Instructions to use counter-geo/c-geo-guard with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- sentence-transformers
How to use counter-geo/c-geo-guard with sentence-transformers:
from sentence_transformers import SentenceTransformer model = SentenceTransformer("counter-geo/c-geo-guard") sentences = [ "The weather is lovely today.", "It's so sunny outside!", "He drove to the stadium." ] embeddings = model.encode(sentences) similarities = model.similarity(embeddings, embeddings) print(similarities.shape) # [3, 3] - Notebooks
- Google Colab
- Kaggle
C-GEO Guard
C-GEO Guard is a lightweight chunk-level detector designed to filter information-distorting GEO content from retrieved context before answer generation. It is evaluated with Counter-GEO-Bench. See the Counter-GEO-Bench paper for implementation details.
Recommended threshold
The recommended threshold is 0.90, which favors precision and a low
false-positive rate.
Files and evaluation
model.safetensorsand the tokenizer/configuration files: fine-tuned DeBERTa-v3-base SentenceTransformer checkpoint.centroids/class_1.npy--class_8.npy: normalized 768-dimensional attack-class centroids used by the detector.calibration.json: held-out calibration statistics.code/: training, chunk-scanning, and defended-synthesis code.
The phase3_ script prefix denotes the defense-filtering stage between victim
synthesis and judge-based evaluation.
The evaluation code expects the checkpoint path in DEBERTA_MODEL_DIR. Set
DEBERTA_THRESHOLDS='[0.90]' to use the recommended threshold. It consumes
reranked chunk caches produced by the
Counter-GEO-Bench harness.
Training
The encoder was trained for one epoch with multiple negatives ranking loss on 293 ID documents. Paired IP chunks, borderline ID rewrites, and clean chunks serve as negatives. The training split is disjoint from the 247-query evaluation benchmark.
Intended use
The model is intended for research on defenses against information-distorting GEO in retrieval-augmented and generative search systems. It filters retrieved chunks before answer generation and is trained to distinguish ID GEO rewrites from paired IP rewrites and clean text.
Access is gated for defensive research and evaluation. The model must not be used to optimize misinformation against detection systems.
License
The model weights and centroids are licensed under CC BY-NC 4.0. Files under
code/ are licensed under Apache 2.0. See LICENSE and LICENSES/ for the
applicable terms.
Citation
Paper: Counter-GEO-Bench
If you use C-GEO Guard, please cite:
@misc{zheng2026countergeo,
title = {{Counter-GEO-Bench}: Evaluating Defenses Against Information-Distorting Generative Engine Optimization},
author = {Zheng, Bing and Zhao, Zongyao and Yang, Wenming},
year = {2026},
eprint = {2609.02316},
archivePrefix = {arXiv},
primaryClass = {cs.IR},
url = {https://arxiv.org/abs/2609.02316}
}
- Downloads last month
- -
Model tree for counter-geo/c-geo-guard
Base model
microsoft/deberta-v3-base