C-GEO Guard Research Access

Access is provided for defensive research and evaluation.

Log in or Sign Up to review the conditions and access this model content.

C-GEO Guard

C-GEO Guard is a lightweight chunk-level detector designed to filter information-distorting GEO content from retrieved context before answer generation. It is evaluated with Counter-GEO-Bench. See the Counter-GEO-Bench paper for implementation details.

Recommended threshold

The recommended threshold is 0.90, which favors precision and a low false-positive rate.

Files and evaluation

  • model.safetensors and the tokenizer/configuration files: fine-tuned DeBERTa-v3-base SentenceTransformer checkpoint.
  • centroids/class_1.npy--class_8.npy: normalized 768-dimensional attack-class centroids used by the detector.
  • calibration.json: held-out calibration statistics.
  • code/: training, chunk-scanning, and defended-synthesis code.

The phase3_ script prefix denotes the defense-filtering stage between victim synthesis and judge-based evaluation.

The evaluation code expects the checkpoint path in DEBERTA_MODEL_DIR. Set DEBERTA_THRESHOLDS='[0.90]' to use the recommended threshold. It consumes reranked chunk caches produced by the Counter-GEO-Bench harness.

Training

The encoder was trained for one epoch with multiple negatives ranking loss on 293 ID documents. Paired IP chunks, borderline ID rewrites, and clean chunks serve as negatives. The training split is disjoint from the 247-query evaluation benchmark.

Intended use

The model is intended for research on defenses against information-distorting GEO in retrieval-augmented and generative search systems. It filters retrieved chunks before answer generation and is trained to distinguish ID GEO rewrites from paired IP rewrites and clean text.

Access is gated for defensive research and evaluation. The model must not be used to optimize misinformation against detection systems.

License

The model weights and centroids are licensed under CC BY-NC 4.0. Files under code/ are licensed under Apache 2.0. See LICENSE and LICENSES/ for the applicable terms.

Citation

Paper: Counter-GEO-Bench

If you use C-GEO Guard, please cite:

@misc{zheng2026countergeo,
  title         = {{Counter-GEO-Bench}: Evaluating Defenses Against Information-Distorting Generative Engine Optimization},
  author        = {Zheng, Bing and Zhao, Zongyao and Yang, Wenming},
  year          = {2026},
  eprint        = {2609.02316},
  archivePrefix = {arXiv},
  primaryClass  = {cs.IR},
  url           = {https://arxiv.org/abs/2609.02316}
}
Downloads last month
-
Safetensors
Model size
0.2B params
Tensor type
F32
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for counter-geo/c-geo-guard

Finetuned
(777)
this model

Paper for counter-geo/c-geo-guard