Adversarial AEO: How Competitors Poison Your AI Citations

Adversarial AEO: How Competitors Poison Your AI Citations
DIRECT ANSWER

Adversarial AEO is the practice of degrading a competitor's AI citation standing, or defending against it being done to you. The real attack surface is not hacking the model; it is manipulating the sources the model reads. Three attacks matter: contradiction injection (seeding conflicting facts about your target across the web so engines lose confidence in any single source), co-mention hijacking (inserting a competitor into the "brands like X" associations an engine has learned), and entity confusion (blurring the line between two similar brands so citations leak). The defense for all three is the same: a strong, consistent, well-corroborated entity that is expensive to contradict. You do not out-attack this. You out-anchor it.

Most AEO writing assumes a neutral field: you optimize, the engine reads, citations follow. The field is not neutral. Because AI engines assemble answers from public sources, anyone who can influence those sources can influence the answer, and that includes people who would rather you were not cited. This is the uncomfortable adjacent topic to how co-mentions build compound authority: the same mechanism that lets you build standing lets someone else attack it.

A caution before the mechanics: this article is written for defense. The attacks are described so you can detect and harden against them, and the framing throughout is that manipulation is fragile and anchoring is durable, which is both the ethical position and, usefully, the true one. Engines are actively hardening against source manipulation, so the attacker's edge decays while the defender's anchor compounds.

Attack one: contradiction injection

An engine's confidence in a fact rises when sources agree and falls when they conflict. Contradiction injection exploits the second half: seed conflicting claims about a target across low-friction surfaces, forums, low-quality directories, comment sections, scraped-content sites, so that when an engine assembles what it knows about the target, it finds disagreement and hedges. The target does not get defamed in any single visible place; it gets made uncertain everywhere at once. The symptom is an engine describing you with hedges ("some sources indicate") or declining to state facts about you it should know cleanly.

The defense is corroboration density. A fact stated once on your own site is contradictable; the same fact stated consistently on your site, your entity home, authoritative third-party profiles, and structured data that all agree is expensive to overwhelm, because the attacker now has to out-publish a corroborated consensus. Anchoring your entity across sources with sameAs is the structural version of this defense: you are not hoping engines believe you, you are making your version the cheapest one to confirm.

Attack two: co-mention hijacking

Engines learn associations from how brands appear together. "Tools like Ahrefs and Semrush" repeated across the web teaches the engine those brands are a set. Co-mention hijacking manufactures those associations: publish content that repeatedly places the attacker's brand alongside the incumbents in a category, and over time the engine's learned set expands to include them, so that "best tools for X" answers start surfacing the newcomer beside the established names. Used on yourself, this is a legitimate strategy. Used to displace, it is the same mechanism aimed at diluting a leader's distinctiveness.

The defense is not to police who mentions you, which you cannot, but to own a distinctive position that generic co-mention cannot erode. A brand known for a specific, named capability ("the honesty-first AEO auditor") is harder to blur into an undifferentiated set than a brand known only as "an AEO tool." The way an engine describes your brand is the thing to monitor here: if the descriptors drift toward generic category language, your distinctiveness is eroding, whether by attack or neglect.

Three source-level attacks on AI citations and the single anchoring defense that counters all threeAttack Surface vs AnchorContradictioninjectionseed conflictingfacts to raise doubtCo-mentionhijackingforce into the"brands like X" setEntityconfusionblur two brandsso citations leakTHE ANCHORConsistent, corroborated, distinctive entityacross every source an engine trustsOne defense counters all three: be expensive to contradict.Manipulation is fragile. Anchoring compounds.

Attack three: entity confusion

When two brands have similar names or overlapping categories, an engine can conflate them, and citations meant for one leak to the other. The adversarial version deliberately deepens the confusion: an attacker names or positions a property to sit close to yours in entity space, so that some fraction of the engine's citations for you resolve to them. The defense is entity separation, a distinct name treatment, a clear and consistent entity home, and structured data that pins exactly who you are. The difference between an about-us page and a true entity home is the crux: an entity home exists specifically to be the unambiguous, machine-readable definition of who you are, which is what makes confusion expensive to sustain.

How to detect it

The attacks share a signature: a divergence between what should be true of your citations and what is. Monitor for it. Query the engines regularly for facts about your brand and watch for new hedging or errors that were not there before (contradiction injection). Watch your co-mention set for competitors appearing in associations they did not previously hold (hijacking). Watch for citations resolving to a similar entity, or a rise in "did you mean" style confusion (entity confusion). None of this requires special tooling, it requires reading your citation patterns over time and noticing when a stable pattern turns volatile without a change on your end.

Why defense beats offense here

The strategic asymmetry is the whole point. Attacks operate by adding noise to public sources, and noise is fragile: engines are continuously improving at down-weighting low-quality and manipulated sources, seeded contradictions decay as the manufactured content ages and loses authority, and any attack loud enough to work is loud enough to detect. Anchoring operates by building corroborated consensus, which compounds: every consistent mention, every structured-data agreement, every authoritative profile raises the cost of contradicting you. The attacker rents their effect and pays rising rent; the defender owns theirs and the value accrues.

The best defense against adversarial AEO is indistinguishable from just doing AEO correctly. A brand with a strong entity home, dense corroboration, distinctive positioning, and monitored citations has already paid for the defense as a byproduct of the offense. The teams that are vulnerable to source manipulation are the ones who never built the anchor in the first place, which means the fix for the exotic threat is the same as the fix for the ordinary one: be the source that is cheapest to confirm and most expensive to contradict.

Sources

  • Google, Search Essentials and spam policies: how Google treats manipulated and low-quality sources. developers.google.com
  • arXiv, on prompt-injection and data-poisoning research: the academic grounding for source-level manipulation of LLMs. arxiv.org/abs/2302.12173
  • Website AI Score, brand co-mentions and compound authority: the mechanism both sides of this exploit. View article
  • Website AI Score, the entity home: the structural anchor that makes confusion expensive. View article
  • Website AI Score, five citation patterns: reading the signal that reveals an attack in progress. View article
GEO Protocol: Verified for LLM Optimization
Hristo Stanchev

Audited by Hristo Stanchev

Founder & GEO Specialist

Published on July 18, 2026