Lily Ray

Key takeaways
- 6:03Just 250 poisoned documents can reliably backdoor an LLM with 600 million to 13 billion parameters, overturning prior assumptions that poisoning required a proportional percentage of training data.
- 10:09RAG systems are vulnerable to real-time SEO manipulation through indirect prompt injection, semantic stuffing, and schema manipulation in ways that resemble early search engine optimization tactics.
- 20:16LLMs currently lack built-in fact-checking and spam defenses that search engines have spent 25+ years developing, creating a temporary renaissance for LLM spam that will not last.
- 21:17Best-of listicles and other popular AEO tactics work now but are unsustainable; companies risk being flagged as spam and excluded from future LLM training data if caught manipulating AI visibility.
- 25:20Serving different content to bots than humans (cloaking) raises red flags with Google's anti-spam policies and risks penalizing visibility across all AI systems, including Gemini and AI Overviews.
Questions Lily Ray answered
Lily recommends claiming brand profiles across all platforms, monitoring brand mentions using tools like Alert Mouse, and staying aware of where your brand is mentioned and talked about. Engagement on platforms like Trustpilot and Google Business Profile is critical for managing conversations with consumers.
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search27:22
Removal is difficult; the focus should be on LLM companies themselves developing anti-poisoning measures. Monitoring is the first step, and platforms have systems for reporting defamatory content or filing DMCA takedowns, but there is no straightforward purging mechanism.
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search29:25
Create content for users first, not just machines. Avoid overengineering content for AI that sacrifices readability. Only serve different content to bots if explicitly requested by companies like OpenAI or Google, which they have not yet done. Always maintain parity between human and bot-visible content.
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search31:27
Lily recommends using LLM tracking tools like Profound, Semrush's AIO, Conductor, or more affordable options like Pike and WAIK to monitor how frequently your website is cited. Choose a tool based on your budget and needs; having at least one tracking tool is essential for understanding competitive performance.
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search32:27
Lily doesn't have direct evidence of significant false positive issues. The opposite problem appears to be more prevalent: obvious AI-generated spam content is being treated as high-quality, such as listicle content, while LLMs struggle to detect real spam.
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search34:29
In Lily Ray's words
“I see the writing on the wall with what's happening right now with AEO and GEO. I think that we're going to start to see a crackdown in the next few months and maybe years as it relates to spam and LLM.”
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search3:00
“Attackers actually don't need to control a percentage of the training data. Instead, it's just a fixed small number of malicious documents. So 250 documents that can reliably implant a backdoor in the LLM training data.”
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search6:03
“John Mueller from Google literally said that optimizing sites for embeddings is literally keyword stuffing. When Google is saying something is a version of Google spam, it probably means that they're working on anti-spam measures.”
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search22:18
“It all works until it doesn't. There's so many examples of people getting away with SEO tactics, GEO tactics, growing traffic really quickly in the short term up until they wake up one morning and all their traffic is gone.”
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search23:18
“I would be careful to do anything that your users and your customers wouldn't think is fair or ethical because ultimately I think that's kind of the measurement or the criteria that these companies are using to determine what's fair and what's not.”
Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search31:27