The Ranking Blind Spot: Decision Hijacking in LLM-based Text Ranking

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Qian, Yaoyao, Zeng, Yifan, Jiang, Yuchao, Jain, Chelsi, Wang, Huazheng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911171364257792
author Qian, Yaoyao
Zeng, Yifan
Jiang, Yuchao
Jain, Chelsi
Wang, Huazheng
author_facet Qian, Yaoyao
Zeng, Yifan
Jiang, Yuchao
Jain, Chelsi
Wang, Huazheng
contents Large Language Models (LLMs) have demonstrated strong performance in information retrieval tasks like passage ranking. Our research examines how instruction-following capabilities in LLMs interact with multi-document comparison tasks, identifying what we term the "Ranking Blind Spot", a characteristic of LLM decision processes during comparative evaluation. We analyze how this ranking blind spot affects LLM evaluation systems through two approaches: Decision Objective Hijacking, which alters the evaluation goal in pairwise ranking systems, and Decision Criteria Hijacking, which modifies relevance standards across ranking schemes. These approaches demonstrate how content providers could potentially influence LLM-based ranking systems to affect document positioning. These attacks aim to force the LLM ranker to prefer a specific passage and rank it at the top. Malicious content providers can exploit this weakness, which helps them gain additional exposure by attacking the ranker. In our experiment, We empirically show that the proposed attacks are effective in various LLMs and can be generalized to multiple ranking schemes. We apply these attack to realistic examples to show their effectiveness. We also found stronger LLMs are more vulnerable to these attacks. Our code is available at: https://github.com/blindspotorg/RankingBlindSpot
format Preprint
id arxiv_https___arxiv_org_abs_2509_18575
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle The Ranking Blind Spot: Decision Hijacking in LLM-based Text Ranking
Qian, Yaoyao
Zeng, Yifan
Jiang, Yuchao
Jain, Chelsi
Wang, Huazheng
Information Retrieval
Artificial Intelligence
Large Language Models (LLMs) have demonstrated strong performance in information retrieval tasks like passage ranking. Our research examines how instruction-following capabilities in LLMs interact with multi-document comparison tasks, identifying what we term the "Ranking Blind Spot", a characteristic of LLM decision processes during comparative evaluation. We analyze how this ranking blind spot affects LLM evaluation systems through two approaches: Decision Objective Hijacking, which alters the evaluation goal in pairwise ranking systems, and Decision Criteria Hijacking, which modifies relevance standards across ranking schemes. These approaches demonstrate how content providers could potentially influence LLM-based ranking systems to affect document positioning. These attacks aim to force the LLM ranker to prefer a specific passage and rank it at the top. Malicious content providers can exploit this weakness, which helps them gain additional exposure by attacking the ranker. In our experiment, We empirically show that the proposed attacks are effective in various LLMs and can be generalized to multiple ranking schemes. We apply these attack to realistic examples to show their effectiveness. We also found stronger LLMs are more vulnerable to these attacks. Our code is available at: https://github.com/blindspotorg/RankingBlindSpot
title The Ranking Blind Spot: Decision Hijacking in LLM-based Text Ranking
topic Information Retrieval
Artificial Intelligence
url https://arxiv.org/abs/2509.18575