Deep Researchは信頼できるのか?誤解を招く知識が誤った結論を導く
Is Deep Research Reliable? Misleading Knowledge Induces False Conclusions
July 23, 2026
著者: Pengyu Zhu, Lijun Li, Longju Yang, Sen Su
cs.AI
要旨
ディープリサーチエージェントは、LLMベースのアシスタントを、計画立案、検索、エビデンス統合、レポート生成を含む長期的ワークフローへと拡張するが、オープンな情報環境におけるそれらの信頼性は依然として十分に調査されていない。主要な懸念事項は、そのような環境で遭遇する一見もっともらしいが事実に反する誤誘導的知識が、これらのワークフローを通じて伝播し、最終レポートにおいて誤った結論として採用され得るかどうかである。この障害モードを研究するため、我々はMisKnow-Agentを紹介する。これはディープリサーチタスク向けの誤誘導的知識を構築・検証するためのフレームワークである。MisKnow-Agentは、制御可能な権威レベルとスタイルを持つ誤誘導的インスタンスを生成し、DeepResearchベンチマークタスクに基づいて5,933件の品質管理済みインスタンスを生成する。オープンソースおよびクローズドソースのディープリサーチエージェントにわたる広範な実験により、限られた誤誘導的知識への曝露でも最終レポートにおける誤った結論の採用を誘発し得ることが示され、現在のディープリサーチエージェントにおける広範な信頼性の脆弱性が明らかになった。検索機能を備えた検証モデルは、焦点を絞ったコーパス検証中に保持されたインスタンスを一貫して誤誘導的と識別する一方で、同じインスタンスが長期的研究の過程では依然として採用され得る。これは、焦点を絞った検証とワークフローレベルのエビデンス利用との間の乖離を明らかにするものである。最後に、研究前および研究後の防御策を個別および組み合わせの両方で評価し、3つの構成すべてが誤った結論の採用を軽減するものの完全には防止しないことを見いだした。我々の知見は、信頼性の高いディープリサーチには、計画立案、検索、エビデンス統合、レポート生成能力の改善を超えて、モデルレベルとフレームワークレベルの両方でのエビデンス検証および修正機能が必要であることを示唆している。
English
Deep Research agents extend LLM-based assistants into long-horizon workflows involving planning, retrieval, evidence synthesis, and report generation, yet their reliability in open information environments remains underexplored. A key concern is whether apparently credible but factually misleading knowledge encountered in such environments can propagate through these workflows and be adopted as false conclusions in final reports. To study this failure mode, we introduce MisKnow-Agent, a framework for constructing and validating misleading knowledge for Deep Research tasks. MisKnow-Agent generates misleading instances with controllable authority levels and styles, yielding 5,933 quality-controlled instances built on DeepResearch Benchmark tasks. Extensive experiments across open-source and closed-source Deep Research agents show that even limited exposure to misleading knowledge can induce false-conclusion adoption in final reports, revealing a broad reliability vulnerability in current Deep Research agents. Although search-enabled verifier models consistently identify the retained instances as misleading during focused corpus validation, the same instances can still be adopted during long-horizon research, revealing a disconnect between focused verification and workflow-level evidence use. Finally, we evaluate pre- and post-research defenses, both individually and in combination, finding that all three configurations mitigate but do not fully prevent false-conclusion adoption. Our findings suggest that reliable Deep Research requires evidence verification and correction capabilities at both the model and framework levels, beyond improvements in planning, retrieval, evidence integration, or report-generation abilities.