeks after patch release
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.