
ABSTRACTSearch engine optimisation grew a shadow discipline almost as soon as it appeared: link farms, keyword stuffing,cloaking and the other tactics that search engines spent two decades policing. Its successor, answer engine optimisation,is inheriting that shadow, but the target has changed. Where a manipulated search result competed for attention againstnine other links on a page, a manipulated answer arrives as a single synthesised statement, cited and confident, withnothing beside it for the reader to weigh it against. This paper treats adversarial AEO as a data-poisoning problem: themanipulation of the corpus an aggregation agent retrieves from, in order to control what it says. It sets out a taxonomyspanning commercial optimisation, the exploitation of sparse-data queries, indirect prompt injection and coordinateddisinformation, and reviews evidence that a handful of planted documents can steer a retrieval system with success ratesabove ninety per cent. It argues that aggregation agents are structurally more exposed than ranked search, because theyconcentrate authority into one answer and lend the trust of the aggregator to whatever source it cites. It proposes alayered defence, from provenance and source vetting at ingestion to corroboration at retrieval and inspectable citation atoutput, and connects these to earlier work in this series on auditability, confirmatory friction and misplaced trust. Itcloses with the defender's asymmetry and the unresolved question of who decides which sources are trustworthy. Keywords: adversarial AEO; answer engine optimisation; data poisoning; retrieval-augmented generation; aggregationagents; indirect prompt injection; LLM grooming; content provenance; disinformation; trust calibration Disclosure by Author: Portions of this manuscript were prepared with the assistance of generative AI tools for research synthesis, drafting, and editing. The models used were Indian Sovereign AI models provided by Ayen.
data poisoning, disinformation, adversarial AEO, retrieval-augmented generation, answer engine optimisation, indirect prompt injection, aggregation agents, trust calibration, content provenance, LLM grooming
data poisoning, disinformation, adversarial AEO, retrieval-augmented generation, answer engine optimisation, indirect prompt injection, aggregation agents, trust calibration, content provenance, LLM grooming
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
