ChatPaper.aiChatPaper

深度研究可靠吗?误导性知识诱发错误结论

Is Deep Research Reliable? Misleading Knowledge Induces False Conclusions

July 23, 2026
作者: Pengyu Zhu, Lijun Li, Longju Yang, Sen Su
cs.AI

摘要

Deep Research智能体将基于LLM的助手扩展到涉及规划、检索、证据综合和报告生成的长周期工作流中,但它们在开放信息环境中的可靠性仍未得到充分探索。一个关键问题是,在此类环境中遇到的看似可信但事实上具有误导性的知识是否能够通过这些工作流传播,并在最终报告中被采纳为错误结论。为研究这一失效模式,我们提出MisKnow-Agent——一个用于构建和验证Deep Research任务中误导性知识的框架。MisKnow-Agent以可控的权威级别和风格生成误导性实例,基于DeepResearch Benchmark任务产生5,933个质量受控的实例。对开源和闭源Deep Research智能体的大量实验表明,即使仅接触少量误导性知识,也可能导致最终报告采纳错误结论,揭示了当前Deep Research智能体中普遍存在的可靠性漏洞。尽管具备搜索能力的验证模型在聚焦语料验证过程中一致地将保留实例识别为误导性,但在长周期研究过程中,相同实例仍可能被采纳,这揭示了聚焦验证与工作流级证据使用之间的脱节。最后,我们评估了研究前与研究后的防御措施,包括单独及组合使用,发现所有三种配置均能缓解但无法完全阻止错误结论的采纳。我们的研究结果表明,可靠的Deep Research需要在模型层面和框架层面同时具备证据验证与纠正能力,而不仅仅是提升规划、检索、证据整合或报告生成能力。
English
Deep Research agents extend LLM-based assistants into long-horizon workflows involving planning, retrieval, evidence synthesis, and report generation, yet their reliability in open information environments remains underexplored. A key concern is whether apparently credible but factually misleading knowledge encountered in such environments can propagate through these workflows and be adopted as false conclusions in final reports. To study this failure mode, we introduce MisKnow-Agent, a framework for constructing and validating misleading knowledge for Deep Research tasks. MisKnow-Agent generates misleading instances with controllable authority levels and styles, yielding 5,933 quality-controlled instances built on DeepResearch Benchmark tasks. Extensive experiments across open-source and closed-source Deep Research agents show that even limited exposure to misleading knowledge can induce false-conclusion adoption in final reports, revealing a broad reliability vulnerability in current Deep Research agents. Although search-enabled verifier models consistently identify the retained instances as misleading during focused corpus validation, the same instances can still be adopted during long-horizon research, revealing a disconnect between focused verification and workflow-level evidence use. Finally, we evaluate pre- and post-research defenses, both individually and in combination, finding that all three configurations mitigate but do not fully prevent false-conclusion adoption. Our findings suggest that reliable Deep Research requires evidence verification and correction capabilities at both the model and framework levels, beyond improvements in planning, retrieval, evidence integration, or report-generation abilities.