LLM poisoning defense for companies whose AI answers have been tampered with — or could be. An attacker does not need to hack a model to corrupt what it says about you; they only need to seed what it reads.

What is LLM poisoning defense?

LLM poisoning defense is the detection, attribution, and correction of manipulated information in the sources AI models retrieve from — the pages, forums, and datasets that ChatGPT, Perplexity, and Google AI Overviews consult when answering questions about a company. Because modern AI answers are grounded in retrieved web content, an attacker can corrupt them without touching the model: seed false content where the model looks, and the model repeats it. LLM poisoning defense finds the seeded content, identifies who placed it, and displaces it with verifiable, higher-authority sources.

Most firms still cover this threat in blog posts. We treat it as an operational discipline: monitoring, forensics, correction, hardening.

How the attack works: data voids and seeded retrieval.

A data void is a query with no authoritative coverage — a company name plus "lawsuit," a founder's name plus a loaded word. Nobody credible has written about it, so nothing credible ranks. An attacker fills the void: a handful of pages, forum threads, and spun "review" posts written for machine retrieval rather than human readers. When an engine gets the query, the seeded content is the only evidence available. The model does what models do. It summarizes its sources.

Two variants matter. Retrieval poisoning corrupts what engines fetch at answer time; it works today, is cheap to attempt, and reverses fastest. Training-data poisoning targets what future models memorize; slower, blunter, harder to reverse once a model ships. Most live cases are retrieval-side. That is the good news: retrieval can be fought on the open web.

Can competitors poison AI results about my brand?

Yes. It requires no special access, and the tooling is commodity. But before accusing anyone: most wrong AI answers are not attacks. Stale data, thin coverage, and entity confusion — your name colliding with a similarly named company — produce the same symptoms as sabotage. The first job is diagnosis, not retaliation.

When it is deliberate, attribution matters. We run it through OSINT investigation: who published, when, from what infrastructure, in what sequence. Evidence is preserved to a standard your counsel can use. Attribution before accusation. Always.

The defense: detect, attribute, correct, harden.

Detect. Standing answer monitoring across ChatGPT, Perplexity, Gemini, and AI Overviews — the same prompt panels that power our generative engine optimization practice, with drift alerts when an answer turns false or hostile.

Attribute. OSINT forensics on the poisoned sources: registration data, publishing patterns, network overlap. You get an evidence file, not a hunch.

Correct. Authoritative source engineering. We do not hack, delist by deception, or fabricate anything. We publish and place accurate, corroborated, higher-authority content that engines retrieve first, and we fill the data voids the attack exploited. Where seeded content violates platform policy or law, we support removal through the platform's own process and your counsel. This is de-positioning, honestly framed: displacement, not deletion.

Harden. Entity clarity so there is nothing empty to poison: consistent structured data, llms.txt, canonical fact pages for the queries that matter. If the seeding is part of a broader campaign against your infrastructure or your people, we bring in cybersecurity as one team, not a referral.

What you get. What you own.

A poisoning assessment with severity and blast radius. The evidence file. A source map of what each engine reads about you. The corrected-content inventory and placements. Monitoring dashboards and a hardening backlog your team owns outright. Every LLM poisoning defense engagement ends with full IP transfer and a clean exit.

Everything operates under an explicit legal and ethical charter: no fake reviews, no guaranteed removal of truthful content, no action we would not defend in a deposition. If something cannot be fixed honestly, we tell you what can be done instead — and what it costs to live with.

Under attack right now?

If ChatGPT or Perplexity is repeating something false about your company today, speed matters more than ceremony. We run a rapid triage — current answers captured across engines, poisoned sources identified, severity called — then a two-week Diagnostic Sprint to scope the full correction. Ongoing defense runs as a Strategic Advisor retainer.

If the damage is reputational as much as informational — executives named, customers asking — pair this with fixing what ChatGPT says about you. Different disciplines, one operating picture.

Frequently asked questions

What should I do when ChatGPT says something wrong about my company?
First, document it: capture the prompt, the answer, the date, and any cited sources across ChatGPT, Perplexity, and Google AI Overviews. Second, diagnose the cause — stale data, entity confusion with a similarly named organization, or deliberately seeded content each require a different fix. Third, correct at the source: publish authoritative, corroborated content that answers the query directly, fix your structured data, and use platform feedback channels where the content violates policy. Wrong AI answers are usually a sourcing problem, and sourcing problems are fixable.
What is a data void attack?
A data void attack exploits a query with little or no authoritative coverage, such as a company name paired with a loaded term like "scandal" or "lawsuit." An attacker publishes content targeting that empty query, and because nothing credible competes, AI engines and search engines retrieve the seeded content as their only source. The defense is filling the void: authoritative, corroborated content on the exact queries an attacker would target.
Is LLM poisoning illegal?
Sometimes. Deliberately seeding false statements about a company can constitute defamation, trade libel, or tortious interference depending on jurisdiction and intent, and coordinated fake reviews violate platform policy and consumer-protection rules in the United States. Much of it lives in gray zones: misleading-but-arguable comparison content, offshore actors, anonymous forums. Blankpage preserves evidence to a forensic standard and works alongside your counsel — and corrects the record on the open web whether or not a legal remedy exists.
How long does it take to fix a poisoned AI answer?
It depends on where the poison lives. Answers grounded in live retrieval — Perplexity, ChatGPT with browsing, Google AI Overviews — can shift within weeks once higher-authority sources displace the seeded ones. Answers baked into a model's training data persist until the provider retrains, which no outside party controls or can honestly promise a date for. Blankpage reports answer drift monthly against a fixed prompt panel, so you see correction happen rather than taking it on faith.