Are LLMs Reliable Rankers? Rank Manipulation via Two-Stage Token Optimization
Researchers have demonstrated a method to manipulate the ranking output of large language models used in information retrieval, exposing a vulnerability in systems that increasingly rely on these models to order search results. [1] The technique, called Rank Anything First (RAF), crafts small, natural-sounding text prompts that can consistently push a chosen item to the top of an LLM-generated list without appearing obviously manipulated. [1][2] The work was submitted to the arXiv preprint repository on October 8, 2025, by Xiyang Hu and colleagues, and a revised version followed on June 28, 2026. [1] arXiv, which began in 1991, hosts over two million scholarly preprints and receives roughly 24,000 new articles each month, serving as a primary distribution channel for computer science research. [6] RAF operates in two stages. The first stage uses a Greedy Coordinate Gradient approach to identify candidate tokens by balancing a ranking-effectiveness gradient against a readability score. [2] The second stage evaluates those candidates under exact ranking and readability losses, employing an entropy-based dynamic weighting scheme, and selects a token through temperature-controlled sampling. [2] The prompt is built token-by-token, guided by the dual objectives of maximizing the target item's rank and preserving linguistic naturalness. [2] Experiments across multiple LLMs showed that RAF significantly boosts the rank of target items using naturalistic language, and the authors report it is more robust than existing methods at both promoting items and maintaining naturalness. [2] The findings highlight that LLM-based reranking is susceptible to adversarial manipulation, raising concerns for the trustworthiness of modern retrieval systems. [1][2] The paper appears on arXiv under the Computation and Language category. The initial submission was 428 KB, and the revised version grew to 438 KB. [1] The authors have released their code on GitHub. [2] The research arrives as the arXiv platform continues to expand its community collaboration tools through arXivLabs, a framework launched in 2020 that allows third-party developers to build experimental features on top of the repository while adhering to principles of openness and user data privacy. [5]
safety-researchmodel-releaseresearch-paperproduct-launchtool-release
Background sources we checked (7)
- arxiv.org ↗ Large language models (LLMs) are increasingly used as rerankers in information retrieval, yet their ranking behavior can be steered by small, natural-sounding prompts. To expose this vulnerability, we present Rank Anything First (RAF), a two-stage token optimization method that c…
- info.arxiv.org ↗ arXiv Labs - arXiv info | arXiv e-print repository Skip to content # arXiv Labs Attention arXiv Users: arXiv Labs is pausing new proposals ## What are arXiv Labs? arXiv Labs are a way for the community to contribute new, useful features to arXiv. These integrations are avail…
- info.arxiv.org ↗ arXivLabs: Showcase - arXiv info | arXiv e-print repository ... # arXivLabs: Showcase ... arXiv is surrounded by a community of researchers and developers working at the cutting edge of information science and technology. ... While the arXiv team is focused on our core mission—pr…
- blog.arxiv.org ↗ arXivLabs: a space for community innovation – arXiv blog arXiv has launched a new, formalized framework enabling innovative collaborations with individuals and organizations. “Members of our community want to contribute tools that enhance the arXiv experience, and we val…
- en.wikipedia.org ↗ arXiv (pronounced as "archive"—the X represents the Greek letter chi ⟨χ⟩) is an open-access repository of electronic preprints and postprints (known as e-prints) approved for posting after moderation, but not peer reviewed. It consists of scientific papers in the fields of mathem…
- en.wikipedia.org ↗ 14 (fourteen) is the natural number following 13 and preceding 15.…
- en.wikipedia.org ↗ LK-99 also called PCPOSOS, is a gray–black, polycrystalline compound, identified as a copper-doped lead‒oxyapatite. A team from Korea University led by Lee Sukbae (이석배) and Kim Ji-Hoon (김지훈) began studying this material as a potential superconductor in 1999, and in July 2023 publ…