arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

深度研究可靠吗?误导性知识会导致错误结论

Is Deep Research Reliable? Misleading Knowledge Induces False Conclusions

Pengyu Zhu, Lijun Li, Longju Yang, Sen Su, Jing Shao

arXiv 2607.20891首次发表:更新:

发表机构

Beijing University of Posts and Telecommunications; Shanghai Artificial Intelligence Laboratory; Chongqing University of Posts and Telecommunications(北京邮电大学; 上海人工智能实验室; 重庆邮电大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究深度研究代理在开放信息环境中的可靠性,引入MisKnow-Agent框架生成误导性实例,通过实验发现其易因误导知识得出错误结论,验证与实际证据使用脱节,评估防御措施效果,强调需提升模型和框架层面的证据验证及纠正能力。

AI 中文摘要

深度研究代理将基于大语言模型的助手扩展到涉及规划、检索、证据合成和报告生成的长期工作流程中,但其在开放信息环境中的可靠性仍未得到充分探索。一个关键问题是,在这种环境中遇到的看似可信但实际上具有误导性的知识是否会在这些工作流程中传播,并在最终报告中被用作错误结论。为了研究这种失败模式,我们引入了MisKnow-Agent,这是一个用于构建和验证深度研究任务中误导性知识的框架。MisKnow-Agent生成具有可控权威级别和风格的误导性实例,在深度研究基准任务上产生了5933个经过质量控制的实例。跨开源和闭源深度研究代理的广泛实验表明,即使有限地接触误导性知识也会导致最终报告中采用错误结论,揭示了当前深度研究代理中广泛存在的可靠性漏洞。虽然启用搜索的验证器模型在聚焦语料库验证期间始终将保留的实例识别为具有误导性,但在长期研究期间相同的实例仍可能被采用,揭示了聚焦验证与工作流程级证据使用之间的脱节。最后,我们评估了研究前和研究后的防御措施,单独评估和组合评估,发现所有三种配置都能减轻但不能完全防止错误结论的采用。我们的研究结果表明,可靠的深度研究需要在模型和框架层面具备证据验证和纠正能力,而不仅仅是改进规划、检索、证据整合或报告生成能力。

英文摘要

Deep Research agents conduct long-horizon investigations by iteratively planning, retrieving evidence, and generating reports. However, it remains unclear whether they can resist apparently credible but factually false information introduced into these workflows. To study this failure mode, we introduce MisKnow-Agent, a controlled evaluation framework that constructs task-specific documents supporting manually audited false conclusions with controlled authority cues and source styles. Applied to the tasks from DeepResearch Bench, it generates 5,933 misleading documents after filtering. We evaluate DeerFlow and WebThinker with three backbone LLMs, together with Gemini Deep Research, using a report-level false-conclusion adoption rate (FCAR) that counts only reports endorsing the false conclusion. Across the configurations, introducing one misleading document increases the mean FCAR from 0\% in the no-injection control to 54.7\%. FCAR varies substantially with lifecycle stage and framework design, and also with source authority and presentation style, whereas search-result rank and additional documents beyond the first have limited influence. Although cross-model verification consistently classifies retained instances as misleading, Deep Research agents can still adopt the corresponding false conclusions during long-horizon research. Pre- and post-research defenses reduce FCAR but do not eliminate adoption, motivating continuous verification when evidence enters intermediate research states and final synthesis. To facilitate reproducibility, our code and dataset are publicly available at https://github.com/whfeLingYu/MisKnow-Agent and https://huggingface.co/datasets/whfeLingYu/Misleading_Knowledge, respectively.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑